endoflife.ai
FortiMail EOS Edge Device List Exploited & Unpatchable EOL Watch

FortiMail CVE-2026-104286: Exploited, No Patch Yet, None for 7.2

By Scott Bissett  ·  Published: October 3, 2026  ·  EOL Watch — news analysis  ·  Read at Fortinet's advisory and CISA's catalog on October 3, 2026; lifecycle dates from Fortinet's product lifecycle, as served on our FortiMail page.

FortiMail has an exploited flaw with no fixed build, and one supported branch that will never get one. Fortinet's advisory FG-IR-26-175, published October 1, 2026, describes CVE-2026-104286: a path traversal combined with a NULL-byte handling flaw that, in Fortinet's words, "may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests". Fortinet rates it critical, CVSS 9.8, and states that it "has been reported to be exploited in the wild". The advisory lists every branch from 7.2 to 8.0 as affected. For 7.4, 7.6 and 8.0 it names the release that will carry the fix. For 7.2 it names a different branch.

The deadline arrives before the patch. CISA added the flaw to its Known Exploited Vulnerabilities catalog on October 1, 2026 with a due date of October 4, 2026. As of October 3, 2026, Fortinet's advisory still lists the fixed releases as upcoming, so the only way to meet that date is the workaround below. CISA's required action allows for exactly that: apply the vendor's mitigations, or discontinue use of the product if mitigations are unavailable. The entry also points to CISA's forensics triage requirements, so checking the appliance for compromise is part of the job.
Quick answer: FortiMail CVE-2026-104286 has no fixed build as of October 3, 2026; Fortinet's workaround is to disable the IBE service or take the webmail interface off the internet. FortiMail 7.2 will not receive a fix: Fortinet's solution for that branch is an upgrade to 7.4 or above, and 7.2 reaches end of support on November 10, 2026.

What Fortinet says, branch by branch

The affected ranges and solutions are Fortinet's, from the advisory. The two lifecycle columns are Fortinet's end of engineering support and end of support dates as we serve them on the FortiMail page.

BranchAffectedFortinet's solutionEnd of engineering supportEnd of support
8.08.0.0 through 8.0.1Upgrade to upcoming 8.0.2 or aboveMay 6, 2029November 6, 2030
7.67.6.0 through 7.6.6Upgrade to upcoming 7.6.7 or aboveAugust 1, 2027February 1, 2029
7.47.4.0 through 7.4.8Upgrade to upcoming 7.4.9 or aboveJuly 4, 2026January 4, 2028
7.27.2.0 through 7.2.9Upgrade to branch 7.4 or aboveMay 10, 2025November 10, 2026

The advisory does not list 7.0 or any older branch, as affected or as unaffected. FortiMail 7.0 reached end of support on November 17, 2025; an appliance on a branch that old has no statement from Fortinet either way and should be treated as exposed.

Running FortiMail past end of life?
Extended support past the official EOL date exists for many products in this position — whether it covers FortiMail is exactly what we check. Tell us where to reach you and we’ll reply with matched options and pricing guidance — or an honest “no vendor covers this.” Free, no obligation.

Free · No obligation · Independent — we track the dates, vendors don’t pay for placement · dates verified against vendor sources. See all support options →

Why 7.2 gets an upgrade path and not a build

FortiMail 7.2 is a supported branch today. Its end of support is November 10, 2026. But Fortinet's lifecycle has two dates per branch, and 7.2 passed the first one, end of engineering support, on May 10, 2025. This advisory shows what being past that date can mean in practice: the fix for a 7.2 appliance is to stop being a 7.2 appliance.

Note what that does to the 7.4 branch as well. FortiMail 7.4 passed its own end of engineering support on July 4, 2026, and it is still getting a build for this flaw, 7.4.9. So being past engineering support does not by itself decide the outcome: in this advisory one branch past that date gets a build and the other is told to upgrade. The advisory does not say why.

What we are not saying. We are not saying 7.2 is end of life; Fortinet's lifecycle says it is supported until November. We are also not adding 7.2 to our Exploited & Unpatchable feed today: that feed lists exploited flaws on products past their end date, and 7.2 is not past it. What a 7.2 operator needs to know this week is narrower: the workaround is available to you, the patch never will be, and the branch itself ends in weeks.

The workaround

Fortinet gives three options, in this order:

The advisory also publishes indicators of compromise: two source IP addresses, system event log lines showing a cron job created under root and an unexpected remote archive account, and IBE decryption errors in the encryption log. Read the advisory for the exact strings and check the logs before treating a mitigated appliance as clean.

What to do, by branch

8.0, 7.6 and 7.4: apply the workaround now and install the fixed release when Fortinet publishes it (8.0.2, 7.6.7 or 7.4.9). Check the logs against Fortinet's indicators either way.

7.2: apply the workaround now, then plan the upgrade as two decisions, not one. The advisory's minimum is branch 7.4, which is itself past engineering support and ends on January 4, 2028. Moving to 7.6 in the same change window lands on a branch with engineering support until August 1, 2027.

7.0 or older: the appliance is already past end of support and is not addressed by the advisory. Apply the same mitigations, assume exposure, and move to a supported branch.

Frequently Asked Questions

Is there a patch for FortiMail CVE-2026-104286?

Not yet, as of October 3, 2026. Fortinet's advisory FG-IR-26-175 lists the fixes as upcoming releases: 8.0.2 for the 8.0 branch, 7.6.7 for 7.6 and 7.4.9 for 7.4. Until they ship, Fortinet's workaround is to disable the IBE service, or to block internet access to the FortiMail webmail interface.

Will FortiMail 7.2 get a fix for CVE-2026-104286?

No. Fortinet's advisory lists 7.2.0 through 7.2.9 as affected and gives the solution for that branch as an upgrade to branch 7.4 or above. No 7.2 build is planned.

What is CISA's deadline for CVE-2026-104286?

CISA added CVE-2026-104286 to its Known Exploited Vulnerabilities catalog on October 1, 2026 with a due date of October 4, 2026 for federal agencies. The required action is to apply the vendor's mitigations under BOD 26-04, or to discontinue use of the product if mitigations are unavailable, and the entry points to CISA's forensics triage requirements.

Is FortiMail 7.2 still supported?

FortiMail 7.2 is past its end of engineering support and inside its last weeks of support: Fortinet's lifecycle gives end of engineering support as May 10, 2025 and end of support as November 10, 2026. That is why the advisory offers 7.2 an upgrade path and not a build.

What is the workaround for CVE-2026-104286?

Fortinet gives three options: disable IBE feature support (Encryption, IBE, IBE Service off, or the CLI command config system encryption ibe, set status disable); or remove internet access to the FortiMail webmail interface, limiting it to a trusted private network; or, where a web application firewall sits in front of FortiMail, block POST requests to /ibe that contain a path traversal sequence.

Related

© 2026 endoflife.ai · How we verify our dates · API · About