FortiMail CVE-2026-104286 zero-day exploited in attacks
Fortinet has disclosed a critical vulnerability in FortiMail, its email security appliance. Attackers are already exploiting it in the wild to run unauthorized code or commands on exposed devices. The flaw is tracked as CVE-2026-104286, carries a CVSS score of 9.8, and sits in the product's management interface.
Patches are not yet out for most affected branches. For now, many administrators can only rely on workarounds.
How the flaw works
In its advisory, published Thursday, Fortinet describes the bug as a combination of two weaknesses. The first is a path traversal issue (CWE-22). The second is improper handling of NULL bytes or NULL characters (CWE-158). Together, they may let an attacker with no credentials write arbitrary files to the underlying system by sending specially crafted HTTP or HTTPS requests.
Gwendal Guégniaud of Fortinet's Product Security team found the vulnerability internally. The affected releases are:
- FortiMail 8.0.0 through 8.0.1
- FortiMail 7.6.0 through 7.6.6
- FortiMail 7.4.0 through 7.4.8
- FortiMail 7.2.0 through 7.2.9
Patches still pending for most branches
Only FortiMail 7.2 users have a direct fix today. They can upgrade to the 7.4 branch or later. Installations running 7.4, 7.6 and 8.0 have no security update yet. Fortinet lists FortiMail 7.4.9, 7.6.7 and 8.0.2 as the upcoming releases that will contain the fix.
Until those versions ship, Fortinet recommends disabling support for the IBE feature. IBE refers to FortiMail's identity-based encryption for email. Fortinet's advisory includes the commands needed to switch it off.
A second option is to cut off Internet access to the FortiMail management interface, or to limit it to trusted private networks.
What the attackers left behind
Fortinet has also shared indicators of compromise (IOCs). These include several files that were added or changed on breached systems and two IP addresses linked to the attacks: 79[.]141.169.187 and 45[.]129.0.192.
The advisory also lists log entries that can help administrators spot compromised appliances. One of them shows an archive account called "archive234" being set up from the command line. It points to 79.141.169.187 as the remote server and /uploads as the remote directory. This suggests the attacker may have configured the hijacked appliance to ship archived data to an external server. For an email gateway, that data could include mail traffic passing through the organization.
Other logged events include:
- a cron job running a command related to /migadmin
- an administrator logout
- an IBE decryption error caused by invalid Base64 encoding
- failed login attempts
Many questions still open
Fortinet has not said when exploitation began, how many devices were hit, or who is behind the campaign. Asked for details, the company pointed customers to the advisory. It said it is working with government bodies, including CISA, the US Cybersecurity and Infrastructure Security Agency.
"Fortinet published an advisory to provide guidance regarding CVE-2026-104286 (FG-IR-26-175), including workarounds to help customers mitigate risk," the company told BleepingComputer.
It added that, "consistent with Fortinet's commitment to responsible PSIRT disclosure and public-private partnerships," it is in contact with relevant government organizations, including CISA, about the content of the advisory.
CISA has since added CVE-2026-104286 to its Known Exploited Vulnerabilities (KEV) catalog. The KEV catalog lists flaws with confirmed real-world abuse, and it sets binding remediation deadlines for US federal civilian agencies. In this case, agencies must carry out forensic triage and mitigate the flaw by October 4th, which leaves only a few days.
Our Take
The tight CISA deadline and the demand for forensic triage, not just patching, say a lot. Organizations running FortiMail should not assume that applying the workaround means they are clean. The archive account entry in Fortinet's logs suggests that attackers may have set up data exfiltration from the appliance itself. That kind of persistence would not go away when IBE is disabled. Checking for the published files, IP addresses and log patterns should come first.
Fortinet's disclosure fits a pattern our readers will recognise. Over the past weeks, attackers have repeatedly gone after internet-facing edge and gateway products, including a Check Point VPN flaw and a NetScaler zero-day tied to state hackers. Mail infrastructure in particular has drawn attention, as seen in a Zimbra bug exploited before disclosure. These systems are an attractive target because they sit at the network edge and handle sensitive data.
Several points are worth watching. The first is how quickly Fortinet ships 7.4.9, 7.6.7 and 8.0.2. The second is whether the company or outside researchers name the actor behind the attacks. A third question is whether exposure scans show many FortiMail management interfaces still reachable from the Internet. If they do, that would point to a basic hardening gap that goes beyond this single flaw.
