Unpatched FortiMail flaw under attack
Fortinet warns of CVE-2026-104286, a critical FortiMail flaw under active exploitation that lets unauthenticated attackers write arbitrary files.
An unauthenticated attacker can write arbitrary files onto a FortiMail appliance with a crafted HTTP or HTTPS request to the management interface. Fortinet rates the bug, CVE-2026-104286, at CVSS 9.8, and says it is already being exploited in the wild. For the 7.4, 7.6, and 8.0 branches there is no fix yet.
The root cause is a pair of input-handling failures in the management interface: a path traversal (CWE-22) combined with improper neutralization of a NULL byte or NULL character (CWE-158). Both are familiar ways to defeat a filesystem path check, and together, Fortinet says, they let an unauthenticated attacker write arbitrary files on the underlying system through crafted HTTP or HTTPS requests.
Fortinet says the flaw can lead to unauthorized code or command execution, and it published the files that were added or modified on compromised systems. Added: /data/lib/liblog.so, /data/bin/webconsole, /data/bin/mailservice, and /data/etc/ld.so.preload. Modified: /bin/smit, /data/etc/httpd.conf, and /data/migadmin.tar.gz. On Linux, ld.so.preload names shared objects the dynamic linker loads into every dynamically linked process before anything else, so an added ld.so.preload sitting among the indicators is worth a careful look.
Fortinet also shared log evidence from the appliances. One entry records an archive account named archive234 being configured from the CLI with 79.141.169.187 as the remote server and /uploads as the remote directory; Fortinet says this could indicate the appliance was configured to send archived data to a remote server. Other entries show a cron job running a command tied to /migadmin, an admin logout, failed logins, and an IBE decryption error caused by invalid Base64 (Invalid Base64 Encoding at pos 0. Character=0x2a).
The primary workaround is to turn IBE off:
config system encryption ibe
set status disable
end
If you run FortiMail without Identity-Based Encryption, this workaround costs you nothing. If you use it, you lose that feature until a patched build is available.
The second workaround is the one that should have been in place already: take the management interface off the public internet, or restrict it to trusted private networks. A management plane reachable from the internet is what makes an unauthenticated write exploitable at scale.
Affected versions are FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9. If you are on 7.2, you can patch now by moving to the 7.4 branch or later. For 7.4, 7.6, and 8.0 the fixes are listed as upcoming releases 7.4.9, 7.6.7, and 8.0.2, none of which are out yet, so the workarounds are your only option today.
Check your appliances against the published IOCs regardless of whether you think you were exposed. Look for the added and modified files above, scan logs for the archive234 archive account and connections to 79.141.169.187 or 45.129.0.192, and treat any /migadmin cron activity or unexplained IBE Base64 errors as suspect.
The bug was found internally, by Gwendal Guégniaud of Fortinet’s Product Security team. Fortinet has not said when exploitation began, how many systems were hit, or who is behind it, and told BleepingComputer it is coordinating with CISA. CISA has added CVE-2026-104286 to its Known Exploited Vulnerabilities catalog and set a deadline of October 4 for federal agencies to triage and mitigate.
Keep Reading
appleiOS CoreGraphics PoC published two days after the patch
Apple patched CVE-2026-86950, an out-of-bounds write in CoreGraphics triggered by a malicious PDF font and used in targeted attacks on iOS before 27.
cryptocurrencyAttackers drained $387.5M through Bitget's own security appliances
Bitget confirms a third-party zero-day let attackers reach its wallet job server and drain $387.5M; SlowMist and Mandiant trace the two-stage path.
netscalerCitrix patches second NetScaler SAML bug in days
Citrix patched NetScaler zero-day CVE-2026-88779, a SAML memory overflow under active attack that causes denial-of-service and may allow code execution.
Latest on the Wire
Full wire →- 16 Fake Firefox Extensions Stole Crypto Recovery PhrasesThe Hacker News
- AI Bolsters and Threatens Autocratic RegimesSchneier on Security
- AI Developer Launches Open-Source Adobe AlternativesArs Technica
- AI Helps Solve 15-Year Mystery of Obscure Band SalvageHacker News
New signal daily · RSS
Stay in the loop
New writing delivered when it's ready. No schedule, no spam.