York Computer logo York Computer
Managed IT & Security
Cybersecurity News

FortiMail Zero-Day Under Active Attack — If Your Email Gateway Is Fortinet, Act Now

York Computer •

Fortinet is warning that attackers are actively exploiting a critical zero-day in its FortiMail email security gateway — a product that sits at the front door of many small-business inboxes. The flaw lets an unauthenticated attacker on the internet take control of the appliance without a password, and CISA gave federal agencies just three days to patch or pull it offline. If your business uses FortiMail (or your MSP does on your behalf), this one lands directly in your lap.

What happened

On October 1, 2026, Fortinet published advisory FG-IR-26-175 disclosing CVE-2026-104286, a critical CVSS 9.8 flaw that combines unauthenticated path traversal with null-byte handling and permits arbitrary file writes through HTTP or HTTPS . In plain English: an attacker who can reach your FortiMail management interface over the internet can drop files onto the appliance without logging in — which is typically enough to take it over.

The U.S. Cybersecurity and Infrastructure Security Agency added the vulnerability to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. The flaw affects Fortinet FortiMail, an email-security product commonly deployed at the network perimeter to filter malicious emails and protect enterprise messaging systems. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on October 1, 2026, confirming that exploitation is not theoretical. Federal Civilian Executive Branch agencies were instructed to apply the vendor-recommended remediation or mitigations by October 4, highlighting the urgency of the issue.

Fortinet has not attributed the attacks to a named group, but the published indicators are serious. The published indicators point to attacker behavior rather than a named actor: added and modified binaries on the appliance, a malicious ld.so.preload entry, tampering with the web server configuration, and an archive account configured to exfiltrate data to an external server. That last item — an archive account quietly shipping email data to an outside server — is the kind of thing that can run undetected for weeks.

Who is affected

This is a FortiMail problem, not a FortiGate firewall problem. If you don't run FortiMail, you're not exposed to this specific CVE. If you do, the affected versions are broad.

Affected branches are FortiMail 8.0.0-8.0.1, 7.6.0-7.6.6, 7.4.0-7.4.8, and 7.2.0-7.2.9, with some fixes still upcoming. Fortinet's guidance for versions without a patch yet is to disable the Identity-Based Encryption (IBE) feature and block internet access to the management interface. Fortinet advised disabling identity-based encryption or restricting the management interface and published attack indicators.

Small businesses rarely buy FortiMail directly — it usually arrives bundled through an IT provider or managed email security package. That's why this is a question for whoever manages your stack, not something you solve from your own desk. A current look at York Computer's managed IT services explains how perimeter devices like email gateways get monitored and patched on a schedule rather than when a headline forces it.

What your IT provider should be doing this week

If you have an MSP (or an internal IT person), these are the questions worth sending today:

1. Do we run FortiMail anywhere — on-prem, hosted, or as part of a bundled service? If yes, which version? 2. Is the FortiMail management interface reachable from the public internet? If so, has it been restricted to trusted networks? 3. Has IBE support been disabled on any appliance still running an unpatched version? 4. Have you checked the appliance for Fortinet's published indicators — modified binaries, ld.so.preload entries, suspicious web server config changes, and unexpected archive accounts? 5. If we were already compromised before the patch, what's the forensic plan?

That last point matters. The entry falls under Binding Operational Directive 26-04, which also requires covered agencies to perform forensic triage to determine whether a system was compromised before the fix was applied. Private businesses aren't bound by that directive, but the logic is the same: patching closes the door, it doesn't tell you who already walked through it.

If you already have internal IT and just need backup horsepower on incidents like this, that's exactly what co-managed IT support is designed for — a second set of eyes on perimeter appliances, after-hours coverage, and forensic triage when a KEV listing drops on a Thursday.

The bigger pattern

FortiMail is the fourth internet-facing security appliance in a week with an actively exploited critical flaw — joining ongoing exploitation of Citrix NetScaler, Cisco Catalyst SD-WAN Manager, and Microsoft SharePoint. The common thread is that attackers are hunting the exact devices small businesses rely on to keep attackers out: email gateways, VPNs, remote-access tools, and collaboration servers. These appliances sit on the public internet by design, and when one has an unauthenticated bug, there is no "user clicked a link" step for an attacker to work through.

The practical defense isn't exotic. It's keeping a current inventory of what you own, keeping management interfaces off the public internet, subscribing to vendor advisories, and having someone whose job it is to act within hours — not weeks — when CISA posts a new KEV entry.

What York Businesses Should Do

If your York County business uses FortiMail — directly or through a managed email security service — ask your IT provider this week whether you're on an affected version and whether the management interface is exposed to the internet. York Computer can confirm your exposure and apply the vendor mitigations if you don't have anyone else handling it.

Sources

Worried whether your business is exposed to this? Talk to York Computer.

Managed IT & cybersecurity for York County small businesses.

← Back to all articles