CVE-2026-104286 carries a CVSS score of 9.8 and is being actively exploited in zero-day attacks against Fortinet's FortiMail appliances, the vendor warned in an advisory published Thursday.
CVE-2026-104286: the technical failure Fortinet described
Fortinet says the flaw affects the FortiMail management interface and stems from "An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] and Improper Neutralization of NULL Byte or NULL Character [CWE-158] vulnerability" that "may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests," the company wrote in its advisory. The vulnerability was discovered internally by Gwendal Guégniaud of Fortinet's Product Security team.
Affected FortiMail versions and Fortinet's remediation roadmap
Fortinet lists the affected releases as FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, and FortiMail 7.2.0 through 7.2.9. Fortinet states that security updates are not yet available for FortiMail 7.4, 7.6, and 8.0 branches; it identified upcoming fixed versions as FortiMail 7.4.9, 7.6.7, and 8.0.2. Fortinet advised that FortiMail 7.2 users can remediate by upgrading to the 7.4 branch or later.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleWorkarounds Fortinet recommends until patches arrive
Because the flaw is being actively exploited, Fortinet urged customers to apply its shared workarounds until updates are released. One recommended mitigation is to disable IBE feature support using the following commands:
config system encryption ibe set status disable end
As an alternative, administrators can "disable access to the FortiMail management interface from the Internet or restrict access to trusted private networks," Fortinet advised.
Indicators of compromise and sample log evidence
Fortinet published indicators of compromise (IOCs) tied to the active exploitation, including files added or modified on compromised systems and two IP addresses: 79[.]141.169.187 and 45[.]129.0.192. The advisory includes example log entries that administrators can use to find potentially compromised appliances.
Fortinet highlighted one log showing an archive account named "archive234" configured from the command line with 79.141.169.187 as the remote server and /uploads as the remote directory — a configuration that "could indicate that the attacker configured the compromised FortiMail appliance to send archived data to a remote server."
Other sample entries Fortinet provided include a cron job execution referencing /migadmin, an administrator logout event, an IBE decryption error citing "Invalid Base64 Encoding," and failed login attempts. Example events shared by Fortinet include:
- type=event subtype=system pri=debug user=system ui=cron msg="(root) CMD (/bin/sh -c 'O=/migadmin ..."
- type=kevent subtype=admin pri=information user=admin ui=(null) action=logout status=success reason=unknown msg="User admin logged out from (null)."
- type=kevent subtype=config pri=information user=admin ui=cli module=unknown submodule=unknown msg="Added 'archive234' to 'archive account' : rotation-size[50]rotation-time[1] rotation-hour[14]destination[remote]remote-ip[79.141.169.187]remote-username[archive234]remote-password[***]remote-directory[/uploads] (user: admin, from: cli)"
- FortiMail::IBE::DecrypterMediaIn::DecrypterMediaIn(...): Caught BufferException(2), BufferImpl.cpp:973, 'Invalid Base64 Encoding at pos 0. Character=0x2a'
- Internal user *@domain.tld failed to log in.
How security teams, federal agencies, and FortiMail administrators are responding
Security teams and FortiMail administrators are being asked to apply Fortinet's mitigations immediately where patching is not yet possible: disabling IBE support or removing management interface exposure to the Internet, and hunting for the IOCs and log patterns Fortinet published. Fortinet's advisory (FG-IR-26-175) supplies the specific log samples and IP addresses needed to perform that triage.
Federal agencies face an expedited timeline: CISA has added CVE-2026-104286 to its Known Exploited Vulnerability catalog and requires federal agencies to perform forensic triage and mitigate the flaw by October 4th, according to the advisory summary.
Fortinet also said it is coordinating with government organizations, including CISA, and referred requests for additional exploitation details to its advisory.
Scope, attribution, and immediate open questions
Fortinet confirmed active exploitation but has not disclosed when the flaw was first used, how many devices were compromised, or who is behind the attacks. The company provided IOCs and log artifacts to help detection and mitigation, and it emphasized that fixes will arrive in upcoming maintenance releases for affected branches.
The immediate operational realities are clear: vulnerable FortiMail appliances with management interfaces reachable from the Internet remain at risk until either the IBE workaround is applied or the appliance is upgraded to a fixed release. Federal entities must act by the October 4th CISA deadline; other operators should treat the published IOCs and log entries as actionable indicators to guide triage now.
Source: BleepingComputer — Fortinet warns of critical FortiMail flaw exploited in zero-day attacks




