Fortinet warned of active exploitation of CVE-2026-104286 in the FortiMail management interface, a vulnerability rated critical with a score of 9.8 under the CVSS scale. It can be exploited through specially crafted HTTP or HTTPS requests, without requiring authentication, to write arbitrary files to the device’s underlying system, paving the way for the execution of unauthorized commands or instructions.
The issue is linked to two underlying vulnerabilities: path traversal to access restricted directories, and improper handling of NULL characters. It was discovered by Gwendal Guégniaud of Fortinet’s Product Security team. Affected versions include FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9.
What fixes and workarounds are available?
FortiMail 7.2 users can move to the 7.4 branch or a later version. For users of the 7.4, 7.6, and 8.0 branches, final fix updates are not yet available; Fortinet lists versions 7.4.9, 7.6.7, and 8.0.2 as upcoming releases that include the remediation.
Until the patched versions are installed, the company recommends disabling support for the IBE feature using the following commands:
config system encryption ibe
set status disable
end
Administrators can also disable access to the FortiMail management interface from the internet, or restrict it to trusted private networks.
Indicators of compromise
Fortinet published IP addresses associated with the attacks, namely 79.141.169.187 and 45.129.0.192, as well as indicators of files added to or modified on compromised systems, including:
- /data/lib/liblog.so — an added file whose SHA-256 hash is 8015f34dc84922b03688399d7f9fe7a00361789f7e420c7e2a2cdb23e75cef84.
- /bin/smit — a modified file whose hash is 77324ac428bde86d351fc5fc06f6d64a6bfe737dfb2743df1d4c5ac2418a5b6a.
- /data/bin/webconsole, /data/bin/mailservice, /data/etc/httpd.conf, /data/etc/ld.so.preload, and /data/migadmin.tar.gz.
The audit logs published by the company include the creation of an archive account named archive234 to send data to the server 79.141.169.187 under the /uploads path. Other notable examples include a scheduled task executing commands associated with /migadmin, IBE decryption errors, and failed login attempts.
Why does this matter?
The risk is not limited to the existence of a highly rated vulnerability, but also to the fact that exploitation is occurring before fixes are complete for some branches. Organizations running FortiMail therefore need to treat the workarounds as an urgent measure and examine logs, files, and network indicators rather than simply waiting for the update. At the same time, Fortinet has not disclosed when the exploitation began, how many devices were affected, or which party is responsible, leaving the campaign’s scope and the attackers’ identity as open questions.
CISA added the vulnerability to its Known Exploited Vulnerabilities catalog and required federal agencies to conduct initial forensic triage and mitigate the risk by October 4. Fortinet said it is coordinating guidance with government agencies, including CISA.