SecuFocus
BriefAnnouncements

FortiMail: the fix is not published yet

On 1 October 2026, Fortinet published FG-IR-26-175. An unauthenticated attacker can write files through webmail. The fix versions are listed as upcoming. Until then, Fortinet says to turn IBE off or cut Internet access to webmail.

Illustration, not a FortiMail screenshot.

Original AI-generated illustration · SecuFocus

At a glance

Key points

The CVE number does not say what to do. The fix is not published yet. The workaround is.

What changed

On 1 October 2026, Fortinet published FG-IR-26-175, CVE-2026-104286. A path traversal combined with improper handling of a null byte may let an unauthenticated attacker write files on the system through HTTP or HTTPS requests. Fortinet says the flaw has been exploited. CISA added it to the Known Exploited Vulnerabilities catalog the same day.

The branches named are 8.0.0 through 8.0.1, with a fix announced as 8.0.2 or above; 7.6.0 through 7.6.6, announced as 7.6.7 or above; 7.4.0 through 7.4.8, announced as 7.4.9 or above; 7.2.0 through 7.2.9, move to the 7.4 branch or above. Fortinet writes “upcoming”. On 3 October 2026 those version numbers are not presented as already available to download.

What you can do before the fix

Until then, Fortinet asks you to disable IBE. In the interface: Encryption, then IBE, then IBE Service off. The advisory also gives three CLI lines: config system encryption ibe, set status disable, end.

Two other options are on the same page. Close Internet access to the webmail interface, or limit it to a trusted private network. If a web application firewall already sits in front of FortiMail, block POST requests to /ibe that contain ../ .

Fortinet also publishes two IP addresses and log lines. They stay on the advisory. This note does not replay them.

What we did not check

We do not have a FortiMail appliance, and we did not test the workaround. “Exploited” comes from Fortinet, then from the CISA addition. It is not a SecuFocus test. We do not confirm that 8.0.2, 7.6.7 or 7.4.9 is already available to download.

The choice

If FortiMail webmail can be reached from the Internet, apply the workaround before waiting for a version number. Then reread the Fortinet advisory: that is where the fix will be named, once it exists.

Check and explore

Sources for this article

Numbers connect each reference to the passages that use it. Dates show when the documentation was consulted.

This article draws on the sources above. The exercises are for you to try on your devices; SecuFocus does not present them as tests carried out by its editorial team. Interfaces and features can change. Method and corrections.

Cite this article

Keep this reference with the article when you save or share it.