NEWS

Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action

CVE-2026-104286, a critical FortiMail path traversal flaw (CVSS 9.8), is under active exploitation. No patch yet — Fortinet urges workarounds now.

Dylan H.

News Desk

October 3, 2026
8 min read
Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action

No Patch, Active Exploitation: Why FortiMail Admins Can't Wait

Fortinet and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) are jointly pressing organizations to act immediately on CVE-2026-104286, a critical-severity path traversal vulnerability in FortiMail that attackers are already exploiting in live attacks. Fortinet's advisory, FG-IR-26-175, published October 1, 2026, confirms the flaw lets an unauthenticated attacker send a crafted HTTP or HTTPS request to the FortiMail management interface and write arbitrary files to the underlying system — a capability that can be escalated into full code or command execution.

What makes this disclosure unusual is the order of events: exploitation came first, the advisory second, and a patch has not shipped for any affected branch as of publication. CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog the same day Fortinet's advisory went live, and federal civilian agencies have been given a compressed window to remediate under Binding Operational Directive 26-04. For every other organization running FortiMail, the practical message from both Fortinet and CISA is the same: treat this as an active incident, not a routine patch cycle.


Vulnerability Details

AttributeValue
CVE IDCVE-2026-104286
CVSS v3.1 Score9.8 (Critical)
Vulnerability ClassPath traversal (CWE-22) combined with improper neutralization of a NULL byte/character (CWE-158)
Affected ProductFortinet FortiMail secure email gateway
Vulnerable ComponentFortiMail's Identity-Based Encryption (IBE) web GUI
Authentication RequiredNone — unauthenticated, remotely exploitable
Primary ImpactArbitrary file write; chainable to arbitrary code/command execution
Fortinet AdvisoryFG-IR-26-175, published October 1, 2026
Exploitation StatusConfirmed exploited in the wild
CISA KEVAdded October 1, 2026
Patch StatusNot yet released for any branch at time of publication

How the Exploit Chain Works

Escaping the sandboxed directory

The flaw lives in the web interface that backs FortiMail's Identity-Based Encryption feature, which is reachable through the appliance's management GUI without a login. The IBE component is supposed to confine any file operations it performs to a safe, designated directory. CVE-2026-104286 breaks that confinement: an attacker appends repeated ../ directory traversal sequences to a request, walking the file-write operation back out of the sandboxed folder and into arbitrary locations on the underlying filesystem.

Defeating the filename check with a NULL byte

Directory traversal alone is often caught by filename validation logic that rejects suspicious paths. Here, the second half of the bug — improper neutralization of a NULL character — lets the attacker smuggle a NULL byte into the crafted filename. Many filename-validation routines treat a NULL byte as a string terminator, so the validator inspects only the portion of the string before the NULL and approves it, while the underlying file-write operation processes the full, unterminated string. The combination lets a specially crafted HTTP or HTTPS request land a file anywhere the FortiMail process has write access — with no credentials, VPN foothold, or prior compromise required.

From file write to system compromise

An arbitrary file write on its own is dangerous; chained against a mail security appliance sitting in the inbound and outbound mail path, it is severe. Writing to the right location — a library loaded by a system process, a preload configuration, or a binary in a trusted system directory — converts the primitive into persistent code execution.


Exploitation in the Wild

Fortinet and third-party researchers have published indicators of compromise consistent with hands-on-keyboard post-exploitation activity rather than opportunistic scanning:

Indicator TypeDetails
Outbound C2 IP addresses79.141.169.187 and 45.129.0.192
Library preload hijackModified /data/lib/liblog.so, used to hijack process library loading
Persistence artifactAttacker-modified /data/etc/ld.so.preload
Dropped binariesFiles named smit, webconsole, and mailservice planted in standard system directories
Data exfiltrationArchived mail data transferred off compromised appliances via FTP or SFTP to attacker infrastructure
Attack surfacePOST requests to the IBE endpoint carrying ../ traversal sequences

The pattern — library hijacking plus renamed system-looking binaries plus outbound exfiltration — indicates attackers are using the file-write primitive not just to probe FortiMail, but to establish durable footholds and pull mail contents and credentials off the appliance before defenders notice.


