BTC$85,484+1.97% LTC$70.78+5.63% XMR$542.06+0.66%
TorPortal TorPortalMarkets, mirrors, dark web news
BleepingComputer · Oct 1, 2026 · 4 min read · Original story

Fortinet warns of critical FortiMail flaw exploited in zero-day attacks

Fortinet warns of critical FortiMail flaw exploited in zero-day attacks

Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices.

The vulnerability is rated critical, with a CVSS score of 9.8, and affects the FortiMail management interface.

"An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] and Improper Neutralization of NULL Byte or NULL Character [CWE-158] vulnerability may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests," Fortinet said in an advisory published Thursday.

Gwendal Guégniaud of Fortinet's Product Security team discovered the vulnerability internally, and it affects FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, and FortiMail 7.2.0 through 7.2.9.

Fortinet says the flaw is being actively exploited and is urging customers to apply the shared workarounds until a security update can be installed.

FortiMail 7.2 users can patch the vulnerability by upgrading to the 7.4 branch or later. For affected FortiMail 7.4, 7.6, and 8.0 installations, security updates are not yet available, with Fortinet listing FortiMail 7.4.9, 7.6.7, and 8.0.2 as upcoming versions containing the fix.

Until patched versions are available, Fortinet says admins can mitigate the flaw by disabling IBE feature support using the following commands:

config system encryption ibe set status disable end

As an alternative workaround, administrators can disable access to the FortiMail management interface from the Internet or restrict access to trusted private networks.

Fortinet also published indicators of compromise (IOCs) associated with the attacks, including several files that were added or modified on compromised systems.

File Status SHA-256
/data/lib/liblog.so Added 8015f34dc84922b03688399d7f9fe7a00361789f7e420c7e2a2cdb23e75cef84
/bin/smit Modified 77324ac428bde86d351fc5fc06f6d64a6bfe737dfb2743df1d4c5ac2418a5b6a
/data/bin/webconsole Added 7a6cea9f5c9e2e9994d4e3c4da73f86cf5acd05ea5d312c066c9d1dafd69ee38
/data/bin/mailservice Added 4000276a150a165d3c2537d1e19fb393c4de8333076a16655e28059cae82157b
/data/etc/httpd.conf Modified 703e97c64e61e41dc3aaba580d82bb2aa7b6a11b54ee6fb467ed5d5a3bffdef5
/data/etc/ld.so.preload Added 8953ec7960b09f544a880b072ad4e6cfda7a8303f486251d3478dcfdfbac23b6
/data/migadmin.tar.gz Modified d6fe51c22b91776f4c961ea58bcac5917f15d560a619d7ce726d3d51795609d3

Fortinet also listed 79[.]141.169.187 and 45[.]129.0.192 as IP addresses associated with the attacks.

The advisory also includes log entries that administrators can use to identify potentially compromised appliances.

One of those entries shows an archive account named archive234 being configured from the command line with 79.141.169.187 as the remote server and /uploads as the remote directory. This could indicate that the attacker configured the compromised FortiMail appliance to send archived data to a remote server.

Other log entries include a cron job executing a command related to /migadmin, an administrator logout event, an IBE decryption error due to invalid Base64 encoding, and failed login attempts.

Example log events shared by Fortinet are listed below:

type=event subtype=system pri=debug user=system ui=cron msg="(root) CMD (/bin/sh -c 'O=/migadmin ... - type=kevent subtype=admin pri=information user=admin ui=(null) action=logout status=success reason=unknown msg="User admin logged out from (null)." - type=kevent subtype=config pri=information user=admin ui=cli module=unknown submodule=unknown msg="Added 'archive234' to 'archive account' : rotation-size[50]rotation-time[1] rotation-hour[14]destination[remote]remote-ip[79.141.169.187]remote-username[archive234]remote-password[***]remote-directory[/uploads] (user: admin, from: cli)" - FortiMail::IBE::DecrypterMediaIn::DecrypterMediaIn(FortiMail::MediaIn&, const FortiMail::IBE::KeyFinder&, const FortiMail::EmailAddress&, const FortiMail::Buffer&, FortiMail::IBE::DecrypterMediaIn::Version): Caught BufferException(2), BufferImpl.cpp:973, 'Invalid Base64 Encoding at pos 0. Character=0x2a' - Internal user *@domain.tld<mailto:*@domain.tld> failed to log in.

Fortinet has not disclosed when the flaw was first exploited, how many systems were compromised, or who is behind the attacks.

When BleepingComputer asked for more information about the exploitation activity, Fortinet referred customers to the advisory and said it is coordinating with government agencies, including CISA.

"Fortinet published an advisory to provide guidance regarding CVE-2026-104286 (FG-IR-26-175), including workarounds to help customers mitigate risk," Fortinet told BleepingComputer.

"Consistent with Fortinet’s commitment to responsible PSIRT disclosure and public-private partnerships, we are communicating with relevant government organizations, including CISA, on the content of this advisory."

CISA has now added the CVE-2026-104286 flaw to the Known Exploited Vulnerability catalog and requires federal agencies to perform forensic triage and mitigate the flaw by October 4th.

References in this story

  1. PSIRT | FortiGuard Labs fortiguard.fortinet.com None

← Back to all news