Your email could be hijacked today – critical FortiMail flaw under active attack

Your email could be hijacked today – critical FortiMail flaw under active attack
If your business relies on an on‑premise email security gateway such as FortiMail, you could be staring at ransomware, data loss, or a hijacked inbox right now. A vulnerability that lets attackers write files to the server without any credentials has been confirmed to be exploited in the wild. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added it to its Known Exploited Vulnerabilities (KEV) catalog, which is a clear signal: patch now or face serious consequences.
Critical FortiMail flaw – what it does and why it matters
How this email‑security vulnerability impacts small businesses
FortiMail is a device that sits between the internet and your mail server, scanning incoming and outgoing messages for spam, phishing, and malware. The newly discovered flaw (CVE‑2026‑104286, CVSS 9.8) (CVE‑2026‑104286 is the public identifier security researchers use for this flaw) lets anyone on the internet send a specially crafted web request that tricks the system into writing files wherever they want on the underlying operating system. In everyday terms, it’s like giving a stranger a master key to your office and letting them place a malicious program on any desk they choose.
Why does that matter for your business?
- Ransomware risk – An attacker could drop ransomware directly onto the mail server, encrypting all stored messages and potentially spreading to other systems.
- Data loss – Malicious files could delete or corrupt stored emails, which many small businesses rely on for contracts, invoices, and customer communication.
- Credential theft – By planting a back‑door, attackers can later capture login details for your email accounts, giving them ongoing access.
The vulnerability affects several FortiMail versions that many small‑business owners still run:
| Affected versions | Recommended upgrade |
|---|---|
| 8.0.0 – 8.0.1 | Upgrade to 8.0.2 or newer |
| 7.6.0 – 7.6.6 | Upgrade to 7.6.7 or newer |
| 7.4.0 – 7.4.8 | Upgrade to 7.4.9 or newer |
| 7.2.0 – 7.2.9 | Upgrade to any 7.4 branch or newer |
If you cannot upgrade immediately, Fortinet has published two short‑term work‑arounds that can be applied from the command line:
- Disable the IBE feature (the built‑in encryption support that is not needed for most small businesses):
config system encryption ibe set status disable end - Block internet access to the FortiMail management interface – only allow connections from trusted internal IP addresses or a VPN. This removes the direct path attackers use to send the malicious request.
These steps buy you time, but they are not a substitute for the official patch.
Urgent three‑step checklist
-
Verify your FortiMail version
Log into the device or ask your IT provider to check the “System Information” page. If you see any version listed in the table above, you are at risk. -
Apply the patch or work‑around right away
If a patch is available: download it from the Fortinet support portal and follow the upgrade guide.
If a patch is not yet released for your version: run the two work‑arounds immediately and schedule the upgrade as soon as the fix arrives. -
Consider a managed email security service
Maintaining on‑premise gateways requires regular updates, monitoring, and expertise that many small‑business owners simply do not have. A managed service handles patching, monitoring, and threat response for you, letting you focus on running your bakery, clinic, or shop without worrying about the inbox.
- Why patch now? CISA has placed this flaw on its Known Exploited Vulnerabilities (KEV) list, meaning attackers are already using it in the wild.
Frequently asked questions
Q: How do I know if my small‑business email security is vulnerable to the critical FortiMail flaw?
A: Most FortiMail devices have a web‑based admin console. Log in with your admin credentials, go to System → Dashboard → System Information. The version number is displayed at the top. If you cannot log in, ask the person who set up the system (often a local IT consultant) to run the check for you.
Q: I don’t have an IT department. How can I check the FortiMail version myself?
A: Most FortiMail devices have a web‑based admin console. Log in with your admin credentials, go to System → Dashboard → System Information. The version number is displayed at the top. If you cannot log in, ask the person who set up the system (often a local IT consultant) to run the check for you.
Q: Will disabling IBE affect my ability to send encrypted emails?
A: IBE is an optional feature that many small businesses do not use. Disabling it will not impact standard TLS encryption that protects email in transit. If you rely on IBE for a specific workflow, discuss alternatives with your email provider before turning it off.
Q: Is moving to a cloud‑based email security service expensive?
A: Costs vary, but most providers offer tiered pricing based on the number of users. For a small business, the monthly fee is often lower than the hidden costs of managing hardware, applying patches, and dealing with a potential breach. Ask for a quote that matches your current user count.
Keep your inbox safe – let us help
Dealing with a critical FortiMail flaw can feel overwhelming, especially when you’re focused on serving customers and growing your business. At IT Move NL we specialize in Security & Protection for small businesses. Whether you need us to:
- Apply the latest FortiMail patches and verify the work‑arounds are correctly configured,
- Harden your email gateway by restricting management access and disabling unnecessary features, or
- Migrate to a fully managed email security solution that removes the maintenance burden entirely,
we’re here to make the process painless. A quick, no‑obligation review takes less than an hour, and you’ll walk away with a clear action plan.
Don’t wait for an attack to happen. Contact IT Move NL today, and let us secure your email before the next malicious request lands in your inbox.
Sources:

He/Him · AWS Certified Solutions Architect | Cloud Engineer @ Essent
Cloud Engineer at Essent B.V. with 10+ years of experience in the tech industry. AWS Certified, passionate about serverless architectures, Infrastructure as Code, and DevOps. Proficient in TypeScript, Python, and Terraform. Based in Amersfoort, Netherlands.
STAY IN THE LOOP
// Cloud, AI & DevOps insights — straight to your inbox.
No spam. Unsubscribe anytime.
// Related articles
Need help with your cloud infrastructure?
Our team of experts is ready to help you navigate the complexities of modern cloud architecture.
Get in Touch