Skip to main content
Emerging ThreatsMalware & Ransomware

Fortinet FortiMail Zero-Day Flaw Exploited in Attacks

Rack-mounted network device with blinking lights in a data center setting.

CVE-2026-104286 — a Fortinet FortiMail flaw rated CVSS 9.8 — allows unauthenticated attackers to write arbitrary files to affected systems and has been observed in active exploitation, the vendor and U.S. federal authorities report.

CVE-2026-104286: how Fortinet describes the bug

Fortinet said the flaw combines a path traversal and a NULL-byte handling error. In its advisory the company wrote: "An improper limitation of a pathname to a restricted directory ('path traversal') [CWE-22] and improper neutralization of NULL byte or NULL character [CWE-158] vulnerability may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests." That capability — unauthenticated arbitrary file writes — is why the bug carries a near-maximum CVSS score of 9.8 and why Fortinet acknowledged that it has been exploited in the wild.

Products and upgrade paths Fortinet named

The vendor published the specific FortiMail versions affected and the upgrade branches customers should move to:

  • FortiMail 8.0.0 through 8.0.1 — upgrade to upcoming 8.0.2 or above
  • FortiMail 7.6.0 through 7.6.6 — upgrade to upcoming 7.6.7 or above
  • FortiMail 7.4.0 through 7.4.8 — upgrade to upcoming 7.4.9 or above
  • FortiMail 7.2.0 through 7.2.9 — upgrade to branch 7.4 or above

Fortinet credited Gwendal Guégniaud of the Fortinet Product Security team with discovering and reporting the flaw.

Indicators of compromise and observed filesystem artifacts

Fortinet shared indicators of compromise tied to the in-the-wild activity. Two IP addresses were listed:

  • 79.141.169[.]187
  • 45.129.0[.]192

Fortinet also published a short list of files that were added or modified on exploited systems. Observed additions included:

  • /data/lib/liblog.so
  • /data/bin/webconsole
  • /data/bin/mailservice
  • /data/etc/ld.so.preload

Files noted as modified included /bin/smit, /data/etc/httpd.conf, and /data/migadmin.tar.gz. These artifacts were presented as evidence of active compromise in affected FortiMail deployments.

CISA KEV listing and the Federal Civilian Executive Branch deadline

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-104286 to its Known Exploited Vulnerabilities (KEV) catalog on Thursday after reports of active exploitation. CISA recommended Federal Civilian Executive Branch (FCEB) agencies apply the patch or the vendor-provided workarounds by October 4, 2026.

The bulletin placed this FortiMail zero-day alongside a string of other products that have seen in-the-wild exploitation in recent weeks, naming Check Point (CVE-2026-85102 and CVE-2026-93616), Arista VeloCloud Orchestrator (CVE-2026-93952), F5 BIG-IP Access Policy Manager (CVE-2026-94127), Cisco Catalyst SD-WAN Manager (CVE-2026-76504), and Citrix NetScaler ADC and NetScaler Gateway (CVE-2026-88771 and CVE-2026-88772).

Fortinet workarounds and what this means for FCEB agencies, technologists, and customers

Fortinet urged customers to apply fixes when available and to implement temporary mitigations for certain versions until those fixes are released. The vendor supplied two specific mitigations:

  • Disable IBE feature support with the CLI command: config system encryption ibe set status disable end
  • Disable access to the FortiMail management interface from the internet or restrict access only from trusted private networks

For FCEB agencies, the CISA listing establishes an operational deadline: the agency recommended applying patches or the above workarounds by October 4, 2026. For security teams and operations engineers, the combined presence of active exploitation plus published indicators — IPs and filesystem artifacts — gives both immediate detection handles and an urgency to apply the vendor's mitigations or upgrades. Fortinet customers were explicitly urged to follow the upgrade guidance to the named upcoming releases or branches until vendor-fixed versions are available.

The overlap of an exploited zero-day, a near-critical-severity CVSS score, and a CISA KEV designation compresses the response window. Fortinet has identified the technical root cause, supplied mitigations and upgrade targets, and shared indicators; CISA has set a firm remediation recommendation for FCEB agencies. Whether the upcoming 8.0.2, 7.6.7 and 7.4.9 fixes will reach all affected users before the October 4 FCEB timeline is the immediate question left by these facts.

Original story