Protect.Computer
NEWS

FortiMail Zero-Day CVE-2026-104286 Exploited, No Patch Yet

· 1 min read · Got hacked Network safety
FortiMail Zero-Day CVE-2026-104286 Exploited, No Patch Yet

Fortinet has disclosed a critical vulnerability in FortiMail, its email security gateway, that attackers are already exploiting as a zero-day. Tracked as CVE-2026-104286 (CVSS 9.8), it is a path-traversal and NULL-byte handling flaw in the management interface that lets an unauthenticated attacker write arbitrary files to the underlying system with crafted HTTP or HTTPS requests, leading to unauthorized code or command execution. Fortinet’s own product security team found the bug internally.

There is no fix for most branches yet. FortiMail 7.2 customers can upgrade to the 7.4 branch or later, but patched releases for 7.4, 7.6 and 8.0 (7.4.9, 7.6.7 and 8.0.2) are still listed as upcoming. CISA has added the flaw to its Known Exploited Vulnerabilities catalog and gave federal agencies until October 4 to triage and mitigate. Fortinet has not said when exploitation began, how many appliances were compromised, or who is behind it.

How to check if you’re affected

Affected products are FortiMail versions 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9, on any appliance or virtual device exposing the management interface.

  • Mitigate now: disable IBE (identity-based encryption) support with config system encryption ibe, set status disable, end, or block Internet access to the management interface and restrict it to trusted private networks.
  • Hunt for compromise: Fortinet lists files added or modified on hit systems, including /data/lib/liblog.so, /data/bin/webconsole, /data/bin/mailservice, /data/etc/ld.so.preload, plus modified /bin/smit, /data/etc/httpd.conf and /data/migadmin.tar.gz. The advisory carries the SHA-256 hashes.
  • Check network and logs: look for traffic to 79.141.169.187 and 45.129.0.192, an unexpected archive account (the example is named archive234) pointing at a remote server with directory /uploads, a cron job referencing /migadmin, and IBE decryption errors about invalid Base64 encoding.

If you find any of these, treat the appliance as compromised: archived mail may have been sent off-box, so review what mail data it held.

Sources

Related reading