Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes
At a glance
- Severity
- Critical
- Used in attacks
- Yes, 1 of 1 flaw named
- Flaws named
- CVE-2026-104286
- Vendors and products
- Fortinet
- Industries
- Government
- Reported by
- 1 outlet
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation.
The vulnerability, tracked as CVE-2026-104286 (CVSS score: 9.8), allows unauthenticated attackers to write arbitrary files on the underlying system.
"An improper limitation of a pathname to a restricted directory ('path traversal') [CWE-22] and improper neutralization of NULL byte or NULL character [CWE-158] vulnerability may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests," Fortinet said in an advisory.
The vulnerability impacts the following versions -
- FortiMail 8.0.0 through 8.0.1 (Upgrade to upcoming 8.0.2 or above)
- FortiMail 7.6.0 through 7.6.6 (Upgrade to upcoming 7.6.7 or above)
- FortiMail 7.4.0 through 7.4.8 (Upgrade to upcoming 7.4.9 or above)
- FortiMail 7.2.0 through 7.2.9 (Upgrade to branch 7.4 or above)
Fortinet has acknowledged that the vulnerability has been exploited in the wild, urging customers to apply the following workarounds until fixes are available for certain versions -
- Disable IBE feature support using the following CLI command:
config system encryption ibe set status disable end
- Disable access to the FortiMail management interface from the internet or restrict access only from trusted private networks.
Fortinet credited Gwendal Guégniaud of the Fortinet Product Security team with discovering and reporting the flaw. It has shared the following indicators of compromise -
-
IP addresses -
- 79.141.169[.]187
- 45.129.0[.]192
-
Files -
- /data/lib/liblog.so (added)
- /data/bin/webconsole (added)
- /data/bin/mailservice (added)
- /data/etc/ld.so.preload (added)
- /bin/smit (modified)
- /data/etc/httpd.conf (modified)
- /data/migadmin.tar.gz (modified)
In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies are recommended to apply the patch or workarounds by October 4, 2026.
The development comes as number of security flaws in Check Point (CVE-2026-85102 and CVE-2026-93616), Arista VeloCloud Orchestrator (CVE-2026-93952), F5 BIG-IP Access Policy Manager (CVE-2026-94127), Cisco Catalyst SD-WAN Manager (CVE-2026-76504), and Citrix NetScaler ADC and NetScaler Gateway (CVE-2026-88771 and CVE-2026-88772) have come under in-the-wild exploitation.
Originally published by The Hacker News. © The Hacker News. Written by info@thehackernews.com (The Hacker News).
Vulnerabilities referenced
- CVE-2026-104286Not scored yet
Fortinet FortiMail
Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
Used in attacksAdded to CISA's list 2026-10-01
Full record →
Fastnexa security experts
This story involves a flaw attackers are already using. Are you exposed?
A Fastnexa penetration tester can check whether CVE-2026-104286 or anything like it can be used against your websites, apps and network.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →
Coverage
One outlet has carried this so far.
2026-10-02 05:49 UTC
Related stories
- Fortinet warns of critical FortiMail flaw exploited in zero-day attacks
BleepingComputer · 2026-10-01 · exploited
- Alleged KillSec Ransomware Mastermind a 16-Year-Old
Dark Reading · 2026-10-01
- AI agents hacked the hackers, stealing email addresses from security research org
The Register · 2026-10-01
- Autonomous AI agents tried to hack US, Canadian government websites
BleepingComputer · 2026-10-01
- Microsoft says threat actors are ahead in the early AI race
BleepingComputer · 2026-10-01