Unbiased headlines. Facts, not spin.
Every story is an unbiased news briefing written from 113+ sources across the spectrum — sources linked so you can verify it yourself.
FortiMail Zero-Day Lets Hackers Write Files With No Password, No Patch Available Yet

Fortinet published a security advisory on Thursday, October 1, 2026, warning customers that a critical flaw in its FortiMail email security gateway is being actively exploited by attackers who need zero credentials to get in.
The vulnerability, tracked as CVE-2026-104286, carries a CVSS score of 9.8 out of 10, according to Fortinet's advisory FG-IR-26-175. That score reflects what the flaw actually lets someone do: write arbitrary files onto the underlying operating system of a FortiMail appliance using nothing more than a crafted HTTP or HTTPS request. No username. No password.
How the Attack Works
Fortinet describes it as a combination of two separate bugs. One is a path traversal flaw, tracked as CWE-22, where crafted file paths escape the directory they're supposed to be confined to. The other is improper handling of NULL bytes, tracked as CWE-158, which Tech Times reported lets attackers slip past validation checks that would otherwise catch the directory escape.
Chained together, the two bugs give an unauthenticated attacker the ability to drop files directly onto the FortiMail operating system. Because FortiMail sits between an organization and every email it sends or receives, a web shell planted through this flaw puts an attacker in a position to intercept, read, or manipulate mail traffic, as Tech Times noted.
Gwendal Guégniaud of Fortinet's own Product Security team is credited with discovering and reporting the issue, according to Bleeping Computer, The Hacker News, and Help Net Security. Fortinet has not said how the exploitation was first detected, how many organizations have been hit, or who is behind the attacks. Help Net Security flagged that absence directly, writing that Fortinet "did not share details about when or where the attacks were spotted, how many systems were compromised, or who was behind them."
No Patch for Most Affected Versions
The flaw hits FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9. Fortinet has named 8.0.2, 7.6.7, and 7.4.9 as the versions that will carry the fix, but as of the advisory's publication those releases had not shipped, according to Cybersecurity News and Bleeping Computer. Customers running the 7.2 branch are told to jump to 7.4 or later, though GB Hackers pointed out that administrators need to confirm their exact build first, since earlier releases within the 7.4 branch are affected too.
Until a real patch exists, Fortinet's published workaround is to disable the product's Identity-Based Encryption feature entirely, using three commands in the command-line interface: config system encryption ibe, set status disable, end. The alternative, for anyone who can't live without IBE, is to pull the FortiMail management interface off the public internet altogether or lock it down to trusted private networks only.
What to Look For
Fortinet shared indicators of compromise for administrators to check against their own systems, including new files at /data/lib/liblog.so, /data/bin/webconsole, /data/bin/mailservice, and /data/etc/ld.so.preload, along with modifications to /bin/smit, /data/etc/httpd.conf, and /data/migadmin.tar.gz. Two IP addresses, 79.141.169.187 and 45.129.0.192, are tied to the observed activity, according to Bleeping Computer and GB Hackers. Bleeping Computer also flagged a log entry showing an attacker configuring an archive account named archive234 to route data to 79.141.169.187 over an /uploads directory, which it described as a possible sign of data exfiltration.
The Federal Deadline
CISA added CVE-2026-104286 to its Known Exploited Vulnerabilities catalog on October 1, 2026, the same day as Fortinet's advisory. The Hacker News and Help Net Security both reported that federal civilian agencies now have until October 4, 2026, to remediate. Tech Times additionally tied that deadline to Binding Operational Directive 26-04, the federal rule that forces agencies to patch known-exploited bugs on a fixed clock or answer for it.
That four-day window covers federal agencies only. Everyone else running FortiMail, hospitals, banks, law firms, any company that routes its email through a Fortinet gateway, is on its own clock, with no deadline but the one an attacker sets.
The Hacker News noted that FortiMail isn't the only edge device under active attack right now. It listed concurrent in-the-wild exploitation of flaws in Check Point, Arista VeloCloud Orchestrator, F5 BIG-IP Access Policy Manager, Cisco Catalyst SD-WAN Manager, and Citrix NetScaler products. None of the sources connected those campaigns to the FortiMail attackers, and no link between them has been established.
Fortinet has not said when fixed versions 8.0.2, 7.6.7, and 7.4.9 will actually ship. Until they do, the only real options for FortiMail customers are to turn off a feature they may depend on or cut their management interface off from the internet. Neither is a patch. Both are an admission that one doesn't exist yet.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.