Affected Versions and Fix Status

FortiMail BranchAffected VersionsFixed Build
8.08.0.0 – 8.0.18.0.2 (not yet released)
7.67.6.0 – 7.6.67.6.7 (not yet released)
7.47.4.0 – 7.4.87.4.9 (not yet released)
7.27.2.0 – 7.2.9No fix planned — upgrade to 7.4 or later

Every supported FortiMail branch at the time of disclosure is affected. Administrators should treat the 7.4.9, 7.6.7, and 8.0.2 build numbers as the ones to watch for and apply the moment Fortinet publishes them, since none were available as of this writing.


Impact Assessment

Impact AreaDescription
ConfidentialityArbitrary file write enables credential theft and bulk exfiltration of stored and in-transit mail
IntegrityAttackers have modified system libraries and planted unauthorized binaries, undermining trust in the appliance's software state
AvailabilityA compromised FortiMail sits directly in the mail flow path; tampering can disrupt, delay, or silently redirect organizational email
Perimeter ExposureFortiMail is typically internet-facing by design, making an unauthenticated bug a direct bridge from the public internet into internal mail infrastructure
Regulatory/Federal UrgencyCISA's same-day KEV addition and BOD 26-04 deadline reflect confirmed active exploitation, not theoretical risk

Recommendations

For FortiMail administrators (immediate, today)

  1. Disable Identity-Based Encryption (IBE) support on every FortiMail instance until a patch is available — this directly removes the vulnerable code path.
  2. Restrict access to the FortiMail management interface so it is reachable only from trusted internal networks, not the open internet.
  3. Inventory every FortiMail deployment and version across the organization; do not assume a single appliance represents the whole footprint.
  4. Plan the upgrade path now for 7.4.9, 7.6.7, or 8.0.2, and for FortiMail 7.2.x specifically, budget for migration to the 7.4 branch or later since no fix is planned for 7.2.

For security teams

  1. Hunt for the published indicators of compromise: outbound connections to 79.141.169.187 and 45.129.0.192, unexpected modifications to /data/lib/liblog.so or /data/etc/ld.so.preload, and unfamiliar binaries named smit, webconsole, or mailservice.
  2. Review outbound FTP/SFTP traffic from mail appliances for signs of mail archive exfiltration to unrecognized destinations.
  3. Treat any confirmed compromise as a credential-reset event — assume mail contents and any stored credentials on the appliance may have been exposed.
  4. Deploy a WAF or reverse-proxy rule blocking requests to the IBE endpoint that contain ../ traversal sequences as an interim compensating control.

For end users and IT leadership

  1. Expect temporary friction if IBE is disabled — encrypted-mail workflows that depend on it will be unavailable until Fortinet ships a fix and the feature is safely re-enabled.
  2. Escalate patching this specific CVE above routine vulnerability-management cadence given confirmed in-the-wild exploitation and KEV status.
  3. Communicate to stakeholders that a perimeter mail security appliance, not just an internal workstation, may be the entry point in this incident class.

Key Takeaways

  1. CVE-2026-104286 is a CVSS 9.8 critical, unauthenticated path traversal and NULL-byte flaw in FortiMail's Identity-Based Encryption component, allowing arbitrary file writes.
  2. Exploitation in the wild was confirmed before a patch existed — Fortinet's FG-IR-26-175 advisory and CISA's KEV addition both landed on October 1, 2026, with no fixed build yet available for any branch.
  3. All four supported branches (7.2, 7.4, 7.6, 8.0) are affected; fixes are planned as 7.4.9, 7.6.7, and 8.0.2, while 7.2.x has no planned fix and requires migration.
  4. Published indicators of compromise include two attacker-controlled IPs, a hijacked library preload mechanism, and renamed system binaries used for persistence and mail exfiltration.
  5. Disabling IBE and restricting management-interface access are the only current defenses — there is no "just patch it" option yet.
  6. CISA's compressed federal remediation deadline under BOD 26-04 signals this is being treated as an active, urgent incident, not a routine advisory, and private-sector organizations should match that urgency.

Sources