Free delivery

GGuestNot signed in
You're not signed in
LoginCreate account

10/2/2026 • Security

FortiMail Zero-Day: The Encryption Feature Is the Way In

Fortinet has confirmed a CVSS 9.8 flaw in FortiMail's Identity-Based Encryption portal is being exploited in the wild, letting attackers write files to the appliance with no login. Fixed builds were still listed as upcoming when the advisory landed, so the workaround is the fix for now.

The feature on a FortiMail appliance that exists to keep email private is the one attackers are now using to get in. On 1 October 2026 Fortinet published advisory FG-IR-26-175 for CVE-2026-104286, a CVSS 9.8 path traversal flaw in FortiMail's Identity-Based Encryption (IBE) component that lets someone with no login at all write arbitrary files onto the appliance with a crafted web request. Fortinet says it is already being exploited in the wild. The same day, the US cyber agency CISA added it to its Known Exploited Vulnerabilities catalogue and gave federal agencies three days to deal with it.

Here is the part that makes this one different from the usual "patch and move on" advisory: when the advisory went out, the fixed firmware builds were listed as upcoming, not available. If your business runs a FortiMail secure email gateway, the workaround is the fix for now, and it is worth doing today.

What happened, in plain English

FortiMail is Fortinet's email security appliance: it sits in front of your mail server, filters spam and malware, and optionally encrypts outgoing messages. IBE is the built-in option for that last job. Rather than requiring the recipient to have encryption software, FortiMail can hold the encrypted message and let the outside recipient pick it up through a secure web portal served by the appliance itself. That portal, by design, faces the internet and accepts requests from people who are not your staff.

The flaw is a combination of two classic web bugs. The IBE portal does not properly limit which path on the filesystem a request can reach (CWE-22, path traversal), and it mishandles null characters in input (CWE-158), which is a well-known way to sneak past filename checks. Put together, an unauthenticated attacker can send a crafted HTTP or HTTPS request and write a file of their choosing to the underlying system. The CVSS vector confirms the worst case: reachable over the network, low complexity, no privileges required, no user interaction, and full impact on confidentiality, integrity and availability. Being able to write any file to an appliance is generally one short step from running your own code on it.

The affected versions are broad. Every current branch is in scope:

  • FortiMail 8.0.0 through 8.0.1
  • FortiMail 7.6.0 through 7.6.6
  • FortiMail 7.4.0 through 7.4.8
  • FortiMail 7.2.0 through 7.2.9

Fortinet's stated fixes are 8.0.2, 7.6.7 and 7.4.9. For the 7.2 branch there is no fixed 7.2 build at all: the instruction is to move to 7.4 or later. At the time the advisory was published those three fixed builds had not yet shipped, so check the advisory for their current status before you plan an upgrade window.

The honest nuance, because getting it right matters: the "unauthenticated" claim is real and comes straight from Fortinet's own CVSS vector. The "actively exploited" claim is real too, confirmed by both Fortinet and the KEV listing. CISA's entry also flags this one for forensic triage, which is its way of saying "check whether you were already hit, not just whether you are patched." Reporting from BleepingComputer credits discovery to a researcher on Fortinet's own product security team. What nobody has published is who is behind the attacks, how many appliances have been compromised, or when the exploitation started.

Why it matters: the protective feature is the attack surface

Most of the flaws we cover in this series live in a management interface that should never have been on the internet in the first place. This one is different, and more uncomfortable. The IBE portal is supposed to be reachable from outside. Its whole purpose is to let customers, suppliers and patients who are not on your network collect an encrypted message. You cannot hide it behind the firewall without breaking the feature.

That is the real lesson here. Every feature you switch on that accepts input from strangers is a door, and "it's a security feature" does not change that. Secure-mail portals, guest Wi-Fi captive pages, customer self-service logins, file-drop sites: each one is a place where an unauthenticated person gets to send bytes to a box on your network. They deserve the same scrutiny as a VPN gateway, and the same question every few months: do we still use this, and does it still need to face the world?

