NEWS

Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes

CISA added FortiMail flaw CVE-2026-104286 (CVSS 9.8) to its KEV catalog after active exploitation; no patch yet, only workarounds.

Dylan H.

News Desk

October 3, 2026
7 min read
Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes

CISA Adds Actively Exploited FortiMail Zero-Day to KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a critical Fortinet FortiMail vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on October 1, 2026, following confirmed reports of active, in-the-wild exploitation. The flaw, tracked as CVE-2026-104286 and carrying a maximum-severity CVSS score of 9.8, combines a path-traversal weakness with a NULL-byte neutralization flaw to let a completely unauthenticated attacker write arbitrary files to the underlying FortiMail operating system via crafted HTTP or HTTPS requests to the management interface.

Fortinet published its own advisory, FG-IR-26-175, on October 1, 2026, crediting discovery to Gwendal Guégniaud of the Fortinet Product Security team. Unlike most KEV additions, this one arrived with no fixed firmware build yet available — Fortinet has published only interim workarounds while patched versions remain in development, leaving administrators to rely on mitigations rather than a straightforward upgrade.


Vulnerability Details

AttributeValue
CVE IDCVE-2026-104286
CVSS Score9.8 (Critical) — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE ClassificationCWE-22 (Path Traversal) and CWE-158 (Improper Neutralization of NULL Byte/Character)
Affected ProductFortinet FortiMail
Affected Versions8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8, 7.2.0–7.2.9
Fixed Versions8.0.2, 7.6.7, 7.4.9 — all listed by Fortinet as "upcoming," not yet released as of this writing
Attack VectorCrafted HTTP/HTTPS requests to the FortiMail management interface, no authentication required
Fortinet AdvisoryFG-IR-26-175
CISA KEV AddedOctober 1, 2026
Federal Remediation DeadlineOctober 4, 2026 (per Binding Operational Directive 22-01)
Exploitation StatusConfirmed active exploitation in the wild

How It Worked

The Vulnerability Mechanism

CVE-2026-104286 stems from two chained weaknesses in how FortiMail's web-facing components — tied to the Identity-Based Encryption (IBE) feature's GUI — process file paths supplied in incoming requests. An improper limitation of a pathname to a restricted directory (CWE-22, path traversal) lets an attacker escape the directory a request should be confined to, while an improper neutralization of NULL byte or NULL character (CWE-158) allows truncation tricks that bypass path-sanitization checks layered on top of the traversal protection. Combined, the two flaws let an attacker who has never authenticated to the appliance write files anywhere the FortiMail process has permission to write, simply by sending specially crafted HTTP or HTTPS requests to the exposed management interface.

Because the vulnerability requires no credentials, no user interaction, and no prior access, and because successful exploitation yields full read/write/availability impact on the underlying system, Fortinet and CISA both treat this as a direct path to complete device compromise rather than a narrow information-disclosure bug.

Observed Exploitation and Indicators of Compromise

Fortinet's advisory and subsequent reporting describe attackers using the file-write primitive to drop and modify a consistent set of files on compromised FortiMail appliances, which administrators can use for forensic triage:

PathStatus
/data/lib/liblog.soAdded
/data/bin/webconsoleAdded
/data/bin/mailserviceAdded
/data/etc/ld.so.preloadAdded
/bin/smitModified
/data/etc/httpd.confModified
/data/migadmin.tar.gzModified

Two IP addresses have been associated with the observed activity: 79.141.169[.]187 and 45.129.0[.]192. Investigators also flagged a suspicious archived-mail account named archive234 tied to the first IP, which attackers appear to have used to stage or exfiltrate mail data from compromised systems. Fortinet has not attributed the activity to a specific named threat actor or disclosed how many organizations have been compromised, and the company says it is coordinating directly with government partners, including CISA, on the advisory's contents.

Why There's No Patch Yet

As of this article's publication, Fortinet has not shipped the fixed builds (8.0.2, 7.6.7, 7.4.9) referenced in FG-IR-26-175 — they remain listed as upcoming. In the interim, Fortinet's guidance is limited to two workarounds: disabling the IBE feature in the FortiMail GUI, or restricting access to the FortiMail management interface so only trusted, internal IP ranges can reach it. Neither step is a complete fix for organizations that depend on IBE in production, which leaves a meaningful window of exposure for internet-facing appliances that cannot simply turn the feature off.


