Skip to content
RegionAmericas

MediumII Cyber Warfare & Critical Infrastructure1 October 2026, Thursday

FortiMail flaw exploited before any patch as CISA gives agencies three days

Fortinet announced on 1 October that a 9.8-rated flaw in its FortiMail email security appliances is being actively exploited. CISA added the flaw to its catalogue of exploited vulnerabilities the same day and gave federal agencies until 4 October. Fixed versions had not been released as of 2 October.

Location: UNITED STATES

According to CISA's alert of 1 October, CVE-2026-104286 is a path traversal flaw. In other words, an attacker can manipulate file paths to write to folders that should be off limits. Fortinet's advisory FG-IR-26-175 says an unauthenticated attacker can write files and execute commands using specially crafted HTTP or HTTPS requests. The flaw sits in the web interface of the identity-based encryption (IBE) module.

According to SecurityOnline, the flaw has a CVSS score of 9.8, and fixes are planned for versions 8.0.2, 7.6.7 and 7.4.9. Shattered.io wrote that these versions were not available for download as of 2 October and that no patch is planned for the 7.2 branch. Sources diverge on the affected version range: one lists 7.6 branch versions up to 7.6.5, the other up to 7.6.6. CISA's binding directive 26-04 leaves agencies a remediation window of only 3 days. With no patch available, the only options are to disable IBE or take the management interface off the internet.

Talay assessment

Bottom line

A 3-day deadline with no patch available forces agencies to curtail service rather than fix the flaw. If IBE is switched off, encrypted email flows are disrupted. Email gateways are the latest link in a wave of attacks on edge devices. The most likely path is that patches arrive within days, but that the first signs of intrusion surface before then.

Likely effects

  • Corporate email securityNegativeWeeks

    Organisations using FortiMail must disable IBE until a patch arrives, which could disrupt encrypted email traffic within 3 days.

  • Cyber insuranceNegative1–6 months

    Unpatched, actively exploited 9.8-rated flaws give insurers grounds to tighten edge device exclusions and premium assessments.

  • Institutions in TürkiyeNegativeWeeks

    Fortinet products are also widely used by public and private institutions in Türkiye. Local organisations will have to apply the same interim measure.

Possibilities, ranked

  1. 1
    Patch arrives, intrusion checks continue55%

    Fortinet releases versions 8.0.2, 7.6.7 and 7.4.9 within days, and organisations run retrospective intrusion scans.

    Watch: Fixed versions added to Fortinet's advisory FG-IR-26-175

  2. 2
    Mass exploitation30%

    The flaw is exploited at scale through automated scanning before a patch appears, and the first organisational breaches are announced.

    Watch: Security firms' scanning and breach reports targeting FortiMail

  3. 3
    Limited impact15%

    Exploitation stays targeted, disabling IBE narrows the attack surface and no new cases emerge.

    Watch: No new exploitation notice from CISA or Fortinet after 4 October

Probabilities are calibrated judgement based on the sources, not measurement, and are revised as new information arrives. Not investment advice.

Market reaction

Indicators affected

  • CVSS score▼ 9.8
  • CISA remediation window▼ 3 days
  • Released patch▼ None

Sources

  1. CISA — CISA Adds One Known Exploited Vulnerability to Catalog (1 October 2026)
  2. SecurityOnline — FortiMail Path Traversal Flaw CVE-2026-104286 Exploited in the Wild
  3. Shattered — FortiMail CVE-2026-104286: CVSS 9.8, CISA Alert