Fortinet Zero-Day Hits FortiMail Gateways
Fortinet reports active exploitation of a critical FortiMail flaw, with patches still pending and CISA ordering federal fixes by October 4th.
A newly disclosed critical vulnerability in Fortinet's FortiMail email security appliance is already being exploited in the wild, and for most affected versions there is no patch yet. Fortinet published an advisory on Thursday describing the flaw, tracked as CVE-2026-104286, and confirmed it is being used in zero-day attacks to execute unauthorized code or commands on vulnerable devices. The company has issued temporary workarounds while security updates are prepared, and CISA has added the bug to its Known Exploited Vulnerability catalog.
CVE-2026-104286 at a glance
The vulnerability carries a CVSS score of 9.8 and affects the FortiMail management interface. According to Fortinet's advisory, the issue combines two weaknesses: an improper limitation of a pathname to a restricted directory (path traversal, CWE-22) and improper neutralization of a NULL byte or NULL character (CWE-158). Fortinet said the flaw "may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests."
The vendor credited Gwendal Guégniaud of Fortinet's Product Security team with discovering the vulnerability internally. No external researcher or report is named in the advisory. Because the bug lives in the management interface, any FortiMail deployment that exposes that interface to untrusted networks is potentially reachable.
Affected versions and missing patches
FortiMail releases from four branches are impacted. The affected ranges are 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9. For administrators on the 7.2 branch, the fix is available now by upgrading to the 7.4 branch or later.
For the remaining branches, no security update exists yet. Fortinet lists FortiMail 7.4.9, 7.6.7, and 8.0.2 as the upcoming releases that will contain the fix. Until those versions ship, the vendor is directing customers to apply shared workarounds.
Workarounds until updates arrive
The primary mitigation is to disable IBE (Identity Based Encryption) feature support. Fortinet provides the following CLI commands to turn it off:
config system encryption ibe
set status disable
end
As an alternative, Fortinet says administrators can disable access to the FortiMail management interface from the Internet, or restrict that access to trusted private networks. Both steps are intended to reduce exposure while the permanent updates are pending.
Indicators of compromise
Fortinet also published indicators of compromise associated with the attacks, including several files that were added or modified on compromised systems. The advisory lists specific SHA-256 hashes and file paths for each artifact:
- /data/lib/liblog.so — Added — 8015f34dc84922b03688399d7f9fe7a00361789f7e420c7e2a2cdb23e75cef84
- /bin/smit — Modified — 77324ac428bde86d351fc5fc06f6d64a6bfe737dfb2743df1d4c5ac2418a5b6a
- /data/bin/webconsole — Added — 7a6cea9f5c9e2e9994d4e3c4da73f86cf5acd05ea5d312c066c9d1dafd69ee38
- /data/bin/mailservice — Added — 4000276a150a165d3c2537d1e19fb393c4de8333076a16655e28059cae82157b
- /data/etc/httpd.conf — Modified — 703e97c64e61e41dc3aaba580d82bb2aa7b6a11b54ee6fb467ed5d5a3bffdef5
- /data/etc/ld.so.preload — Added — 8953ec7960b09f544a880b072ad4e6cfda7a8303f486251d3478dcfdfbac23b6
- /data/migadmin.tar.gz — Modified — d6fe51c22b91776f4c961ea58bcac5917f15d560a619d7ce726d3d51795609d3
Fortinet also listed 79[.]141.169.187 and 45[.]129.0.192 as IP addresses associated with the attacks.
Log entries to check for
The advisory includes sample log entries administrators can use to identify potentially compromised appliances. One entry shows an archive account named archive234 being configured from the command line, with 79.141.169.187 as the remote server and /uploads as the remote directory. Other entries include a cron job executing a command related to /migadmin, an administrator logout event, an IBE decryption error due to invalid Base64 encoding, and failed login attempts. The example log events listed by Fortinet are:
type=event subtype=system pri=debug user=system ui=cron msg="(root) CMD (/bin/sh -c 'O=/migadmin ...
type=kevent subtype=admin pri=information user=admin ui=(null) action=logout status=success reason=unknown msg="User admin logged out from (null)."
type=kevent subtype=config pri=information user=admin ui=cli module=unknown submodule=unknown msg="Added 'archive234' to 'archive account' : rotation-size[50]rotation-time[1] rotation-hour[14]destination[remote]remote-ip[79.141.169.187]remote-username[archive234]remote-password[***]remote-directory[/uploads] (user: admin, from: cli)"
FortiMail::IBE::DecrypterMediaIn::DecrypterMediaIn(FortiMail::MediaIn&, const FortiMail::IBE::KeyFinder&, const FortiMail::EmailAddress&, const FortiMail::Buffer&, FortiMail::IBE::DecrypterMediaIn::Version): Caught BufferException(2), BufferImpl.cpp:973, 'Invalid Base64 Encoding at pos 0. Character=0x2a'
Internal user *@domain.tld failed to log in.
Fortinet points to advisory, CISA involvement
When BleepingComputer asked for more information about the exploitation activity, Fortinet referred customers to the advisory and said it is coordinating with government agencies, including CISA.
"Fortinet published an advisory to provide guidance regarding CVE-2026-104286 (FG-IR-26-175), including workarounds to help customers mitigate risk. Consistent with Fortinet's commitment to responsible PSIRT disclosure and public-private partnerships, we are communicating with relevant government organizations, including CISA, on the content of this advisory."
— Fortinet
Fortinet has not disclosed when the flaw was first exploited, how many systems were compromised, or who is behind the attacks. The advisory is available for reference, and the vendor maintains a PSIRT page for the issue.
Federal deadline set
CISA has added CVE-2026-104286 to the Known Exploited Vulnerability catalog. That listing requires federal agencies to perform forensic triage and mitigate the flaw by October 4th. The catalog addition is a formal signal that the vulnerability is being actively exploited and that federal networks must address it within the specified window.
What defenders should do now
For organizations running affected FortiMail versions, the immediate steps are to apply the IBE disable workaround or restrict management-interface access, then monitor for the published indicators of compromise. The file hashes and IP addresses give defenders concrete artifacts to search for across their appliances and network logs. The known log patterns — an archive account configured from the CLI, a cron job touching /migadmin, an IBE decryption error, and failed login attempts — offer additional starting points for triage.
Because patches are not yet available for the 7.4, 7.6, and 8.0 branches, administrators should plan to upgrade to FortiMail 7.4.9, 7.6.7, or 8.0.2 once those versions are released. Until then, the workarounds and monitoring guidance in the advisory are the primary defenses. Fortinet's coordination with CISA means federal agencies have a hard deadline, but private organizations should treat the same timeline as a reason to move quickly on mitigation and hunting.
Sources
- BleepingComputer Original source
Continue Reading
DIVD breach linked to agentic AI attack
Dutch bug-hunting nonprofit says AI agents exploited Zammad zero-days, stealing researcher emails in seconds.
China-Linked Group Poses as AI Policy Experts
Proofpoint says TA419 has impersonated AI policy figures and economists since at least April 2025 to steal credentials from US think tank staff.
Scammers Hijack University Emails for Fraud
Proofpoint says Nigerian scammers are using stolen .edu accounts to trick students with fake job offers and gift card schemes.