Critical Fortinet FortiMail 0-Day Vulnerability Actively Exploited in Attacks
Attackers are exploiting critical FortiMail zero-day CVE-2026-104286 to write files without authentication.
Fortinet advisory FG-IR-26-175 says attackers are exploiting CVE-2026-104286, a critical FortiMail zero-day scored CVSS 9.8. Unauthenticated attackers can write files through crafted HTTP or HTTPS requests by combining path traversal (CWE-22) with improper NULL-byte handling (CWE-158). Affected releases span FortiMail 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8, and 7.2.0–7.2.9, while fixes such as 8.0.2, 7.6.7, and 7.4.9 were still upcoming. Fortinet urges disabling IBE or restricting management access and lists added files, hashes, and IPs 79.141.169.187 and 45.129.0.192. This is separate from earlier CVE-2025-32756.
- CVE-2026-104286 is CVSS 9.8 and requires no credentials.
- Crafted HTTP or HTTPS requests allow unauthorized file writes.
- Affected branches are FortiMail 8.0, 7.6, 7.4, and 7.2.
- Several fixed releases were still upcoming at disclosure.
- Fortinet published file paths, hashes, and two IP indicators.
Vulnerabilities mentionedAll →
- CVE-2025-327569.830%Stack-based overflow RCE in Fortinet FortiMail, FortiVoice, FortiNDR, FortiFonepublished · Fortinet FortiMail KEV
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| ipv4 | 79.141.169.187 | e account named archive234 , configured to send archives to 79.141.169.187 under /uploads . This entry deserves investigation alongsid |
Full article625 words · extracted from cybersecuritynews.com · click to collapse
Fortinet has warned that attackers are actively exploiting a critical FortiMail zero-day vulnerability, putting exposed email security systems at risk. Tracked as CVE-2026-104286, the flaw carries a CVSS score of 9.8 and allows attackers without login credentials to write files on affected devices through specially crafted HTTP or HTTPS requests.
Fortinet published advisory FG-IR-26-175 on October 1, 2026, and urged customers to apply workarounds immediately. Security fixes for several affected branches were still listed as upcoming releases at disclosure, making prompt action important for organizations running vulnerable systems.
FortiMail 0-Day Vulnerability
The vulnerability combines two weaknesses: path traversal, tracked as CWE-22, and improper handling of NULL bytes, tracked as CWE-158. Path traversal involves file paths escaping their intended directory. Here, Fortinet says crafted web requests can allow unauthorized file writes on the underlying system.
This is more serious than a simple login problem. An attacker does not need an account to exploit the flaw, and unauthorized file writes can undermine the integrity of a security appliance. However, Fortinet has not publicly explained the full attack chain, identified the attackers, or disclosed how many organizations were affected.
Gwendal Guégniaud of Fortinet’s Product Security team discovered and reported the issue internally. The advisory confirms exploitation in the wild and lists no virtual patch, so administrators should not wait for additional attack details before reducing exposure.
Affected and Patched Versions
The affected releases are FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9. Fortinet lists upcoming versions 8.0.2, 7.6.7, and 7.4.9, or later releases, as fixes for the corresponding branches.
For FortiMail 7.2, the vendor recommends moving to branch 7.4 or later. Administrators should select a fixed release rather than assume that every version in those branches is safe, because earlier 7.4 builds are also affected.
The recommended workaround disables IBE feature support. Administrators should enter config system encryption ibe, then set status disable, followed by end in the command-line interface. Alternatively, Fortinet recommends removing internet access to the FortiMail management interface or restricting access to trusted private networks.
Indicators Security Teams Should Check
Fortinet lists added files at /data/lib/liblog.so, /data/bin/webconsole, /data/bin/mailservice, and /data/etc/ld.so.preload. It also identifies changes to /bin/smit, /data/etc/httpd.conf, and /data/migadmin.tar.gz. The advisory provides MD5 and SHA256 hashes for checking these files against the reported indicators.
Two IP addresses appear in the indicators: 79[.]141.169.187 and 45[.]129.0.192. One suspicious configuration log shows an archive account named archive234, configured to send archives to 79.141.169.187 under /uploads. This entry deserves investigation alongside file changes and other unusual activity.
Other listed clues include root cron commands referencing /migadmin, an admin logout with a null interface value, IBE decryption errors reporting invalid Base64 data, and failed internal-user logins. These entries should be assessed together rather than treated as standalone proof of compromise.
Cybersecurity News previously covered CVE-2025-32756, a separate Fortinet zero-day affecting FortiMail and other products, with exploitation confirmed against FortiVoice. That earlier incident should not be confused with this new flaw.
Organizations should apply the current workaround, preserve relevant logs, and investigate matching indicators. Closing public management access limits exposure but does not establish whether an appliance was already compromised.
Follow Fortinet’s advisory for fixed-release availability and updated guidance. Teams should also review unexpected account changes and outbound connections when assessing whether the listed activity occurred locally.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.