NoticiasNews

FortiMail: zero-day crítico CVE-2026-104286 ya se explota y aún no tiene parche para todas las versionesFortiMail critical zero-day CVE-2026-104286 is under active exploitation, with patches not yet out for every branch

2026-10-04

El 2 de octubre de 2026, Fortinet advirtió sobre una vulnerabilidad crítica en FortiMail, su pasarela de seguridad de correo, identificada como CVE-2026-104286 y con una puntuación CVSS de 9.8. Según el reporte de Help Net Security, el fallo combina un recorrido de rutas (path traversal) con una neutralización incorrecta de caracteres nulos, y permite que un atacante sin autenticación escriba archivos arbitrarios en el sistema mediante solicitudes HTTP o HTTPS manipuladas.

Qué versiones están afectadas

  • FortiMail 8.0.0 a 8.0.1
  • FortiMail 7.6.0 a 7.6.6
  • FortiMail 7.4.0 a 7.4.8
  • FortiMail 7.2.0 a 7.2.9

Las versiones corregidas anunciadas son 8.0.2, 7.6.7 y 7.4.9, pero según la fuente aún no estaban publicadas al momento del aviso. La falla ya se explota en ataques reales y la CISA fijó el 4 de octubre como fecha límite para las agencias federales de EE. UU.

Qué hacer mientras llega el parche

  • Deshabilitar el cifrado basado en identidad (IBE) mediante la línea de comandos, como recomienda Fortinet.
  • Bloquear o restringir el acceso desde internet a la interfaz de administración.
  • Quienes usan la rama 7.2 deben planificar el salto a 7.4 o superior.

Por qué importa más allá del equipo de TI

El correo corporativo sigue siendo la puerta de entrada de gran parte de la operación: reclamos de clientes, solicitudes de soporte y comunicaciones con reguladores pasan por ahí. Un dispositivo de borde comprometido puede exponer ese tráfico. Es la misma lección de otros fallos recientes en equipos de perímetro: inventariar, limitar la exposición de las consolas de administración y tener un plan de contingencia cuando el parche todavía no existe.

En TEKFENIX diseñamos nuestras soluciones pensando en que el canal de atención no dependa de un único punto frágil. Servigo365 centraliza solicitudes multicanal con trazabilidad por ticket, y CumplimientoControl mantiene el registro auditable de lo que ocurre con la información regulatoria, de modo que un incidente en un componente no deje a la empresa sin evidencia ni continuidad. Si quiere revisar la exposición de sus sistemas de soporte y cumplimiento, hablemos.

Fuente: Help Net Security (2 de octubre de 2026), con datos del aviso de Fortinet.

On October 2, 2026, Fortinet warned of a critical flaw in FortiMail, its email security gateway, tracked as CVE-2026-104286 with a CVSS score of 9.8. According to Help Net Security, the bug combines path traversal with improper neutralization of null characters, allowing an unauthenticated attacker to write arbitrary files on the system through crafted HTTP or HTTPS requests.

Affected versions

  • FortiMail 8.0.0 to 8.0.1
  • FortiMail 7.6.0 to 7.6.6
  • FortiMail 7.4.0 to 7.4.8
  • FortiMail 7.2.0 to 7.2.9

Fixed versions announced are 8.0.2, 7.6.7 and 7.4.9, but per the source they were not yet released at the time of the advisory. The flaw is already exploited in real attacks and CISA set October 4 as the deadline for US federal agencies.

What to do until the patch arrives

  • Disable identity-based encryption (IBE) via the CLI, as Fortinet recommends.
  • Block or restrict internet access to the management interface.
  • Teams on the 7.2 branch should plan a move to 7.4 or later.

Why it matters beyond IT

Corporate email remains the entry point for much of daily operations: customer complaints, support requests and regulator communications all flow through it. A compromised edge appliance can expose that traffic. It is the same lesson as other recent perimeter-device flaws: keep an inventory, limit exposure of admin consoles, and have a contingency plan when no patch exists yet.

At TEKFENIX we design our solutions so the service channel does not depend on a single fragile point. Servigo365 centralizes multichannel requests with per-ticket traceability, and CumplimientoControl keeps an auditable record of regulatory information, so an incident in one component does not leave a company without evidence or continuity. If you want to review the exposure of your support and compliance systems, let's talk.

Source: Help Net Security (October 2, 2026), citing Fortinet's advisory.

← Volver al blog← Back to blog