← All resources

FortiMail: critical flaw exploited on your mail gateway (01/10/2026)

Published October 5, 2026 · 7 min read · CyberNovaLabs.io

On 1 October 2026 Fortinet issued an emergency advisory for a critical FortiMail flaw that is already being exploited. The appliance in question filters and relays every message you send. For an SME, email gateway security is not one more technical topic: it is the channel your quotes and invoices travel on.

In short

On 1 October 2026 Fortinet published security advisory FG-IR-26-175: a critical flaw in FortiMail, its enterprise mail gateway, rated 9.8 out of 10 on the CVSS scale, lets an unauthenticated attacker write arbitrary files to the appliance through ordinary HTTP or HTTPS requests[1]. The vendor states the flaw is already being exploited, and CERT-FR relayed the alert on 2 October 2026, citing a risk of remote code execution[2]. The US agency CISA added it to its Known Exploited Vulnerabilities catalog on 1 October, with a remediation deadline of 4 October for federal agencies[3].

The way in is the encrypted message portal

The vulnerability is tracked as CVE-2026-104286. It combines two defects: a path traversal and improper handling of the NULL character. The attacker escapes the directory they should be confined to and drops a file wherever they choose, without needing a single credential[1].

One detail deserves a director's attention more than an engineer's: the targeted component is IBE (Identity-Based Encryption), the web portal your correspondents use to read a message you sent them in « secure » mode. That is precisely the feature you switch on to better protect sensitive exchanges: quotes, contracts, accounting documents, payslips. Tellingly, the vendor's suggested workarounds include disabling IBE and restricting access to the webmail interface from the internet[1].

Affected branches and the versions that fix the flaw:

BranchAffected versionsFixed version
FortiMail 8.08.0.0 to 8.0.18.0.2 or later
FortiMail 7.67.6.0 to 7.6.67.6.7 or later
FortiMail 7.47.4.0 to 7.4.87.4.9 or later
FortiMail 7.27.2.0 to 7.2.9migrate to the 7.4 branch or later

Fortinet also published indicators of compromise: the files /data/lib/liblog.so, /data/bin/webconsole and /data/bin/mailservice added, /bin/smit, the httpd configuration and ld.so.preload modified, plus two IP addresses linked to observed attacks[4]. The practical consequence is unpleasant but clear: if the appliance was reached, patching is not enough. A fix closes the door; it does not evict whoever is already inside.

What it changes for an SME: email is also the sales channel

A mail gateway is not just another box. Everything your company sends and receives passes through it in the clear at some point. Whoever controls it gains three things at once.

They read your negotiations. Open offers, the prices you agreed to, the terms discussed with a customer or supplier. To a competitor or a data broker, that has immediate value.

They can redirect a payment. This is the costliest and most ordinary scenario: the attacker spots a pending invoice, changes the IBAN and lets the message go. Supplier fraud does not succeed because the bookkeeper was careless; it succeeds because the message genuinely came from the expected address, in the expected thread.

They can write in your name. An email leaving your own gateway passes your SPF, DKIM and DMARC authentication checks. It therefore lands in your customers' inboxes carrying your technical signature. Your correctly configured anti-spoofing protections work against you here. It is the same mechanism we described in our piece on the NetScaler flaws exploited before the patch shipped: an edge device becomes a trusted supplier of attacks the moment it flips.

Notify or not: what the texts say, country by country

Two regimes can be triggered at the same time. They are distinct and they have different recipients.

Personal data. Article 33 GDPR provides for notifying the supervisory authority within 72 hours of becoming aware of a breach where it is likely to result in a risk to the rights and freedoms of individuals; Article 34 requires informing the individuals themselves where the risk is high[6]. The competent authority is the CNIL in France, the Data Protection Authority (APD/GBA) in Belgium, the Autoriteit Persoonsgegevens in the Netherlands, the CNPD in Luxembourg. A compromised mail gateway is a serious case, because it has seen message content and not merely addresses. We set out how notification works in our analysis of the Jims data breach and an SME's notification duties.

