Fortinet has disclosed a critical zero-day vulnerability affecting multiple supported versions of FortiMail. The vulnerability, tracked as CVE-2026-104286, can allow an unauthenticated remote attacker to write arbitrary files to the underlying FortiMail system by sending specially crafted HTTP or HTTPS requests.
The vulnerability combines a path traversal weakness (CWE-22) with improper handling of NULL bytes/characters (CWE-158). Fortinet has confirmed that the vulnerability has been exploited in the wild.
CISA added CVE-2026-104286 to its Known Exploited Vulnerabilities (KEV) Catalog on October 1, 2026. The remediation deadline for affected U.S. Federal Civilian Executive Branch systems is October 4, 2026; reporting on the KEV entry also indicates forensic triage is required for covered federal systems.
Organisations operating affected FortiMail appliances should treat this vulnerability as an immediate incident-response and remediation priority, particularly where the FortiMail management interface is accessible from untrusted networks.
CVE-2026-104286 results from insufficient restriction of filesystem paths combined with improper NULL-byte neutralisation.
An attacker does not require valid credentials or user interaction. Specially crafted requests sent over HTTP or HTTPS can result in files being written outside the intended filesystem location.
This creates a significant integrity risk on the FortiMail appliance. Fortinet's published indicators from observed attacks include added libraries and executables, modification of system configuration files, use of ld.so.preload, and changes associated with remote archiving and scheduled commands.
CWE-22: Improper Limitation of a Pathname to a Restricted Directory — Path Traversal
CWE-158: Improper Neutralization of NULL Byte or NULL Character
Confirmed Impact
Unauthenticated arbitrary file write to the underlying FortiMail system.
Successful exploitation may enable additional post-exploitation activity depending on the files written and the attack chain used. Fortinet has published indicators demonstrating that real-world compromises involved added or modified system files.
|
FortiMail Branch |
Affected Versions |
Vendor Remediation |
|
8.0 |
8.0.0 – 8.0.1 |
Upgrade to 8.0.2 or later when available |
|
7.6 |
7.6.0 – 7.6.6 |
Upgrade to 7.6.7 or later when available |
|
7.4 |
7.4.0 – 7.4.8 |
Upgrade to 7.4.9 or later when available |
|
7.2 |
7.2.0 – 7.2.9 |
Move to the 7.4 or later branch, ensuring the destination release itself contains the fix |
As of October 2, 2026, Fortinet's identified fixed builds 8.0.2, 7.6.7 and 7.4.9 were still listed as upcoming in current reporting of FG-IR-26-175.
Important: Organisations migrating from FortiMail 7.2 should not assume that simply moving to any 7.4 release removes exposure. FortiMail 7.4.0 through 7.4.8 are themselves listed as vulnerable. The destination release must be a fixed version such as 7.4.9 or later once available.
Organisations operating affected FortiMail systems should immediately identify all FortiMail appliances in their environment and confirm the exact software version running on each system. This will help determine which appliances are affected and require remediation.
The FortiMail management interface should be removed from direct Internet exposure wherever possible. Administrative access should be restricted to trusted management networks, VPN infrastructure, jump hosts, or other explicitly authorised private networks.
Administrators should also review affected appliances for Fortinet-published indicators of compromise before carrying out destructive remediation or rebuilding the system. If suspicious activity or a matching indicator of compromise is identified, relevant logs and forensic evidence should be preserved to support further investigation.
Finally, organisations should upgrade affected FortiMail appliances to the appropriate fixed release as soon as Fortinet makes the relevant update available.
Network Indicators
The following IP addresses have been associated with observed exploitation:
79.141.169[.]187
45.129.0[.]192
Security teams should review firewall, proxy, FortiMail, NetFlow and other network telemetry for communications involving these addresses.
An IOC match should be investigated in context and should not by itself be considered definitive evidence regarding the complete scope or attribution of an intrusion.
Added Files
Fortinet has reported the following files as added on compromised appliances:
/data/lib/liblog.so
/data/bin/webconsole
/data/bin/mailservice
/data/etc/ld.so.preload
Modified Files
The following files were reported as modified:
/bin/smit
/data/etc/httpd.conf
/data/migadmin.tar.gz
Published reporting reproducing Fortinet's IOC information confirms these added/modified files and the two associated IP addresses.
Security teams should also review FortiMail configuration and system logs for activity resembling the following:
archive234
79.141.169[.]187
/uploads
/migadmin
Fortinet's published attack evidence reportedly includes the archive234 remote archive configuration and /migadmin-related scheduled activity. The existence of an archive configuration does not by itself prove that email data was successfully exfiltrated, so potential data exposure should be established through forensic investigation.
Incident-Response Guidance
If any published IOC or unexplained system modification is identified:
Simply applying a workaround or eventual firmware update addresses the vulnerability but does not establish that an appliance exploited before remediation is clean.
Exposure Prioritisation
Highest priority should be given to FortiMail systems that:
Current Patch Status
At the time of this advisory, Fortinet's remediation targets are:
FortiMail 8.0 → 8.0.2 or later
FortiMail 7.6 → 7.6.7 or later
FortiMail 7.4 → 7.4.9 or later
FortiMail 7.2 → migrate to a fixed 7.4+ release
The identified fixed builds were still reported as upcoming on October 2, 2026, so organisations should verify release availability directly with Fortinet before beginning an upgrade.
If you are worried about any of the threats outlined in this bulletin or need help in determining what steps you should take to protect yourself from the most material threats facing your organisation, please contact your account manager, or alternatively get in touch to find out how you can protect your organisation.