
Fortinet is telling FortiMail customers to act now: CVE-2026-104286, a critical path traversal flaw in the appliance’s Identity-Based Encryption (IBE) component, is being actively exploited, and there is still no official patch.
The bug combines path traversal with improper handling of NULL-byte characters, letting an unauthenticated attacker manipulate file paths processed by the IBE GUI and write arbitrary files to the underlying OS via a crafted HTTP or HTTPS request. CVSS 9.8, no authentication, no user interaction. CISA added it to the Known Exploited Vulnerabilities catalog on October 1 and gave federal agencies until October 4 to remediate.
Affected versions span FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9. Fortinet’s own product security team found this one internally, which is the only reason there is an advisory at all before fixed builds ship. Until 8.0.2, 7.6.7, and 7.4.9 are out, the vendor’s own mitigation is blunt: disable IBE entirely (config system encryption ibe / set status disable) if you do not need it.
Mail gateways sit exactly where this kind of flaw does the most damage: internet-facing by design, trusted by everything behind them. If FortiMail is part of your perimeter, the question worth answering now is not just “did we apply the hotfix” but whether anything already got in during the window before it existed. That kind of perimeter exposure is exactly what our external network penetration testing is built to catch before an advisory forces the question.