Fortinet warns of critical FortiMail flaw exploited in zero-day attacks

Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices.
The vulnerability is rated critical, with a CVSS score of 9.8, and affects the FortiMail management interface.
"An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] and Improper Neutralization of NULL Byte or NULL Character [CWE-158] vulnerability may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests," Fortinet said in an advisory published Thursday.
Gwendal Guégniaud of Fortinet's Product Security team discovered the vulnerability internally, and it affects FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, and FortiMail 7.2.0 through 7.2.9.
Fortinet says the flaw is being actively exploited and is urging customers to apply the shared workarounds until a security update can be installed.
FortiMail 7.2 users can patch the vulnerability by upgrading to the 7.4 branch or later. For affected FortiMail 7.4, 7.6, and 8.0 installations, security updates are not yet available, with Fortinet listing FortiMail 7.4.9, 7.6.7, and 8.0.2 as upcoming versions containing the fix.
Until patched versions are available, Fortinet says admins can mitigate the flaw by disabling IBE feature support using the following commands:
config system encryption ibe set status disable endAs an alternative workaround, administrators can disable access to the FortiMail management interface from the Internet or restrict access to trusted private networks.
Fortinet also published indicators of compromise (IOCs) associated with the attacks, including several files that were added or modified on compromised systems.
| File | Status | SHA-256 |
|---|---|---|
| /data/lib/liblog.so | Added | 8015f34dc84922b03688399d7f9fe7a00361789f7e420c7e2a2cdb23e75cef84 |
| /bin/smit | Modified | 77324ac428bde86d351fc5fc06f6d64a6bfe737dfb2743df1d4c5ac2418a5b6a |
| /data/bin/webconsole | Added | 7a6cea9f5c9e2e9994d4e3c4da73f86cf5acd05ea5d312c066c9d1dafd69ee38 |
| /data/bin/mailservice | Added | 4000276a150a165d3c2537d1e19fb393c4de8333076a16655e28059cae82157b |
| /data/etc/httpd.conf | Modified | 703e97c64e61e41dc3aaba580d82bb2aa7b6a11b54ee6fb467ed5d5a3bffdef5 |
| /data/etc/ld.so.preload | Added | 8953ec7960b09f544a880b072ad4e6cfda7a8303f486251d3478dcfdfbac23b6 |
| /data/migadmin.tar.gz | Modified | d6fe51c22b91776f4c961ea58bcac5917f15d560a619d7ce726d3d51795609d3 |
Fortinet also listed 79[.]141.169.187 and 45[.]129.0.192 as IP addresses associated with the attacks.
The advisory also includes log entries that administrators can use to identify potentially compromised appliances.
One of those entries shows an archive account named archive234 being configured from the command line with 79.141.169.187 as the remote server and /uploads as the remote directory. This could indicate that the attacker configured the compromised FortiMail appliance to send archived data to a remote server.
Other log entries include a cron job executing a command related to /migadmin, an administrator logout event, an IBE decryption error due to invalid Base64 encoding, and failed login attempts.
Example log events shared by Fortinet are listed below:
type=event subtype=system pri=debug user=system ui=cron msg="(root) CMD (/bin/sh -c 'O=/migadmin ... - type=kevent subtype=admin pri=information user=admin ui=(null) action=logout status=success reason=unknown msg="User admin logged out from (null)." - type=kevent subtype=config pri=information user=admin ui=cli module=unknown submodule=unknown msg="Added 'archive234' to 'archive account' : rotation-size[50]rotation-time[1] rotation-hour[14]destination[remote]remote-ip[79.141.169.187]remote-username[archive234]remote-password[***]remote-directory[/uploads] (user: admin, from: cli)" - FortiMail::IBE::DecrypterMediaIn::DecrypterMediaIn(FortiMail::MediaIn&, const FortiMail::IBE::KeyFinder&, const FortiMail::EmailAddress&, const FortiMail::Buffer&, FortiMail::IBE::DecrypterMediaIn::Version): Caught BufferException(2), BufferImpl.cpp:973, 'Invalid Base64 Encoding at pos 0. Character=0x2a' - Internal user *@domain.tld<mailto:*@domain.tld> failed to log in.Fortinet has not disclosed when the flaw was first exploited, how many systems were compromised, or who is behind the attacks.
When BleepingComputer asked for more information about the exploitation activity, Fortinet referred customers to the advisory and said it is coordinating with government agencies, including CISA.
"Fortinet published an advisory to provide guidance regarding CVE-2026-104286 (FG-IR-26-175), including workarounds to help customers mitigate risk," Fortinet told BleepingComputer.
"Consistent with Fortinet’s commitment to responsible PSIRT disclosure and public-private partnerships, we are communicating with relevant government organizations, including CISA, on the content of this advisory."
CISA has now added the CVE-2026-104286 flaw to the Known Exploited Vulnerability catalog and requires federal agencies to perform forensic triage and mitigate the flaw by October 4th.
References in this story
- PSIRT | FortiGuard Labs fortiguard.fortinet.com None