It also matters because an email gateway is a particularly rich target. It sees every message in and out of your business, it holds credentials to your mail server, and it is trusted by your spam filters, your staff and your customers. We made a similar point when SonicWall's email security appliances had their own root-level flaws in August. An attacker sitting on a mail gateway can read, alter or quietly redirect mail for as long as they go unnoticed.

The honest bit

No vendor is immune, including the ones we like. We sell Cisco and Meraki gear, and Cisco had an identity-services zero-day of its own only last month. Fortinet has had a rough year, with the FortiBleed credential exposure in June still fresh, but this advisory itself was handled reasonably: the bug was found by Fortinet's own researchers, disclosed with a clear workaround, and the affected versions were stated precisely. The awkward gap is the one between "exploited now" and "fix coming," and that gap is exactly where the workaround earns its keep.

One genuine difference worth stating as advice rather than a pitch: on cloud-managed platforms, a fix for something like this is pushed to the device by the vendor, and the vendor can often apply a protective rule fleet-wide before the firmware even ships. We wrote about why that model keeps improving after you buy it. It is not a reason to rip out a working FortiMail. It is a reason to notice how much of this week's work lands on you with an appliance you patch yourself.

What we'd suggest you actually do

  1. Find out if you have one. FortiMail is often installed by a previous IT provider and then forgotten. Check your mail flow: if your MX records or your outbound mail route through a Fortinet appliance, you are in scope, whichever version you are on.
  2. Apply the workaround now, not after the patch. Fortinet's primary mitigation is to turn IBE off: in the web interface under Encryption, set the IBE Service to off, or from the CLI run config system encryption ibe, set status disable, end. If you genuinely cannot turn it off, Fortinet's alternative is to restrict webmail access from the internet, or to block POST requests containing ../ to the /ibe path at your firewall or reverse proxy.
  3. Plan the upgrade, and watch the advisory. Fixed builds are 8.0.2, 7.6.7 and 7.4.9. If you are on 7.2, there is no fix on that branch, so a move to 7.4 or later is now mandatory rather than optional. Re-check FG-IR-26-175 for release status before scheduling the window.
  4. Assume you may already have been hit. This was exploited before the advisory existed, so a workaround applied today does not undo last week. Look for unexpected files, new admin accounts, changed mail routing or relay settings, and unfamiliar outbound connections from the appliance. If anything looks wrong, treat it as an incident: rebuild the appliance from a clean image, rotate every credential it holds, and call the Australian Cyber Security Hotline on 1300 CYBER1 if you need help.
  5. Audit every internet-facing feature, not just this one. Make a list of every portal, page or service on your edge that accepts input from people who are not your staff. For each, ask whether it is still needed and whether it is restricted as tightly as it could be.
  6. Do the basics on the gateway itself. Unique admin credentials, multi-factor authentication where supported, management access only from inside or over VPN, and a subscription to Fortinet's PSIRT feed so the next one of these reaches you the day it lands.

The friendly takeaway

The headline is a zero-day in a mail gateway. The quieter lesson is that the features we add to make things safer are still attack surface, and the ones designed to welcome outsiders need the most watching. This week it was FortiMail's encryption portal. Next time it will be someone else's.

As always, this post is part of us keeping watch so you don't have to. If you would like a second pair of eyes on your email gateway, or just help working out whether you have a FortiMail at all and which version it is running, get in touch. No obligation, no hard sell. Sometimes the most useful answer is simply confirming that IBE is off and the upgrade is booked.

References

Contact Us

Email: [email protected]

Phone: 1300 989 334

About

Your one-stop technology hub for all your networking, security, and IT needs. From cutting-edge networking solutions to robust security products, we provide everything your business requires to stay connected, secure, and efficient. Whether you're looking for advanced hardware, software, or services, we offer reliable, innovative technology tailored to help you build and protect your digital infrastructure.

Copyright © 2026 TYONLINE TECHNOLOGY PTY. LTD. All Rights Reserved.