DEV Community

kozhevniko
kozhevniko

Posted on

FortiMail on the Open Internet: 3,911 Fingerprints and 5,322 Title Matches for a Mail Gateway Under Active Exploitation

FortiMail on the Open Internet: 3,911 Fingerprints and 5,322 Title Matches for a Mail Gateway Under Active Exploitation

FortiMail is a secure email gateway: it inspects inbound mail, enforces policy and stores message data. Fortinet's advisory FG-IR-26-175 covers a 9.8 path-traversal file-write flaw, CVE-2026-104286, and CISA added it to the Known Exploited Vulnerabilities catalog on 1 October 2026. The question a ZoomEye count can answer is narrower and more useful than a severity score: how many FortiMail instances are observable, and what does that number imply about the reachable population?

Context and method

Two queries were run against the ZoomEye index:

  • app="FortiMail" returned 3,911 matches.
  • title="FortiMail" returned 5,322 matches. Both figures are global index totals recorded on 4 October 2026. The app fingerprint relies on product identification from observable service responses, while the title match relies on the returned page title. Neither query is a census of deployed appliances, because an appliance behind a strict firewall, a reverse proxy, or an authenticated portal may not be observable at all. The two numbers differ because they measure different signals, and a host can match one and not the other. Treat each as an observation of an exposed subset.

What the numbers suggest

3,911 app-fingerprinted instances is a small population by the standards of large internet-facing products, and that is roughly what one would expect for a mail security gateway. It is also an internet-facing, high-value device: by design it accepts mail and exposes an administrative interface. The gap between 3,911 and 5,322 is itself informative. Hosts that match on title but not on app fingerprint are either running a variant the fingerprint does not identify, or are fronted by something that changes the response a scanner sees.
The relevant risk is not the raw count. It is the fraction of that population that is internet-reachable with the administrative interface exposed and the vulnerable firmware in place. The count establishes that a reachable population exists. Firmware inventory inside your own estate establishes your exposure.

Implications and next steps

For defenders, the count is a reminder to check whether your own FortiMail appears in public scan data, and whether its administrative interface is restricted to trusted networks. If it is internet-reachable, that is the same precondition the exploitation guidance targets.
ZoomEye's value in this workflow is verification. A query for app="FortiMail" or title="FortiMail" gives an external view of what is publishing a FortiMail identity, which is useful when an internal asset inventory is incomplete. Pair the external count with firmware version checks from the management console, because the index cannot read your version.

References

  • Fortinet, FG-IR-26-175
  • CISA, Known Exploited Vulnerabilities catalog entry for CVE-2026-104286
  • ZoomEye host search, queries app="FortiMail" (3,911) and title="FortiMail" (5,322), retrieved 4 October 2026

Top comments (0)