FortiMail Zero-Day Gives Unauthenticated Attackers a Route to System File Writes

FortiMail zero-day CVE-2026-104286 (CVSS 9.8) enables unauthenticated file writes. Affected versions, fixes, workarounds and IOCs.

FortiMail Zero-Day Gives Unauthenticated Attackers a Route to System File Writes
Vulnerabilities

Illustrative image generated with AI

Listen to this articleAudio edition · 8 min

A critical vulnerability in Fortinet FortiMail is being exploited against Internet-accessible management interfaces, according to a report published on October 1, 2026.

Tracked as CVE-2026-104286 and internally as FG-IR-26-175, the flaw can allow an unauthenticated attacker to write arbitrary files to the appliance’s underlying operating system. BleepingComputer reports that observed attacks used the weakness to run unauthorized code or commands.

The vulnerability carries a CVSS score of 9.8. Fortinet credited Product Security team member Gwendal Guégniaud with discovering it internally.

Crafted web requests can escape the intended file path

CVE-2026-104286 affects the FortiMail management interface. Fortinet classifies the underlying problems as path traversal, identified as CWE-22, and improper handling of a NULL byte or character, identified as CWE-158.

An attacker can send crafted HTTP or HTTPS requests that cause the appliance to write files outside the location intended by the application. No authentication is required.

Its CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. This describes a remotely reachable vulnerability with low attack complexity, no required privileges and no user interaction. Successful exploitation can have a high impact on confidentiality, integrity and availability.

Arbitrary file writing is the vulnerability’s documented primitive. Depending on where and what an attacker writes, that capability can alter application behavior or introduce executable components. The October 1 report characterizes the activity it examined as enabling unauthorized command or code execution.

That distinction matters: Fortinet’s vulnerability description establishes the unauthenticated file-write condition, while the reported attack evidence describes how exploitation manifested on affected appliances.

Four supported FortiMail branches contain vulnerable builds

The affected version ranges are:

FortiMail branch Vulnerable versions
8.0 8.0.0 through 8.0.1
7.6 7.6.0 through 7.6.6
7.4 7.4.0 through 7.4.8
7.2 7.2.0 through 7.2.9

For FortiMail 7.2, Fortinet’s reported guidance is to upgrade to the 7.4 branch or later. Administrators should read that branch-level recommendation together with the fixed-build information: versions through 7.4.8 are affected, while 7.4.9 was listed as an upcoming corrected release.

For affected installations on the 7.4, 7.6 and 8.0 branches, the report said fixes were not yet available. Fortinet identified these planned fixed versions:

  • FortiMail 7.4.9
  • FortiMail 7.6.7
  • FortiMail 8.0.2

Until an appropriate fixed release is available and deployed, Fortinet recommends disabling IBE support:

config system encryption ibe
set status disable
end

The alternative workaround is to remove Internet access from the FortiMail management interface. Where remote administration remains necessary, access should be restricted to trusted private networks.

Administrators should avoid treating network filtering as evidence that an appliance is clean. Systems that were previously exposed still require investigation for the published indicators.

Files, hashes and network indicators support compromise hunting

Fortinet supplied several file indicators associated with the reported activity. Some represent added files, while others are modified versions of existing paths.

File Reported status SHA-256
/data/lib/liblog.so Added 8015f34dc84922b03688399d7f9fe7a00361789f7e420c7e2a2cdb23e75cef84
/bin/smit Modified 77324ac428bde86d351fc5fc06f6d64a6bfe737dfb2743df1d4c5ac2418a5b6a
/data/bin/webconsole Added 7a6cea9f5c9e2e9994d4e3c4da73f86cf5acd05ea5d312c066c9d1dafd69ee38
/data/bin/mailservice Added 4000276a150a165d3c2537d1e19fb393c4de8333076a16655e28059cae82157b
/data/etc/httpd.conf Modified 703e97c64e61e41dc3aaba580d82bb2aa7b6a11b54ee6fb467ed5d5a3bffdef5
/data/etc/ld.so.preload Added 8953ec7960b09f544a880b072ad4e6cfda7a8303f486251d3478dcfdfbac23b6
/data/migadmin.tar.gz Modified d6fe51c22b91776f4c961ea58bcac5917f15d560a619d7ce726d3d51795609d3

The attack-associated IP addresses are:

  • 79[.]141.169.187
  • 45[.]129.0.192

These indicators should be used as investigative leads rather than a mandatory checklist. The available reporting does not establish that every compromised appliance contains every listed file or log event.

Checks should include file integrity validation, comparison of hashes, review of management-interface requests and examination of outbound connections involving the two addresses. Administrators should also inspect configuration changes and persistence mechanisms, particularly modifications affecting service loading or scheduled execution.

Logs show shell activity and a possible archive destination

Fortinet’s examples include a cron debug event in which root invokes a command beginning:

/bin/sh -c 'O=/migadmin ...

The supplied excerpt is truncated, so it does not reveal the complete command or its final effect. However, the combination of a root shell, cron execution and a reference to /migadmin makes the event relevant to forensic triage.

Another event records the creation of an archive account named archive234 through the command-line interface. It points to remote server 79.141.169.187 and directory /uploads, with these values:

  • Rotation size: 50
  • Rotation time: 1
  • Rotation hour: 14
  • Remote password: redacted in the example

This configuration could have been used to direct archived information to the remote host. The log entry by itself does not prove that any data transfer completed.

Other examples include a successful logout by admin, failed authentication attempts for an internal user represented as *@domain.tld, and an IBE decryption error. The latter reports invalid Base64 encoding at position 0, involving character value 0x2a.

Defenders should correlate these records chronologically with HTTP or HTTPS management traffic, configuration changes, file timestamps, cron activity and outbound network sessions. A single matching event is not sufficient to reconstruct the entire intrusion.

CISA sets an October 4 remediation deadline

CISA added CVE-2026-104286 to its Known Exploited Vulnerabilities catalog on October 1, 2026. US federal agencies have a remediation deadline of October 4, 2026.

The required action is to apply Fortinet’s mitigations while following BOD 26-04 Prioritizing Security Updates Based on Risk and CISA’s forensic-triage requirements. Relevant organizations must evaluate each asset’s Internet exposure and comply with the applicable BOD 26-04 patching guidance.

For cloud services, agencies must follow the corresponding BOD 26-04 instructions or discontinue use of the product when mitigations are unavailable.

KEV inclusion confirms that exploitation is not merely theoretical. Operational priorities are therefore to restrict management access, disable IBE support where applicable, conduct forensic triage and deploy the appropriate corrected release once available.

Scope of the attacks remains unresolved

Fortinet told BleepingComputer that it was communicating with government organizations, including CISA, and referred customers to its advisory for remediation guidance.

The available material does not provide an attacker attribution or a total number of compromised systems. It also does not specify when exploitation began.

Those gaps limit conclusions about the campaign’s scale and operators, but not the immediate response. Any organization running one of the affected FortiMail builds should treat prior exposure of the management interface as a reason for investigation, rather than relying only on the eventual installation of a fixed version.

Security dossiers

Read next

Sources

This article is an original reworking based on the sources below.

CVEs covered in this article

Back to home

Latest Cybersecurity News

All cybersecurity news →