CVE-2026-104286: FortiMail exploited as a zero-day, patch pending
Fortinet issued an advisory on Thursday 1 October 2026 for CVE-2026-104286, a critical FortiMail admin interface flaw already exploited as a zero-day. No fix exists for the 7.4, 7.6 and 8.0 branches: only workarounds protect exposed appliances.

An arbitrary file write, with no authentication
Fortinet published a security advisory on Thursday 1 October 2026 covering CVE-2026-104286, a vulnerability in the FortiMail administrative interface. It is rated critical, with a CVSS score of 9.8, and the vendor states that it is being actively exploited in zero-day attacks — that is, before a patch was made available. The news was picked up the same day by Bleeping Computer.
Two defects combine: an improper limitation of a pathname to a restricted directory, in other words a directory traversal (CWE-22), and an improper neutralisation of the null byte (CWE-158). According to the advisory, an unauthenticated attacker can write arbitrary files to the underlying system through crafted HTTP or HTTPS requests. On a mail gateway, writing a file to a chosen location amounts in practice to getting code executed there. The vulnerability was found internally by Gwendal Guégniaud, of Fortinet’s Product Security team.
Four branches affected, three with no fixed release
The affected versions are FortiMail 8.0.0 to 8.0.1, 7.6.0 to 7.6.6, 7.4.0 to 7.4.8 and 7.2.0 to 7.2.9.
If your appliance runs 7.2, you have an immediate way out: moving up to the 7.4 branch or a later one fixes the flaw. For installations on 7.4, 7.6 and 8.0, the security updates have not been released yet. Fortinet names 7.4.9, 7.6.7 and 8.0.2 as the versions that will carry the fix, without giving an availability date.
The two workarounds to put in place before Monday
Until those versions exist, the vendor asks you to apply the workarounds it has published. The first disables support for the IBE feature:
config system encryption ibe
set status disable
end
The second, presented as an alternative, is to cut off access to the FortiMail administrative interface from the internet, or to restrict it to trusted private networks. It is the step that demands the least functional trade-off: the flaw lives in that interface, and the administrative interface of a mail gateway has no reason to be reachable from anywhere.
The traces to look for in your logs
Fortinet has also published indicators of compromise, with the matching SHA-256 hashes. On the filesystem, seven items are to be checked: additions of /data/lib/liblog.so, /data/bin/webconsole, /data/bin/mailservice and /data/etc/ld.so.preload, and changes to /bin/smit, /data/etc/httpd.conf and /data/migadmin.tar.gz. Two IP addresses are associated with the attacks, 79.141.169.187 and 45.129.0.192.
The advisory also supplies log entries that help identify a potentially compromised device. One of them shows the command-line creation of an archiving account named archive234, pointing to 79.141.169.187 as the remote server and /uploads as the destination directory: this may indicate that the compromised appliance was configured to send archived data to an outside server. The other entries cited concern a cron job running a command tied to /migadmin, an administrator logout, an IBE decryption error caused by invalid Base64 encoding, and authentication failures.
Fortinet has not said how long the flaw has been exploited, how many systems have been compromised, or who is behind the attacks. Asked by Bleeping Computer, the vendor pointed back to its advisory and said it is coordinating with government agencies, including CISA.
Between now and the release of 7.4.9, 7.6.7 and 8.0.2, the only variable you control is the exposure of your administrative interface. And if the indicators of compromise match, the question is no longer the patch but incident response.
Sources (1)
- Fortinet warns of critical FortiMail flaw exploited in zero-day attacksbleepingcomputer.com
Written with AI assistance from the sources cited above, then reviewed and approved before publication by Sébastien Soulier.


