Security · October 8, 2026
Critical zero-day vulnerability in FortiMail exploited in attacks
The Cybersecurity and Infrastructure Security Agency (CISA) added a critical vulnerability affecting Fortinet FortiMail to its catalog of Known Exploited Vulnerabilities on Thursday, following reports of active exploitation. The vulnerability, registered as CVE-2026-104286 (CVSS 9.8), allows unauthenticated attackers to write arbitrary files to the underlying system.
The flaw combines insufficient path name validation with improper null byte neutralization, enabling an unauthenticated attacker to write arbitrary files to the system through specially crafted HTTP or HTTPS requests. Affected versions include FortiMail 8.0.0 to 8.0.1, 7.6.0 to 7.6.6, 7.4.0 to 7.4.8, and 7.2.0 to 7.2.9. Fortinet acknowledged that the vulnerability has been exploited in the wild and urged customers to implement mitigations until fixes are available for certain versions.
Recommended mitigations include disabling IBE feature support with the CLI command "config system encryption ibe / set status disable / end" and disabling access to the FortiMail management interface from the internet or restricting it to trusted private networks. Fortinet credited Gwendal Guégniaud from the Fortinet Product Security team for discovering and reporting the flaw. The company shared indicators of compromise, including IP addresses 79.141.169[.]187 and 45.129.0[.]192, along with files added like /data/lib/liblog.so, /data/bin/webconsole, /data/bin/mailservice, and /data/etc/ld.so.preload, and modified files such as /bin/smit, /data/etc/httpd.conf, and /data/migadmin.tar.gz.