# FortiMail RCE flaw exploited in the wild

Published: 2026-10-02 · Severity: severe · Sectors: technology
Canonical: https://vorant.io/reports/4731a3dd-911c-5812-bd77-fd7f27a6bb73/fortimail-rce-flaw-exploited-in-the-wild

> CERT-FR warns that a remote code execution vulnerability in Fortinet FortiMail, CVE-2026-104286, is being actively exploited.

CERT-FR has issued an advisory regarding a remote code execution vulnerability in Fortinet FortiMail, tracked as CVE-2026-104286. The flaw affects multiple FortiMail version branches: versions after 7.2.0 and before 7.4, after 7.4.0 and before the upcoming 7.4.9, after 7.6.0 and before the upcoming 7.6.7, and after 8.0.0 and before the upcoming 8.0.2. Fortinet has confirmed the vulnerability is being actively exploited in the wild and has published indicators of compromise in its own security bulletin (FG-IR-26-175).

Successful exploitation allows an attacker to execute arbitrary code remotely on affected FortiMail systems, which are widely deployed as email security gateways and could provide attackers with a foothold into an organization's mail infrastructure. Defenders operating FortiMail should treat this as an urgent patching priority given confirmed in-the-wild exploitation.

CERT-FR directs administrators to Fortinet's security bulletin for patches and to review the published indicators of compromise to check for prior compromise. Organizations running affected FortiMail versions should apply vendor-provided fixes as soon as they become available and monitor for the IOCs referenced in Fortinet's advisory.

## Mentioned in this report

- Vulnerabilities: CVE-2026-104286 (KEV)

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1257

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/4731a3dd-911c-5812-bd77-fd7f27a6bb73/fortimail-rce-flaw-exploited-in-the-wild.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
