Fortinet Warns of Actively Exploited FortiMail Zero-Day Vulnerability (CVE-2026-104286)
Fortinet has issued an urgent advisory regarding a critical zero-day vulnerability in FortiMail, tracked as CVE-2026-104286 (CVSS 9.8), which is being actively exploited in the wild. The flaw allows unauthenticated attackers to write arbitrary files on vulnerable systems via specially crafted HTTP or HTTPS requests, combining path traversal (CWE-22) and improper NULL byte handling (CWE-158).
Discovered internally by Fortinet’s Gwendal Guégniaud, the vulnerability affects FortiMail versions 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8, and 7.2.0–7.2.9. While patches are pending (8.0.2, 7.6.7, and 7.4.9), Fortinet recommends immediate workarounds, including disabling the IBE feature or restricting management interface access to trusted networks.
Indicators of compromise (IOCs) include unauthorized file modifications (e.g., /data/lib/liblog.so, /data/bin/webconsole), suspicious IP addresses (79[.]141.169.187, 45[.]129.0.192), and unusual account activity (e.g., an archive account named archive234 configured to send data to an external IP). Security teams are advised to check for these signs, along with root cron jobs, IBE decryption errors, and failed internal logins.
Fortinet has not disclosed the attackers’ identities, the full attack chain, or the number of affected organizations. The advisory (FG-IR-26-175) was published on October 1, 2026, with no virtual patch available, emphasizing the need for rapid mitigation. Organizations should preserve logs and investigate potential breaches while awaiting official fixes.
Source: https://cybersecuritynews.com/fortimail-0-day-vulnerability-exploited/
Fortinet TPRM report: https://www.rankiteo.com/company/fortinet
"id": "for1790907819",
"linkid": "fortinet",
"type": "Vulnerability",
"date": "10/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Cybersecurity',
'name': 'Fortinet (FortiMail)',
'type': 'Technology/Vendor'}],
'attack_vector': 'HTTP/HTTPS requests',
'customer_advisories': 'Check for IOCs (e.g., unauthorized file '
'modifications, suspicious IPs, unusual account '
'activity)',
'date_publicly_disclosed': '2026-10-01',
'description': 'Fortinet has issued an urgent advisory regarding a critical '
'zero-day vulnerability in FortiMail, tracked as '
'CVE-2026-104286 (CVSS 9.8), which is being actively exploited '
'in the wild. The flaw allows unauthenticated attackers to '
'write arbitrary files on vulnerable systems via specially '
'crafted HTTP or HTTPS requests, combining path traversal '
'(CWE-22) and improper NULL byte handling (CWE-158).',
'impact': {'operational_impact': 'Unauthorized file modifications, potential '
'data exfiltration, and system compromise',
'systems_affected': 'FortiMail versions 8.0.0–8.0.1, 7.6.0–7.6.6, '
'7.4.0–7.4.8, and 7.2.0–7.2.9'},
'investigation_status': 'Ongoing',
'post_incident_analysis': {'corrective_actions': 'Patch pending; disable IBE '
'feature or restrict '
'management interface access',
'root_causes': 'Path traversal (CWE-22) and '
'improper NULL byte handling '
'(CWE-158)'},
'recommendations': 'Preserve logs, investigate potential breaches, apply '
'workarounds, and await official patches',
'references': [{'source': 'Fortinet Advisory FG-IR-26-175'}],
'response': {'communication_strategy': 'Advisory FG-IR-26-175 published on '
'October 1, 2026',
'containment_measures': 'Disable IBE feature or restrict '
'management interface access to trusted '
'networks',
'enhanced_monitoring': 'Check for unauthorized file '
'modifications, suspicious IP activity, '
'and unusual account activity',
'remediation_measures': 'Patches pending (8.0.2, 7.6.7, 7.4.9)'},
'title': 'Fortinet Warns of Actively Exploited FortiMail Zero-Day '
'Vulnerability (CVE-2026-104286)',
'type': 'Zero-Day Vulnerability Exploitation',
'vulnerability_exploited': 'CVE-2026-104286 (Path traversal + improper NULL '
'byte handling)'}