NIS2. If your entity falls within the scope of Directive (EU) 2022/2555, Article 23 provides for an early warning within 24 hours, an incident notification within 72 hours and a final report within one month[5]. Recipients and forms depend on national transposition: the CCB in Belgium, ANSSI in France, the Cyberbeveiligingswet regime in the Netherlands, the ILR in Luxembourg. So the first question to settle is whether you are in scope at all. Our NIS2 in Belgium and cybersecurity deadlines pages answer that in a few minutes.

Both regimes apply to the entity, not to its IT provider. Outsourcing the appliance does not move the duty to notify.

If your provider runs the appliance, here is what to ask in writing

In the vast majority of SMEs, nobody internally ever logs into the mail gateway. It was installed by an IT provider or an MSP, it works, and nobody looks at it again. That is exactly the profile of a device that stays months behind on versions.

Four questions are enough, and they call for written, dated answers:

  1. Do we use FortiMail, and on exactly which version, today?
  2. If so, has the fix for our branch been applied, on what date and at what time?
  3. Were the webmail interface and the IBE portal reachable from the internet before the fix?
  4. Have the vendor's published indicators of compromise been searched for on the appliance, and with what result?

The fourth is the one people skip and the only one that really settles the matter. « We have updated » answers the patching question, not the intrusion question. NIS2 treats supply chain security as a risk management measure in its own right[5], so demanding these answers is not distrust, it is ordinary record keeping. Our supplier security questionnaire covers these points in a form you can forward as is, and our pages on NIS2 and managed IT services set out what falls on the provider itself.

To do this week

  • Monday: email your provider for the list of your Fortinet devices and their exact versions. Email, not a phone call: you want a record.
  • Tuesday: if FortiMail is present, have the fixed version for your branch applied (8.0.2, 7.6.7, 7.4.9, or migration off 7.2)[1].
  • Wednesday: while waiting for the fix, have IBE disabled and close off internet access to the webmail interface, as the vendor advises[1].
  • Thursday: have the indicators of compromise published by Fortinet searched for[4]. Where there is doubt, treat the appliance as suspect rather than clean.
  • Friday: remind accounts payable of the double-check rule — any IBAN change is verified by phone, on a known number, never on the one given in the message.
  • And once and for all: put edge devices on a dated inventory, with a named owner for updates.

The real lesson: the device nobody ever looks at

Three alerts in one week on edge devices — a remote access gateway, then a mail gateway — point to something structural rather than a bad run. Attackers are no longer trying to trick an employee: they go for the box sitting between the internet and you, the one that is permanently exposed, raises no alarm and that nobody opens.

An SME does not need a security team to defend against this. It needs three things: to know what it exposes to the internet, to know who is responsible for updating it, and to know within what time. Until those three answers exist in writing, every vendor advisory will be discovered too late. The email security check is an honest starting point: it looks at what your domain shows the outside world, in a few minutes.

At CyberNovaLabs.io

We help SMEs in the Netherlands, Belgium, France and Luxembourg answer those three questions and then keep the pace: an inventory of what is exposed, a remediation deadline agreed with the provider, and an evidence file you can hand an authority. Our cybersecurity work is set out on our cybersecurity page. If you cannot say today which mail gateway version is running in your company, that is already the answer to your question: let us talk it through.

Sources

  1. Fortinet PSIRT, FG-IR-26-175 — CVE-2026-104286, FortiMail (1er octobre 2026)
  2. CERT-FR, avis CERTFR-2026-AVI-1257 — Vulnérabilité dans Fortinet FortiMail (2 octobre 2026)
  3. CISA, Known Exploited Vulnerabilities Catalog
  4. BleepingComputer, Fortinet warns of critical FortiMail flaw exploited in zero-day attacks (1er octobre 2026)
  5. Directive (UE) 2022/2555 (NIS2), article 23 — obligations de notification
  6. Règlement (UE) 2016/679 (RGPD), articles 33 et 34 — violation de données
CyberNovaLabs.io

Qualified meetings, no lock-in.

Criteria in writing before launch, pay per meeting or monthly, stop with a simple email.

→ Get meetings booked

Read next

Newsletter · CyberNovaLabs.io

Security Briefing

One email a month: a figure from our barometer, the NIS2 and CRA dates that matter in the Netherlands, Belgium and Luxembourg, and one practical guide. In English. Unsubscribe in one click.

→ Get meetings booked