FortiMail CVE-2026-104286: Exploited, No Patch Yet, None for 7.2
FortiMail has an exploited flaw with no fixed build, and one supported branch that will never get one. Fortinet's advisory FG-IR-26-175, published October 1, 2026, describes CVE-2026-104286: a path traversal combined with a NULL-byte handling flaw that, in Fortinet's words, "may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests". Fortinet rates it critical, CVSS 9.8, and states that it "has been reported to be exploited in the wild". The advisory lists every branch from 7.2 to 8.0 as affected. For 7.4, 7.6 and 8.0 it names the release that will carry the fix. For 7.2 it names a different branch.
What Fortinet says, branch by branch
The affected ranges and solutions are Fortinet's, from the advisory. The two lifecycle columns are Fortinet's end of engineering support and end of support dates as we serve them on the FortiMail page.
| Branch | Affected | Fortinet's solution | End of engineering support | End of support |
|---|---|---|---|---|
| 8.0 | 8.0.0 through 8.0.1 | Upgrade to upcoming 8.0.2 or above | May 6, 2029 | November 6, 2030 |
| 7.6 | 7.6.0 through 7.6.6 | Upgrade to upcoming 7.6.7 or above | August 1, 2027 | February 1, 2029 |
| 7.4 | 7.4.0 through 7.4.8 | Upgrade to upcoming 7.4.9 or above | July 4, 2026 | January 4, 2028 |
| 7.2 | 7.2.0 through 7.2.9 | Upgrade to branch 7.4 or above | May 10, 2025 | November 10, 2026 |
The advisory does not list 7.0 or any older branch, as affected or as unaffected. FortiMail 7.0 reached end of support on November 17, 2025; an appliance on a branch that old has no statement from Fortinet either way and should be treated as exposed.
Why 7.2 gets an upgrade path and not a build
FortiMail 7.2 is a supported branch today. Its end of support is November 10, 2026. But Fortinet's lifecycle has two dates per branch, and 7.2 passed the first one, end of engineering support, on May 10, 2025. This advisory shows what being past that date can mean in practice: the fix for a 7.2 appliance is to stop being a 7.2 appliance.
Note what that does to the 7.4 branch as well. FortiMail 7.4 passed its own end of engineering support on July 4, 2026, and it is still getting a build for this flaw, 7.4.9. So being past engineering support does not by itself decide the outcome: in this advisory one branch past that date gets a build and the other is told to upgrade. The advisory does not say why.
The workaround
Fortinet gives three options, in this order:
- Disable IBE. In the GUI: Encryption, IBE, IBE Service off. In the CLI:
config system encryption ibe,set status disable,end. IBE is FortiMail's identity-based encryption; switching it off affects encrypted mail delivered through IBE, so check who relies on it first. - Take the webmail interface off the internet, or limit access to a trusted private network.
- If a web application firewall sits in front of FortiMail, block POST requests to
/ibethat contain a path traversal sequence (../).
The advisory also publishes indicators of compromise: two source IP addresses, system event log lines showing a cron job created under root and an unexpected remote archive account, and IBE decryption errors in the encryption log. Read the advisory for the exact strings and check the logs before treating a mitigated appliance as clean.
What to do, by branch
8.0, 7.6 and 7.4: apply the workaround now and install the fixed release when Fortinet publishes it (8.0.2, 7.6.7 or 7.4.9). Check the logs against Fortinet's indicators either way.
7.2: apply the workaround now, then plan the upgrade as two decisions, not one. The advisory's minimum is branch 7.4, which is itself past engineering support and ends on January 4, 2028. Moving to 7.6 in the same change window lands on a branch with engineering support until August 1, 2027.
7.0 or older: the appliance is already past end of support and is not addressed by the advisory. Apply the same mitigations, assume exposure, and move to a supported branch.
Frequently Asked Questions
Is there a patch for FortiMail CVE-2026-104286?
Not yet, as of October 3, 2026. Fortinet's advisory FG-IR-26-175 lists the fixes as upcoming releases: 8.0.2 for the 8.0 branch, 7.6.7 for 7.6 and 7.4.9 for 7.4. Until they ship, Fortinet's workaround is to disable the IBE service, or to block internet access to the FortiMail webmail interface.
Will FortiMail 7.2 get a fix for CVE-2026-104286?
No. Fortinet's advisory lists 7.2.0 through 7.2.9 as affected and gives the solution for that branch as an upgrade to branch 7.4 or above. No 7.2 build is planned.
What is CISA's deadline for CVE-2026-104286?
CISA added CVE-2026-104286 to its Known Exploited Vulnerabilities catalog on October 1, 2026 with a due date of October 4, 2026 for federal agencies. The required action is to apply the vendor's mitigations under BOD 26-04, or to discontinue use of the product if mitigations are unavailable, and the entry points to CISA's forensics triage requirements.
Is FortiMail 7.2 still supported?
FortiMail 7.2 is past its end of engineering support and inside its last weeks of support: Fortinet's lifecycle gives end of engineering support as May 10, 2025 and end of support as November 10, 2026. That is why the advisory offers 7.2 an upgrade path and not a build.
What is the workaround for CVE-2026-104286?
Fortinet gives three options: disable IBE feature support (Encryption, IBE, IBE Service off, or the CLI command config system encryption ibe, set status disable); or remove internet access to the FortiMail webmail interface, limiting it to a trusted private network; or, where a web application firewall sits in front of FortiMail, block POST requests to /ibe that contain a path traversal sequence.
Related
- FortiMail — every branch with Fortinet's two lifecycle dates
- Cisco Secure Email Gateway CVE-2026-76461 — September's email-gateway listing, and the same question about a branch inside its support window
- FortiOS 7.2 end of support — how Fortinet's two-date lifecycle works on its firewall line
- EOS Edge Device List — every edge platform we track with a CISA KEV history
- Exploited & Unpatchable — the feed of KEV entries on products past their fix window
- How we verify our dates — the rules every number on this site is held to