FortiMail CVE-2026-104286: Unauthenticated File Write Exploited at Disclosure, With No Fixed Build Yet
Security / news
FortiMail CVE-2026-104286: Unauthenticated File Write Exploited at Disclosure, With No Fixed Build Yet
Fortinet's advisory FG-IR-26-175 lists fixes for 7.4, 7.6 and 8.0 as pending; the interim steps are disabling IBE and closing the management interface.
Fortinet disclosed CVE-2026-104286 on October 1: an unauthenticated attacker can write arbitrary files to a FortiMail appliance with crafted HTTP or HTTPS requests, and the flaw was already being exploited when the advisory went out.
Fortinet's advisory, FG-IR-26-175, was published October 1 and updated October 5, and lists the discovery method as internal and the component as the GUI. Help Net Security and The Hacker News give the CVSS score as 9.8. CISA added the flaw to its exploited-vulnerabilities catalog on October 1.
Affected versions and the missing fixes
Four release lines are affected, and none had a fixed build when the advisory appeared.
| FortiMail line | Affected | Fixed build |
|---|---|---|
| 8.0 | 8.0.0 to 8.0.1 | 8.0.2, not yet released |
| 7.6 | 7.6.0 to 7.6.6 | 7.6.7, not yet released |
| 7.4 | 7.4.0 to 7.4.8 | 7.4.9, not yet released |
| 7.2 | 7.2.0 to 7.2.9 | Move to 7.4 or later |
Fortinet's interim steps are to disable the identity-based encryption (IBE) feature from the command line and to restrict the management interface to trusted private networks. Cybersecurity Dive reported that Fortinet gave no patch timeline. Fortinet has not said how many appliances were compromised, who is behind the attacks or how many are exposed.
A Fortinet spokesperson told Cybersecurity Dive: "We are communicating with relevant government organizations, including CISA, on the content of this advisory."
Indicators of compromise
The Hacker News published Fortinet's indicator list. It names two addresses, 79.141.169[.]187 and 45.129.0[.]192, and seven paths that may have been added or changed: /data/lib/liblog.so, /data/bin/webconsole, /data/bin/mailservice, /data/etc/ld.so.preload, /bin/smit, /data/etc/httpd.conf and /data/migadmin.tar.gz.
One entry stands out. ld.so.preload forces a shared library into every process that starts on a Linux host, so a modified copy would load whatever library it names into every service launch. The list shows what Fortinet found, not how often it appeared.
Severity and the deadline
Preconditions matter more than the score. The attacker needs no account, only reachability of the vulnerable web interface, which is why the interim advice is to take the management interface off the internet. watchTowr threat specialist Yordan Ganchev told Cybersecurity Dive: "This is trivial to exploit." That is one researcher's judgement, and watchTowr is a security firm, not an independent measurement of attack volume.
Accounts of the federal deadline conflict. Help Net Security wrote that agencies had four days. CISA's own catalog file lists October 1 as the date added and October 4 as the due date, which is three days, the same window CISA applied to WordPress CVE-2026-87902. The catalog's required action asks for mitigations "in accordance with vendor instructions," so with no fixed FortiMail build the deadline could be met only through the IBE and network-access steps.
Cybersecurity Dive also reported that this follows Fortinet credential compromises in June 2026 and exploited FortiSandbox flaws the same month. Separately, our Pwn2Own Ireland 2026 day-one report covers the contest entries. For FortiMail owners the next concrete date is the release of 7.4.9, 7.6.7 or 8.0.2, none of which Fortinet had dated as of October 5.
Sources
More in Security
- 01Cling Botnet Hides Commands in the STUN Transaction ID and Spreads Through Realtek Flaw CVE-2021-35394Nozomi Networks says the malware sends traffic that resembles ordinary Google STUN replies, so defenders have to hunt for all-zero transaction IDs instead of blocking an address.
- 02Apple Fixes CoreGraphics Flaw CVE-2026-86950 in iOS 26.7.1 After Meta Reports Targeted AttacksApple's entry says a crafted file can run code and that exploitation may have hit specific people on iOS versions before iOS 27, but it names no victims and no attacker.
- 03NetScaler SAML Zero-Day CVE-2026-88779 Was Exploited Days After Two Others, and CISA's Deadline Is TodayCitrix rates the flaw 8.7 and calls it a denial of service, but a researcher's honeypot ran a downloaded binary, and appliances patched for last week's bugs need a second upgrade.
- 04Cloudflare's Open-Source Audit Skill Is at 25,900 Stars, but Its Own Post Shows 20,799 Candidates Became 7,245 Actionable FindingsThe repository trending on GitHub is the 450-line starting point. The funnel numbers in Cloudflare's June write-up describe a different system that has not been released.