Fortinet warns of critical FortiMail flaw exploited in zero-day attacks
At a glance
- Severity
- Critical
- Used in attacks
- Yes, 1 of 1 flaw named
- Flaws named
- CVE-2026-104286
- Vendors and products
- Fortinet
- Reported by
- 1 outlet
Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices.
The vulnerability is rated critical, with a CVSS score of 9.8, and affects the FortiMail management interface.
"An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] and Improper Neutralization of NULL Byte or NULL Character [CWE-158] vulnerability may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests," Fortinet said in an advisory published Thursday.
Gwendal Guégniaud of Fortinet's Product Security team discovered the vulnerability internally, and it affects FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, and FortiMail 7.2.0 through 7.2.9.
Fortinet says the flaw is being actively exploited and is urging customers to apply the shared workarounds until a security update can be installed.
FortiMail 7.2 users can patch the vulnerability by upgrading to the 7.4 branch or later. For affected FortiMail 7.4, 7.6, and 8.0 installations, security updates are not yet available, with Fortinet listing FortiMail 7.4.9, 7.6.7, and 8.0.2 as upcoming versions containing the fix.
Until patched versions are available, Fortinet says admins can mitigate the flaw by disabling IBE feature support using the following commands:
config system encryption ibe
set status disable
end
As an alternative workaround, administrators can disable access to the FortiMail management interface from the Internet or restrict access to trusted private networks.
Fortinet also published indicators of compromise (IOCs) associated with the attacks, including several files that were added or modified on compromised systems.
| File | Status | SHA-256 |
|---|---|---|
/data/lib/liblog.so |
Added | 8015f34dc84922b03688399d7f9fe7a00361789f7e420c7e2a2cdb23e75cef84 |
/bin/smit |
Modified | 77324ac428bde86d351fc5fc06f6d64a6bfe737dfb2743df1d4c5ac2418a5b6a |
/data/bin/webconsole |
Added | 7a6cea9f5c9e2e9994d4e3c4da73f86cf5acd05ea5d312c066c9d1dafd69ee38 |
/data/bin/mailservice |
Added | 4000276a150a165d3c2537d1e19fb393c4de8333076a16655e28059cae82157b |
/data/etc/httpd.conf |
Modified | 703e97c64e61e41dc3aaba580d82bb2aa7b6a11b54ee6fb467ed5d5a3bffdef5 |
/data/etc/ld.so.preload |
Added | 8953ec7960b09f544a880b072ad4e6cfda7a8303f486251d3478dcfdfbac23b6 |
/data/migadmin.tar.gz |
Modified | d6fe51c22b91776f4c961ea58bcac5917f15d560a619d7ce726d3d51795609d3 |
Fortinet also listed 79[.]141.169.187 and 45[.]129.0.192 as IP addresses associated with the attacks.
The advisory also includes log entries that administrators can use to identify potentially compromised appliances.
One of those entries shows an archive account named archive234 being configured from the command line with 79.141.169.187 as the remote server and /uploads as the remote directory. This could indicate that the attacker configured the compromised FortiMail appliance to send archived data to a remote server.
Other log entries include a cron job executing a command related to /migadmin, an administrator logout event, an IBE decryption error due to invalid Base64 encoding, and failed login attempts.
Example log events shared by Fortinet are listed below:
type=event subtype=system pri=debug user=system ui=cron msg="(root) CMD (/bin/sh -c 'O=/migadmin ...
- type=kevent subtype=admin pri=information user=admin ui=(null) action=logout status=success reason=unknown msg="User admin logged out from (null)."
- type=kevent subtype=config pri=information user=admin ui=cli module=unknown submodule=unknown msg="Added 'archive234' to 'archive account' : rotation-size[50]rotation-time[1] rotation-hour[14]destination[remote]remote-ip[79.141.169.187]remote-username[archive234]remote-password[***]remote-directory[/uploads] (user: admin, from: cli)"
- FortiMail::IBE::DecrypterMediaIn::DecrypterMediaIn(FortiMail::MediaIn&, const FortiMail::IBE::KeyFinder&, const FortiMail::EmailAddress&, const FortiMail::Buffer&, FortiMail::IBE::DecrypterMediaIn::Version): Caught BufferException(2), BufferImpl.cpp:973, 'Invalid Base64 Encoding at pos 0. Character=0x2a'
- Internal user *@domain.tld<mailto:*@domain.tld> failed to log in.
Fortinet has not disclosed when the flaw was first exploited, how many systems were compromised, or who is behind the attacks.
When BleepingComputer asked for more information about the exploitation activity, Fortinet referred customers to the advisory and said it is coordinating with government agencies, including CISA.
"Fortinet published an advisory to provide guidance regarding CVE-2026-104286 (FG-IR-26-175), including workarounds to help customers mitigate risk," Fortinet told BleepingComputer.
"Consistent with Fortinet’s commitment to responsible PSIRT disclosure and public-private partnerships, we are communicating with relevant government organizations, including CISA, on the content of this advisory."
CISA has now added the CVE-2026-104286 flaw to the Known Exploited Vulnerability catalog and requires federal agencies to perform forensic triage and mitigate the flaw by October 4th.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Originally published by BleepingComputer. © BleepingComputer. Written by Lawrence Abrams.
Vulnerabilities referenced
- CVE-2026-104286Not scored yet
Fortinet FortiMail
Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
Used in attacksAdded to CISA's list 2026-10-01
Full record →
Fastnexa security experts
This story involves a flaw attackers are already using. Are you exposed?
A Fastnexa penetration tester can check whether CVE-2026-104286 or anything like it can be used against your websites, apps and network.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →
Coverage
One outlet has carried this so far.
2026-10-01 22:42 UTC
Related stories
- Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes
The Hacker News · 2026-10-02 · exploited
- Alleged KillSec Ransomware Mastermind a 16-Year-Old
Dark Reading · 2026-10-01
- AI agents hacked the hackers, stealing email addresses from security research org
The Register · 2026-10-01
- Autonomous AI agents tried to hack US, Canadian government websites
BleepingComputer · 2026-10-01
- Microsoft says threat actors are ahead in the early AI race
BleepingComputer · 2026-10-01