Fortinet Warns FortiMail Zero-Day Is Being Actively Exploited

· Original article ↗

Summary

Fortinet says attackers are exploiting a critical FortiMail flaw to write arbitrary files and execute commands. Updates are pending for several versions; admins should apply workarounds, and CISA has added the flaw to its Known Exploited Vulnerabilities catalog.

Key points

  • CVE-2026-104286 is a critical path traversal and NULL-byte handling flaw in the FortiMail management interface, rated CVSS 9.8.
  • Unauthenticated attackers can send crafted HTTP or HTTPS requests to write arbitrary files, potentially enabling code or command execution.
  • Affected versions are FortiMail 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8, and 7.2.0–7.2.9.
  • Fortinet recommends disabling IBE feature support or restricting management-interface access to trusted networks until fixes are available. FortiMail 7.2 users can upgrade to 7.4 or later.
  • Fixes are forthcoming in versions 7.4.9, 7.6.7, and 8.0.2. Fortinet has not said when exploitation began, how many appliances were compromised, or who is responsible.
  • Fortinet published file, IP-address, and log indicators to help identify potential compromise; one log example suggests an attacker may have configured remote archiving.
  • CISA added the vulnerability to its Known Exploited Vulnerability catalog and set an October 4 mitigation and forensic-triage deadline for federal agencies.

Article Details

Event Type
Active zero-day exploitation of a critical FortiMail vulnerability
Impact
CVE-2026-104286 allows unauthenticated arbitrary file writes through crafted HTTP or HTTPS requests and can lead to unauthorized code or command execution. Fortinet identified files added or modified on compromised systems. A log entry suggests an attacker may have configured an appliance to send archived data to a remote server; data transfer was not confirmed.

Indicators of compromise

TypeIndicatorContext
IPV445[.]129[.]0[.]192IP address Fortinet associated with the attacks.
IPV479[.]141[.]169[.]187IP address Fortinet associated with the attacks; a log entry identifies it as the remote server for an archive account.
SHA2564000276a150a165d3c2537d1e19fb393c4de8333076a16655e28059cae82157bHash of /data/bin/mailservice, identified as added on compromised systems.
SHA256703e97c64e61e41dc3aaba580d82bb2aa7b6a11b54ee6fb467ed5d5a3bffdef5Hash of /data/etc/httpd.conf, identified as modified on compromised systems.
SHA25677324ac428bde86d351fc5fc06f6d64a6bfe737dfb2743df1d4c5ac2418a5b6aHash of /bin/smit, identified as modified on compromised systems.
SHA2567a6cea9f5c9e2e9994d4e3c4da73f86cf5acd05ea5d312c066c9d1dafd69ee38Hash of /data/bin/webconsole, identified as added on compromised systems.
SHA2568015f34dc84922b03688399d7f9fe7a00361789f7e420c7e2a2cdb23e75cef84Hash of /data/lib/liblog.so, identified as added on compromised systems.
SHA2568953ec7960b09f544a880b072ad4e6cfda7a8303f486251d3478dcfdfbac23b6Hash of /data/etc/ld.so.preload, identified as added on compromised systems.
SHA256d6fe51c22b91776f4c961ea58bcac5917f15d560a619d7ce726d3d51795609d3Hash of /data/migadmin.tar.gz, identified as modified on compromised systems.

MITRE ATT&CK

CVE

Vendors

Products

Related Articles