
Fortinet has disclosed a critical vulnerability in FortiMail, its email security gateway, that attackers are already exploiting as a zero-day. Tracked as CVE-2026-104286 (CVSS 9.8), it is a path-traversal and NULL-byte handling flaw in the management interface that lets an unauthenticated attacker write arbitrary files to the underlying system with crafted HTTP or HTTPS requests, leading to unauthorized code or command execution. Fortinet’s own product security team found the bug internally.
There is no fix for most branches yet. FortiMail 7.2 customers can upgrade to the 7.4 branch or later, but patched releases for 7.4, 7.6 and 8.0 (7.4.9, 7.6.7 and 8.0.2) are still listed as upcoming. CISA has added the flaw to its Known Exploited Vulnerabilities catalog and gave federal agencies until October 4 to triage and mitigate. Fortinet has not said when exploitation began, how many appliances were compromised, or who is behind it.
How to check if you’re affected
Affected products are FortiMail versions 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9, on any appliance or virtual device exposing the management interface.
- Mitigate now: disable IBE (identity-based encryption) support with
config system encryption ibe,set status disable,end, or block Internet access to the management interface and restrict it to trusted private networks. - Hunt for compromise: Fortinet lists files added or modified on hit systems, including
/data/lib/liblog.so,/data/bin/webconsole,/data/bin/mailservice,/data/etc/ld.so.preload, plus modified/bin/smit,/data/etc/httpd.confand/data/migadmin.tar.gz. The advisory carries the SHA-256 hashes. - Check network and logs: look for traffic to
79.141.169.187and45.129.0.192, an unexpected archive account (the example is namedarchive234) pointing at a remote server with directory/uploads, a cron job referencing/migadmin, and IBE decryption errors about invalid Base64 encoding.
If you find any of these, treat the appliance as compromised: archived mail may have been sent off-box, so review what mail data it held.
