Threat Advisories

Critical security advisory: Fortinet FortiMail Zero-Day actively exploited

Written by Integrity360 | Oct 2, 2026, 2:07:23 PM

Fortinet has disclosed a critical zero-day vulnerability affecting multiple supported versions of FortiMail. The vulnerability, tracked as CVE-2026-104286, can allow an unauthenticated remote attacker to write arbitrary files to the underlying FortiMail system by sending specially crafted HTTP or HTTPS requests.

The vulnerability combines a path traversal weakness (CWE-22) with improper handling of NULL bytes/characters (CWE-158). Fortinet has confirmed that the vulnerability has been exploited in the wild.

CISA added CVE-2026-104286 to its Known Exploited Vulnerabilities (KEV) Catalog on October 1, 2026. The remediation deadline for affected U.S. Federal Civilian Executive Branch systems is October 4, 2026; reporting on the KEV entry also indicates forensic triage is required for covered federal systems.

Organisations operating affected FortiMail appliances should treat this vulnerability as an immediate incident-response and remediation priority, particularly where the FortiMail management interface is accessible from untrusted networks.

Vulnerability Details

CVE-2026-104286 results from insufficient restriction of filesystem paths combined with improper NULL-byte neutralisation.

An attacker does not require valid credentials or user interaction. Specially crafted requests sent over HTTP or HTTPS can result in files being written outside the intended filesystem location.

This creates a significant integrity risk on the FortiMail appliance. Fortinet's published indicators from observed attacks include added libraries and executables, modification of system configuration files, use of ld.so.preload, and changes associated with remote archiving and scheduled commands.

Weakness Classification

CWE-22: Improper Limitation of a Pathname to a Restricted Directory — Path Traversal

CWE-158: Improper Neutralization of NULL Byte or NULL Character

Confirmed Impact

Unauthenticated arbitrary file write to the underlying FortiMail system.

Successful exploitation may enable additional post-exploitation activity depending on the files written and the attack chain used. Fortinet has published indicators demonstrating that real-world compromises involved added or modified system files.

 

Affected Versions

FortiMail Branch

Affected Versions

Vendor Remediation

8.0

8.0.0 – 8.0.1

Upgrade to 8.0.2 or later when available

7.6

7.6.0 – 7.6.6

Upgrade to 7.6.7 or later when available

7.4

7.4.0 – 7.4.8

Upgrade to 7.4.9 or later when available

7.2

7.2.0 – 7.2.9

Move to the 7.4 or later branch, ensuring the destination release itself contains the fix

As of October 2, 2026, Fortinet's identified fixed builds 8.0.2, 7.6.7 and 7.4.9 were still listed as upcoming in current reporting of FG-IR-26-175.

Important: Organisations migrating from FortiMail 7.2 should not assume that simply moving to any 7.4 release removes exposure. FortiMail 7.4.0 through 7.4.8 are themselves listed as vulnerable. The destination release must be a fixed version such as 7.4.9 or later once available.

Immediate required actions

Organisations operating affected FortiMail systems should immediately identify all FortiMail appliances in their environment and confirm the exact software version running on each system. This will help determine which appliances are affected and require remediation.

The FortiMail management interface should be removed from direct Internet exposure wherever possible. Administrative access should be restricted to trusted management networks, VPN infrastructure, jump hosts, or other explicitly authorised private networks.

Administrators should also review affected appliances for Fortinet-published indicators of compromise before carrying out destructive remediation or rebuilding the system. If suspicious activity or a matching indicator of compromise is identified, relevant logs and forensic evidence should be preserved to support further investigation.

Finally, organisations should upgrade affected FortiMail appliances to the appropriate fixed release as soon as Fortinet makes the relevant update available.

Indicators of Compromise

Network Indicators

The following IP addresses have been associated with observed exploitation:

79.141.169[.]187

45.129.0[.]192

Security teams should review firewall, proxy, FortiMail, NetFlow and other network telemetry for communications involving these addresses.

An IOC match should be investigated in context and should not by itself be considered definitive evidence regarding the complete scope or attribution of an intrusion.

Added Files

Fortinet has reported the following files as added on compromised appliances:

/data/lib/liblog.so

/data/bin/webconsole

/data/bin/mailservice

/data/etc/ld.so.preload

Modified Files

The following files were reported as modified:

/bin/smit

/data/etc/httpd.conf

/data/migadmin.tar.gz

Published reporting reproducing Fortinet's IOC information confirms these added/modified files and the two associated IP addresses.

Additional Suspicious Activity

Security teams should also review FortiMail configuration and system logs for activity resembling the following:

  • Creation or modification of an archive account named

archive234

  • Archive configuration referencing:

 79.141.169[.]187

 /uploads

  • Root cron or scheduled commands referencing:

 /migadmin

  • Unexpected administrator logout activity, including anomalous or null interface values.
  • IBE-related decryption failures or unusual Base64 decoding errors.
  • Unexpected failed internal-user authentication attempts.

Fortinet's published attack evidence reportedly includes the archive234 remote archive configuration and /migadmin-related scheduled activity. The existence of an archive configuration does not by itself prove that email data was successfully exfiltrated, so potential data exposure should be established through forensic investigation.

Incident-Response Guidance

If any published IOC or unexplained system modification is identified:

  1. Treat the FortiMail appliance as potentially compromised.
  2. Preserve system, administrative, mail, network and security logs.
  3. Preserve relevant files and their cryptographic hashes.
  4. Capture current configuration and account information.
  5. Restrict the appliance from untrusted networks.
  6. Investigate outbound connections and remote archive configuration.
  7. Review whether credentials or secrets accessible to the appliance may have been exposed.
  8. Rotate affected administrative, integration and service credentials where appropriate.
  9. Determine whether email content or other information may have been accessed or transferred.
  10. Follow Fortinet's incident-response and recovery recommendations before returning the appliance to production.

Simply applying a workaround or eventual firmware update addresses the vulnerability but does not establish that an appliance exploited before remediation is clean.

Exposure Prioritisation

Highest priority should be given to FortiMail systems that:

  • Run one of the affected versions.
  • Expose the management interface to the Internet or other untrusted networks.
  • Have IBE enabled.
  • Show connections involving published IOC addresses.
  • Contain any of the identified added or modified files.
  • Show unexpected archive configuration, scheduled commands or administrator activity.

Current Patch Status

At the time of this advisory, Fortinet's remediation targets are:

FortiMail 8.0 → 8.0.2 or later

FortiMail 7.6 → 7.6.7 or later

FortiMail 7.4 → 7.4.9 or later

FortiMail 7.2 → migrate to a fixed 7.4+ release

The identified fixed builds were still reported as upcoming on October 2, 2026, so organisations should verify release availability directly with Fortinet before beginning an upgrade.

 

If you are worried about any of the threats outlined in this bulletin or need help in determining what steps you should take to protect yourself from the most material threats facing your organisation, please contact your account manager, or alternatively get in touch to find out how you can protect your organisation.