FortiMail vulnerability CVE-2026-104286 is being exploited now
A critical FortiMail vulnerability is under active exploitation. This briefing explains which versions are affected, what Fortinet and CISA advise, and immediate steps for admins.
Fortinet has warned that a critical FortiMail vulnerability, tracked as CVE-2026-104286, is being actively exploited in zero-day attacks, according to BleepingComputer. The flaw can let an unauthenticated attacker write arbitrary files to the underlying system via crafted HTTP or HTTPS requests, and Fortinet has published workarounds and indicators of compromise customers can use now.
What the FortiMail vulnerability does and how it is exploited
According to BleepingComputer, the issue is a path traversal combined with a NULL byte handling weakness that may allow remote attackers to place files on the appliance. Fortinet rates the flaw as critical with a CVSS score of 9.8 and says it affects the FortiMail management interface. The company warned the vulnerability is being actively exploited in the wild and published an advisory with guidance and IOCs.
The advisory explains the technical vector as an "Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)" together with "Improper Neutralization of NULL Byte or NULL Character," which lets crafted HTTP or HTTPS requests write files to the device, according to Fortinet and the BleepingComputer report.
Which FortiMail versions are affected
According to BleepingComputer, affected releases include FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9. Fortinet said FortiMail 7.2 users can remediate by upgrading to the 7.4 branch or later. For FortiMail 7.4, 7.6, and 8.0 installations, Fortinet listed upcoming fixed versions: 7.4.9, 7.6.7, and 8.0.2.
Fortinet said it discovered the issue internally, and the company is coordinating with government agencies, including CISA, on the advisory content, BleepingComputer reports. Fortinet has not disclosed when exploitation began, how many devices were compromised, or who is responsible.
Indicators of compromise and log signals to watch for
Fortinet published a set of IOCs that BleepingComputer reproduced. Administrators can check for files that were added or modified and for two IP addresses linked to the attacks, 79.141.169.187 and 45.129.0.192. Examples of files listed as added or changed include /data/lib/liblog.so, /data/bin/webconsole, /data/bin/mailservice, and /data/etc/ld.so.preload, each with associated SHA-256 hashes.
The advisory also includes relevant log entries administrators can use to spot likely compromises. One example shows an archive account being configured from the command line with remote IP 79.141.169.187 and remote-directory set to /uploads, which could mean an attacker arranged for archived data to be sent to an external server. Other sample events include a cron job referencing /migadmin, an IBE decryption error with invalid Base64, and failed or unusual login events. These are the specific indicators Fortinet published, as reported by BleepingComputer.
Immediate actions to protect your FortiMail appliances
Fortinet published temporary mitigations and recommends customers apply them until updates are available, according to BleepingComputer. Practical steps to take now include:
If you run FortiMail 7.2, upgrade to the 7.4 branch or later as Fortinet recommends.
For affected 7.4, 7.6, and 8.0 systems, apply Fortinet's temporary workaround by disabling the IBE feature with the commands Fortinet published:
config system encryption ibe set status disable end
Block or restrict access to the FortiMail management interface from the Internet; allow access only from trusted private networks.
Search appliance file paths and compare hashes against the IOCs Fortinet published, and review logs for the example events (archive account creation to remote IP 79.141.169.187, cron jobs referencing /migadmin, IBE errors, and unexpected admin activity).
If you see signs of compromise, isolate the appliance from networks and follow your incident response plan, including forensic triage where required.
Fortinet also listed the IP addresses and file hashes you can use to look for evidence of compromise, and BleepingComputer reproduced those details in its report.
What agencies and vendors are doing, and what that means for you
BleepingComputer reports Fortinet is coordinating with government agencies, including CISA. CISA has added CVE-2026-104286 to its Known Exploited Vulnerability catalog and requires federal agencies to perform forensic triage and mitigate the flaw by October 4th, according to the BleepingComputer story. That requirement raises the likelihood of continued public visibility and of vendor updates arriving soon.
If your organization uses FortiMail, follow Fortinet's advisory and the practical steps above. Start investigating logs and the specific files and IPs Fortinet published, apply the recommended temporary mitigations, and prepare to install the vendor fixes when they are released. If you would like an external check of your public-facing systems, start with a free external scan at /security.html.
Bottom line for small teams and nonprofits
Treat this as an active, high-severity incident. If you run FortiMail in any of the affected versions, assume risk until you have applied the mitigations, checked for the published IOCs and log signs, and installed vendor updates when available. Follow your incident response procedures and involve IT or external help if you find evidence of compromise.
Sources
- Fortinet warns of critical FortiMail flaw exploited in zero-day attacks BleepingComputer
- Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action SecurityWeek
This post was drafted with AI from the reporting linked above and published by Jones Web Designs. For full details, read the original sources.