Hack

FortiMail Zero-Day CVE-2026-104286 Under Active Attack

A critical FortiMail flaw lets unauthenticated attackers write arbitrary files and is being exploited in the wild.

2 October 2026  ·  4 min read  ·  Anand

FortiMail Zero-Day CVE-2026-104286 Under Active Attack

Fortinet has warned that attackers are exploiting a critical vulnerability in FortiMail, its email security gateway, as a zero-day. On October 1, 2026, the US Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities catalog. It gave federal agencies until October 4 to mitigate it, an unusually short deadline. If your business filters mail through a FortiMail appliance or VM, treat this as an emergency.

What the flaw does

The vulnerability is tracked as CVE-2026-104286, carries a CVSS score of 9.8, and is covered by Fortinet advisory FG-IR-26-175. It combines a path traversal weakness with improper handling of NULL bytes. In practice, an unauthenticated attacker can send crafted HTTP or HTTPS requests to the device and write arbitrary files on the underlying system. On an appliance, being able to write files usually leads straight to running code. Fortinet confirms that attackers have used it to run unauthorised code and commands.

The bug was found by Fortinet’s own product security team. Exploitation was already under way by the time it was disclosed.

Affected and fixed versions

Branch Affected Action
FortiMail 8.0 8.0.0 to 8.0.1 Upgrade to 8.0.2 or later
FortiMail 7.6 7.6.0 to 7.6.6 Upgrade to 7.6.7 or later
FortiMail 7.4 7.4.0 to 7.4.8 Upgrade to 7.4.9 or later
FortiMail 7.2 7.2.0 to 7.2.9 Move to a fixed 7.4 or newer release

Early reports described some of the fixed builds as still upcoming. Check the FG-IR-26-175 advisory and the Fortinet support portal to see what is available for your model today. The 7.2 branch gets no fix at all, so those devices need a branch upgrade. Plan the jump through Fortinet’s supported upgrade path rather than going straight to the newest release.

Do this today

1. Apply the workaround if you cannot patch yet

Fortinet’s interim mitigation is to disable the Identity-Based Encryption (IBE) feature from the CLI:

config system encryption ibe
    set status disable
end

If you use IBE for encrypted mail delivery, disabling it stops that service. Warn the people who rely on it before you make the change.

2. Take the management interface off the internet

The second recommended mitigation is to allow management access only from trusted private networks. Even after patching, this is good practice:

  • Turn off HTTP/HTTPS administrative access on any interface that faces the internet.
  • Use trusted host restrictions on admin accounts so logins only work from known management IPs.
  • Reach the admin interface over a VPN or a dedicated management network.

3. Patch as soon as a fixed build is available

Back up the configuration first. Then upgrade every FortiMail unit, including HA peers and any VM or cloud instances that are easy to forget.

Check whether you were already hit

Because this was a zero-day, patching is not enough on its own. Fortinet and researchers have published indicators of compromise:

  • Source IPs: 79.141.169[.]187 and 45.129.0[.]192. Search your firewall, reverse proxy and FortiMail logs for connections from these addresses.
  • Modified or added files: liblog.so, webconsole, mailservice, ld.so.preload, smit, httpd.conf and migadmin.tar.gz.
  • Configuration changes: unexpected archive accounts set up on the device. Attackers can use these to quietly collect copies of mail passing through the gateway.

A ld.so.preload entry is a classic way to load a malicious library into every process, so finding that file is a strong sign of compromise. Reviewing the archive account list is quick and needs no special access, so do it on every appliance today. If you find indicators, contact Fortinet support, preserve logs and treat all mail that passed through the gateway as potentially read. Rebuild the device from known-good firmware, then reset administrator passwords and any credentials stored on it, such as LDAP bind accounts and relay authentication.

The wider lesson for mail gateways

Mail gateways see every message, attachment and password reset link your business sends or receives. That makes them a prime target, and edge appliances from all the major vendors have been hit by the same pattern of pre-authentication bugs in their management interfaces. Some habits reduce the damage whichever vendor you use:

  • Never expose an appliance admin page to the public internet.
  • Subscribe to your vendor’s PSIRT advisories and the CISA KEV feed.
  • Send appliance logs to a separate system so an attacker on the device cannot erase them.
  • Keep a tested configuration backup so a rebuild takes hours, not days.

How TechProvidence can help

TechProvidence manages mail infrastructure for small and mid-sized businesses, from Postfix and Exim servers to filtering gateways in front of them. We can apply the workaround, plan and carry out firmware upgrades, review appliances for the published indicators, and redesign management access so admin interfaces are not reachable from the internet. To get your mail gateway checked, contact us.

Source: The Hacker News

Running into something similar?

We look after Linux servers, control panels and virtualization for businesses every day. If an update, vulnerability or outage here affects you, we can help.