Fortinet confirmed active exploitation of a critical path-traversal flaw in the FortiMail management interface. An unauthenticated attacker who can reach that interface can write arbitrary files to the appliance — and CISA’s federal due date is Saturday, October 4, with forensic triage required.
Patches for several trains are still upcoming. Until they land, Friday morning is the window to pull management off the internet, disable IBE if you can, and hunt Fortinet’s published indicators before the weekend clock.
Your secure-mail appliance is also a management plane. Attackers already treat it that way.
The 5-Minute Cyber BriefDon’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
What happened
On October 1, 2026, Fortinet published FG-IR-26-175 for CVE-2026-104286. The bug combines path traversal (CWE-22) with improper null-byte handling (CWE-158) in the FortiMail GUI. Crafted HTTP or HTTPS requests from an unauthenticated attacker can write arbitrary files on the underlying system and execute unauthorized code or commands. Fortinet rates it critical (CVSS 9.8) and says the flaw is being exploited in the wild. The issue was discovered internally by Gwendal Guégniaud of Fortinet Product Security.
Affected releases: FortiMail 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8, and 7.2.0–7.2.9. FortiMail 7.2 can move to the 7.4 branch or later. Fixed builds for 7.4 / 7.6 / 8.0 are listed as upcoming: 7.4.9, 7.6.7, and 8.0.2.
Until those builds ship, Fortinet’s workaround is to disable Identity-Based Encryption (IBE) support, or disable / restrict internet access to the FortiMail management interface to trusted private networks only. CISA added CVE-2026-104286 to KEV the same day and ordered federal civilian agencies to perform forensic triage and mitigate by October 4, 2026 under BOD 26-04.
Why it matters
FortiMail sits on the email perimeter and often exposes a management path that operators treat as “internal.” Unauthenticated file write on that path is a foothold into the mail stack — credentials, archives, and outbound relays included. Fortinet published concrete IoCs: planted libraries and binaries under /data, a modified /bin/smit, an ld.so.preload hook, archive accounts pointing at attacker IPs, and cron activity around /migadmin.
The Saturday federal clock is a useful forcing function even outside government. Workarounds first; patches when they land; hunt as if compromise is plausible.
What to do first
- Inventory every FortiMail. List appliances and VMs on 8.0.x, 7.6.x, 7.4.x, and 7.2.x. Note which ones expose the management GUI to the internet.
- Apply the workaround today. Prefer pulling management off the public internet (trusted private networks / jump hosts only). If IBE is not required, disable it:
config system encryption ibe→set status disable→end. - Plan the upgrade path. Move 7.2 fleets toward 7.4+. Watch for FortiMail 7.4.9 / 7.6.7 / 8.0.2 and schedule the cutover as soon as builds are available.
- Hunt Fortinet’s IoCs. Check for the published SHA-256 hashes under
/data/lib/liblog.so,/data/bin/webconsole,/data/bin/mailservice,/data/etc/ld.so.preload, modified/bin/smitandhttpd.conf, and archive accounts aimed at 79.141.169.187 or 45.129.0.192. - Preserve evidence before wipe/rebuild. BOD 26-04 expects forensic triage. Snapshot configs and relevant logs if compromise is suspected, then rotate credentials and certificates tied to the appliance.
Forward this
If you own email security or FortiMail: Fortinet confirmed active exploitation of an unauthenticated management-interface file-write bug (CVE-2026-104286). CISA’s federal due date is Saturday, October 4. Please confirm every FortiMail management GUI is off the public internet (or IBE is disabled), that Fortinet’s published IoCs were checked, and that an upgrade to a fixed build is scheduled the moment 7.4.9 / 7.6.7 / 8.0.2 ship.
Details
- CVE: CVE-2026-104286 (FortiMail path traversal + null-byte → arbitrary file write)
- Impact: Unauthenticated remote file write / unauthorized code or command execution via management GUI
- CVSS: 9.8 (Fortinet)
- Advisory: FG-IR-26-175 (Oct 1, 2026)
- KEV: Added Oct 1, 2026; federal due date Oct 4, 2026; BOD 26-04 forensic triage Yes
- Affected: FortiMail 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8, 7.2.0–7.2.9
- Fixed / upcoming: 7.2 → move to 7.4+; upcoming 7.4.9, 7.6.7, 8.0.2
- Workaround: Disable IBE, or restrict management interface to trusted private networks
- IoC hint: planted
/databinaries,ld.so.preload, archive234 → attacker IPs, cron around/migadmin
Hunt / verify
- Confirm management GUI reachability is limited to approved jump networks.
- Hash-check the Fortinet IoC file list; review
httpd.confandld.so.preloadfor unexpected entries. - Search system and kevent logs for archive accounts with remote destinations, admin logout events from
(null), IBE Base64 decode errors, and cron jobs invoking/migadmin. - Block outbound to 79.141.169.187 and 45.129.0.192 pending investigation.
Slack paste: FortiMail CVE-2026-104286 actively exploited — pull management off the internet / disable IBE today, hunt Fortinet IoCs, federal due Sat Oct 4, upgrade when 7.4.9 / 7.6.7 / 8.0.2 land.
Sources
- Fortinet PSIRT: FG-IR-26-175 (CVE-2026-104286)
- BleepingComputer: Fortinet warns of critical FortiMail flaw exploited in zero-day attacks (Oct 1, 2026)
- CISA Known Exploited Vulnerabilities Catalog (CVE-2026-104286)
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.