Impact Assessment

Impact AreaDescription
System CompromiseUnauthenticated arbitrary file write can lead to full remote code execution and complete device takeover
Mail Infrastructure RiskFortiMail sits at the perimeter of organizational email flow — compromise exposes inbound/outbound mail, archived messages, and potentially downstream trust relationships
No Patch AvailableFixed firmware (7.4.9, 7.6.7, 8.0.2) is not yet released; organizations must rely on workarounds, not an upgrade path
Federal ExposureCISA's KEV addition and the October 4, 2026 deadline mean FCEB agencies running affected versions are under binding, time-boxed remediation pressure
Detection ComplexityExploitation leaves identifiable but non-obvious artifacts (modified system binaries, added shared libraries) that routine monitoring may miss without specific IOC hunting
Broad Version ExposureAffects four separate release branches (7.2.x through 8.0.x), covering a large share of currently deployed FortiMail estates

Recommendations

For FortiMail Administrators

  • Immediately determine whether any FortiMail appliance is running an affected version: 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8, or 7.2.0–7.2.9
  • Apply Fortinet's interim workarounds now: disable the Identity-Based Encryption (IBE) GUI feature where it is not business-critical, and restrict management-interface access to trusted internal IP ranges only — do not expose the FortiMail admin GUI to the open internet
  • Monitor Fortinet's advisory FG-IR-26-175 and apply the fixed firmware (7.4.9, 7.6.7, or 8.0.2) the moment it ships
  • Treat any FortiMail appliance with internet-facing management access as presumed-exposed until mitigations are confirmed in place

For Security Teams

  • Hunt immediately for the published indicators of compromise: unexpected presence of /data/lib/liblog.so, /data/bin/webconsole, /data/bin/mailservice, or /data/etc/ld.so.preload, and unexplained modifications to /bin/smit, /data/etc/httpd.conf, or /data/migadmin.tar.gz
  • Search outbound and inbound connection logs for traffic to or from 79.141.169[.]187 and 45.129.0[.]192
  • Audit FortiMail mail-archive accounts for unfamiliar entries resembling archive234, and review archive-access logs for anomalous bulk retrieval
  • If any IOC matches are found, treat the appliance as compromised: isolate it, rotate all credentials and API keys it held, and perform a full forensic image before remediation
  • Extend monitoring to any systems trusting FortiMail for mail relay or SSO-adjacent integrations, given the appliance's perimeter position

For Federal Agencies (FCEB)

  • CISA's Known Exploited Vulnerabilities catalog entry carries a binding remediation deadline of October 4, 2026 under Binding Operational Directive 22-01
  • Agencies running affected FortiMail versions must apply mitigations or take the device offline by the deadline regardless of whether a permanent patch has shipped
  • Document compensating controls (IBE disablement, network access restriction) if the fixed firmware is not yet available at the deadline, and reassess as soon as Fortinet ships 7.4.9, 7.6.7, or 8.0.2

Key Takeaways

  1. CVE-2026-104286 is a maximum-severity (CVSS 9.8) unauthenticated arbitrary file-write flaw in Fortinet FortiMail, chaining CWE-22 path traversal with a CWE-158 NULL-byte neutralization bypass.
  2. CISA added the flaw to its KEV catalog on October 1, 2026 based on confirmed active exploitation, setting an October 4, 2026 remediation deadline for federal agencies.
  3. No fixed firmware is available yet — Fortinet lists versions 7.4.9, 7.6.7, and 8.0.2 as upcoming, meaning current guidance is limited to workarounds (disabling IBE, restricting management-interface access).
  4. Observed attacks leave identifiable indicators of compromise, including specific added/modified files (liblog.so, webconsole, mailservice, ld.so.preload) and two associated IP addresses.
  5. Affected versions span four release branches — 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8, and 7.2.0–7.2.9 — representing broad exposure across currently deployed FortiMail estates.
  6. Organizations should prioritize IOC hunting and management-interface lockdown immediately; waiting for a patch is not currently a viable remediation path.

Sources