Fortinet Confirms FortiMail Flaw CVE-2026-104286 Is Under Attack
Security / news
Fortinet Confirms FortiMail Flaw CVE-2026-104286 Is Under Attack
An unauthenticated path traversal in the appliance's identity-based encryption service lets an attacker write files to the host, and Fortinet's own indicators show a root cron job and a rogue archive account.
An unauthenticated attacker who can reach a FortiMail appliance's webmail service over HTTP or HTTPS can write arbitrary files to the host, and Fortinet says that is already happening. The flaw, CVE-2026-104286, is a tracking number for one specific bug, rated 9.8 out of 10 on the CVSS severity scale. It affects FortiMail 7.2, 7.4, 7.6 and 8.0.
Fortinet published advisory FG-IR-26-175 on Oct. 1, 2026, and CISA added the flaw to its Known Exploited Vulnerabilities catalog the same day, according to Help Net Security. Federal civilian agencies were told to apply the fix or the workaround by Oct. 4.
What the flaw does and what it needs
The advisory lists two weakness types: path traversal (CWE-22) and improper handling of NULL bytes (CWE-158). Fortinet credits Gwendal Guégniaud of its Product Security team with finding it internally, per The Hacker News. The advisory marks the attack as unauthenticated, known exploited, and rated critical, with no virtual patch available.
The precondition is reachability. Fortinet's workarounds all point at the IBE service, FortiMail's identity-based encryption feature, and at the /ibe request path, so an appliance that exposes that webmail path to untrusted networks is the one to worry about. The advisory's listed impact is execution of unauthorized code or commands.
The score matches the vector here. Network access, no credentials and no user interaction is the worst case for a device that sits on the edge, and the dropped shared library described below shows the attackers got further than a file write.
Affected versions and fixes
| Branch | Affected | Fix listed in advisory |
|---|---|---|
| FortiMail 8.0 | 8.0.0 to 8.0.1 | 8.0.2 or later |
| FortiMail 7.6 | 7.6.0 to 7.6.6 | 7.6.7 or later |
| FortiMail 7.4 | 7.4.0 to 7.4.8 | 7.4.9 or later |
| FortiMail 7.2 | 7.2.0 to 7.2.9 | Move to 7.4 or later |
The fixed builds were described as upcoming when The Hacker News and Help Net Security published on Oct. 2. The advisory page I fetched shows a solution update on Oct. 5 and a last update on Oct. 7 that clarified FortiMail Cloud, which Fortinet fixed itself, so cloud customers need no action. The page does not say on what date each fixed build shipped, and I did not verify that independently.
What the attackers left behind
Fortinet published indicators of compromise, and they describe a hands-on intrusion rather than a drive-by scan. Help Net Security lists the files added: /data/lib/liblog.so, /data/bin/webconsole, /data/bin/mailservice and /data/etc/ld.so.preload. The ld.so.preload entry is how a malicious shared library gets loaded into every process. Modified files include /bin/smit, /data/etc/httpd.conf and /data/migadmin.tar.gz.
The advisory's log indicators include a cron entry that runs a shell command as root, an admin logout, and a CLI entry that adds an archive account named "archive234" that pushes data to a remote host. The two IP addresses it names are 79.141.169.187 and 45.129.0.192.
The archive account matters more than the shared library. An account that pushes data to a remote host means patching alone does not answer whether data left the appliance.
What to do before the patch
Until a fixed build is installed, Fortinet's advisory gives three options. Turn off IBE support: in the GUI, Encryption, then IBE, then IBE Service, set to off. Restrict webmail access to trusted private networks. Or, if a web application firewall sits in front, block POST requests to /ibe that contain ../.
The CLI form of the first option is garbled on the advisory page I fetched, so follow the GUI path or copy the command from Fortinet's page directly. Operators who find any of the files above should treat the appliance as compromised, not merely vulnerable.
Fortinet has not named a threat actor, said how many appliances were hit, or said when exploitation began. This is also not the only edge device in the queue: The Hacker News listed exploited flaws in Check Point, Arista VeloCloud Orchestrator, F5 BIG-IP APM, Cisco Catalyst SD-WAN Manager and Citrix NetScaler in the same period. For another exploited flaw on a different vendor's platform, see The Terminal's report on the Apple CoreGraphics zero-day, and for a botnet built on Realtek-based devices, the Cling botnet report.
The date to watch is the next revision of FG-IR-26-175, which should confirm the shipping date of 7.4.9, 7.6.7 and 8.0.2.
Sources
More in Security
- 01CISA Gave Agencies Three Days for Five 2015-2023 Bugs, and Four Come With a Forensic Triage OrderThe October 8 additions to the exploited-vulnerabilities catalogue show how BOD 26-04 has changed what a deadline means: the patch is the smaller job.
- 02Apple's CoreGraphics Zero-Day CVE-2026-86950 Has a CISA Deadline of October 13, Not the October 2 Being ReportedTrade coverage gives a three-day federal deadline. The catalogue entry itself carries 14 days and no forensic-triage flag.
- 03Rejetto HFS CVE-2026-61500, Found With Anthropic's Mythos, Was Probed One Day After DisclosureA predictable session-signing key lets an unauthenticated attacker forge an HFS admin cookie and run server-side JavaScript; HFS 3.2.1 has carried the fix since July.
- 04Exchange CVE-2026-96940 Lets Any Mailbox User Read Others' Mail, and Patched Servers Need V2Microsoft's out-of-band September V2 update closes an 8.8-rated authorization flaw in on-premises Exchange, with four KBs and a support cliff for 2016 and 2019.