# FortiMail flaw faces active exploitation while fixes remain unavailable

_Published Sunday, October 4, 2026 at 7:18 AM EDT · Security · Latest · Tier 1 — Major_

![FortiMail flaw faces active exploitation while fixes remain unavailable — Primary](https://data.ibtimes.sg/en/full/97962/fortinets-fortimail.jpg?w=1200&h=630?q=60)

Fortinet says attackers are exploiting CVE-2026-104286 in FortiMail, with no fixed build yet available across affected release branches. The vulnerability lets an attacker without authentication send crafted HTTP or HTTPS requests that write arbitrary files to the system, potentially enabling unauthorized code or command execution.

Affected versions include 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, and 7.4.0 through 7.4.8. CISA added the flaw to its Known Exploited Vulnerabilities catalog, setting an Oct. 4 remediation deadline for U.S. federal civilian agencies.

Fortinet recommends disabling IBE feature support and restricting management access to trusted private networks. It has also published indicators of compromise. These mitigations reduce exposure but do not repair the vulnerable code.

## Sources

- [International Business Times Singapore](https://www.ibtimes.sg/fortimail-zero-day-cve-2026-104286-under-attack-no-patch-yet-94641)

---
Canonical: https://techandbusiness.org/newswire/Kq2uORZGCkNvia8BzVuyr9
Published: 2026-10-04T11:18:11.402Z
Story chronology: 2026-10-04T10:10:01.000Z
Retrieved: 2026-10-04T13:22:06.155Z
Publisher: Tech & Business (techandbusiness.org)
