FortiMail Zero-Day Vulnerability Exploited in the Wild

A FortiMail zero-day vulnerability, CVE-2026-104286 (CVSS 9.8), lets an unauthenticated attacker write arbitrary files onto Fortinet’s email security appliance with nothing more than crafted web requests. Fortinet confirmed active exploitation on October 1, CISA added the flaw to its Known Exploited Vulnerabilities catalog the same day, and fixed releases for the 7.4, 7.6 and 8.0 branches were still listed as upcoming at disclosure.
What Happened
The FortiMail zero-day vulnerability combines a path traversal weakness (CWE-22) with improper handling of NULL characters (CWE-158) in the FortiMail management interface. Fortinet’s advisory FG-IR-26-175 says a remote attacker needs no credentials: crafted HTTP or HTTPS requests are enough to write files to the underlying system. Fortinet’s product security team found the flaw internally. The advisory confirms exploitation in the wild, but does not say when it started, how many appliances were hit, or who is behind it.
Affected are FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8 and 7.2.0 through 7.2.9. FortiMail 7.2 customers are told to move to the 7.4 branch or later. For 7.4, 7.6 and 8.0, the fixed releases (7.4.9, 7.6.7 and 8.0.2) were not yet available when the advisory went out. CISA’s federal deadline was October 4, with forensic triage required, not just mitigation.
Fortinet published indicators of compromise. They include new files at /data/lib/liblog.so, /data/bin/webconsole, /data/bin/mailservice and /data/etc/ld.so.preload, modified files at /bin/smit and /data/etc/httpd.conf, a root cron job referencing /migadmin, and two attacker IP addresses (79[.]141.169.187 and 45[.]129.0.192). One logged event shows an archive account named archive234 configured to send archives to a remote server on the first of those IPs. That suggests mail data theft as a goal; this is our reading, not a statement from Fortinet.
Why It Matters
An email gateway sees every inbound and outbound message. A foothold on that appliance sits upstream of the mailbox, the user and most of the controls built around them. We covered the same pattern in mid-September with the Cisco Secure Email Gateway vulnerability: a security appliance that must accept untrusted input from the internet becomes the entry point itself. It is the second email security appliance zero-day in three weeks, and it follows Fortinet products we have already flagged this year, including FortiClient EMS and FortiSandbox.
The bigger issue is timing. At the time of the advisory no branch had a fixed release: 7.2 customers must move to 7.4 or later, but 7.4 itself stays affected until 7.4.9 ships. A standard patch cycle cannot close this exposure until Fortinet ships the fixes, so the workaround is the only protection in the meantime.
What You Should Do Now
- Apply Fortinet’s workaround today: disable IBE support from the CLI (config system encryption ibe, set status disable, end), or remove internet access to the management interface and restrict it to trusted private networks. Do both where you can. Disabling IBE stops FortiMail’s identity-based encryption feature, so tell the teams that rely on it.
- Check your version on every FortiMail appliance, including virtual ones. Plan the move from 7.2 to 7.4 or later, and apply 7.4.9, 7.6.7 or 8.0.2 the day Fortinet releases them.
- Hunt for the published indicators: the added and modified files, the /migadmin cron entry, the archive234 account, and outbound connections to 79[.]141.169.187 and 45[.]129.0.192.
- If anything matches, treat the appliance as compromised. Preserve logs first, then rotate every credential stored on or reachable from it, and review what mail archives may have left the building. If nothing matches, that is not proof of safety: Fortinet has not said when exploitation began.
DIESEC Perspective
The workaround for this flaw is, in effect, a configuration hygiene step: an appliance management interface should not be reachable from the internet at all. Organizations that already enforce that rule across their security appliances lose far less when a zero-day like this lands, because the attacker first needs a path to the interface.
Not sure whether your FortiMail management interface is reachable from the internet, or whether your appliance already shows these indicators? Contact DIESEC for a rapid exposure assessment and compromise check.
Sources: Fortinet PSIRT FG-IR-26-175 | BleepingComputer | Cyber Security News
Published: 2026-10-05 | Category: Vulnerabilities & Patches | ~4 min read

