Fortinet Warns FortiMail Zero-Day Is Being Actively Exploited

Summary
Fortinet says attackers are exploiting a critical FortiMail flaw to write arbitrary files and execute commands. Updates are pending for several versions; admins should apply workarounds, and CISA has added the flaw to its Known Exploited Vulnerabilities catalog.
Key points
- CVE-2026-104286 is a critical path traversal and NULL-byte handling flaw in the FortiMail management interface, rated CVSS 9.8.
- Unauthenticated attackers can send crafted HTTP or HTTPS requests to write arbitrary files, potentially enabling code or command execution.
- Affected versions are FortiMail 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8, and 7.2.0–7.2.9.
- Fortinet recommends disabling IBE feature support or restricting management-interface access to trusted networks until fixes are available. FortiMail 7.2 users can upgrade to 7.4 or later.
- Fixes are forthcoming in versions 7.4.9, 7.6.7, and 8.0.2. Fortinet has not said when exploitation began, how many appliances were compromised, or who is responsible.
- Fortinet published file, IP-address, and log indicators to help identify potential compromise; one log example suggests an attacker may have configured remote archiving.
- CISA added the vulnerability to its Known Exploited Vulnerability catalog and set an October 4 mitigation and forensic-triage deadline for federal agencies.
Article Details
- Event Type
- Active zero-day exploitation of a critical FortiMail vulnerability
- Impact
- CVE-2026-104286 allows unauthenticated arbitrary file writes through crafted HTTP or HTTPS requests and can lead to unauthorized code or command execution. Fortinet identified files added or modified on compromised systems. A log entry suggests an attacker may have configured an appliance to send archived data to a remote server; data transfer was not confirmed.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| IPV4 | 45[.]129[.]0[.]192 | IP address Fortinet associated with the attacks. |
| IPV4 | 79[.]141[.]169[.]187 | IP address Fortinet associated with the attacks; a log entry identifies it as the remote server for an archive account. |
| SHA256 | 4000276a150a165d3c2537d1e19fb393c4de8333076a16655e28059cae82157b | Hash of /data/bin/mailservice, identified as added on compromised systems. |
| SHA256 | 703e97c64e61e41dc3aaba580d82bb2aa7b6a11b54ee6fb467ed5d5a3bffdef5 | Hash of /data/etc/httpd.conf, identified as modified on compromised systems. |
| SHA256 | 77324ac428bde86d351fc5fc06f6d64a6bfe737dfb2743df1d4c5ac2418a5b6a | Hash of /bin/smit, identified as modified on compromised systems. |
| SHA256 | 7a6cea9f5c9e2e9994d4e3c4da73f86cf5acd05ea5d312c066c9d1dafd69ee38 | Hash of /data/bin/webconsole, identified as added on compromised systems. |
| SHA256 | 8015f34dc84922b03688399d7f9fe7a00361789f7e420c7e2a2cdb23e75cef84 | Hash of /data/lib/liblog.so, identified as added on compromised systems. |
| SHA256 | 8953ec7960b09f544a880b072ad4e6cfda7a8303f486251d3478dcfdfbac23b6 | Hash of /data/etc/ld.so.preload, identified as added on compromised systems. |
| SHA256 | d6fe51c22b91776f4c961ea58bcac5917f15d560a619d7ce726d3d51795609d3 | Hash of /data/migadmin.tar.gz, identified as modified on compromised systems. |