CVE-2026-104286 is a path traversal flaw, rated 9.8 (critical), in Fortinet FortiMail, the email security gateway many organizations place in front of their mail servers. Fortinet says it may allow an unauthenticated attacker to write arbitrary files on the underlying system with crafted HTTP or HTTPS requests. The attack is tied to FortiMail's Identity-Based Encryption (IBE) service, which is part of the webmail interface used for encrypted email.
Affected releases are FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9. Fortinet's advisory, published October 1, 2026, lists the fixed releases (8.0.2, 7.6.7 and 7.4.9) as upcoming, and tells 7.2 customers to move to the 7.4 branch. Until those ship, the workaround is the only protection.
Fortinet states the flaw has been reported as exploited in the wild and published indicators of compromise, including two attacker IP addresses and a rogue remote archive account. CISA added CVE-2026-104286 to its Known Exploited Vulnerabilities catalog on October 1, 2026, with a federal remediation deadline of October 4.
Recommended action:If you run FortiMail, act today rather than waiting for the patch. Turn off the IBE service (Encryption > IBE > IBE Service 'off', or the CLI command in Fortinet's advisory) if you do not depend on it. If you do, remove internet access to the FortiMail webmail interface or limit it to trusted networks, or have your web application firewall block POST requests to /ibe that contain '../'. Then check for compromise: search firewall and FortiMail logs for the two IP addresses Fortinet lists, review the archive account configuration for entries nobody created (the advisory shows one named 'archive234' sending mail to a remote server), and look for unexpected admin logins. A gateway that relays patient or citizen email can expose protected health information or confidential records, so treat any match as a security incident and document the risk assessment. Install 8.0.2, 7.6.7 or 7.4.9 as soon as Fortinet releases them, and if you still run 7.2, plan the move to 7.4 now. If a managed service provider runs your email security, ask them in writing which of these steps they have completed.