Fortinet FortiMail Zero-Day Under Active Exploitation: Critical Vulnerability Demands Immediate Attention
A critical zero-day vulnerability, tracked as **CVE-2026-104286**, in **Fortinet**'s **FortiMail** email security platform is being actively exploited, allowing unauthenticated attackers to execute arbitrary code. With a **CVSS** score of 9.8, the flaw poses a severe risk to organizations utilizing affected versions, prompting urgent calls for mitigation.

**Fortinet** has issued a critical warning regarding a zero-day vulnerability in its **FortiMail** product line, identified as **CVE-2026-104286**. This flaw, rated with a severe **CVSS** score of 9.8, is actively being exploited in the wild, enabling unauthorized code or command execution on vulnerable devices.
### The Nature of the Threat
The vulnerability resides within the **FortiMail** management interface. **Fortinet**'s advisory details it as an "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [**CWE-22**] and Improper Neutralization of NULL Byte or NULL Character [**CWE-158**] vulnerability." This combination allows an unauthenticated attacker to write arbitrary files to the underlying system through crafted HTTP or HTTPS requests.
**Gwendal GuΓ©gniaud** of **Fortinet**'s Product Security team discovered the vulnerability internally. It impacts a broad range of **FortiMail** versions, specifically:
* **FortiMail** 8.0.0 through 8.0.1
* **FortiMail** 7.6.0 through 7.6.6
* **FortiMail** 7.4.0 through 7.4.8
* **FortiMail** 7.2.0 through 7.2.9
### Immediate Mitigation and Upcoming Patches
Given the active exploitation, **Fortinet** is urging customers to implement temporary workarounds immediately until security updates become available. For users of **FortiMail** 7.2, upgrading to the 7.4 branch or later is recommended. Unfortunately, for **FortiMail** 7.4, 7.6, and 8.0 installations, dedicated security updates are not yet released, with **FortiMail** 7.4.9, 7.6.7, and 8.0.2 listed as forthcoming versions that will contain the fix.
Until patched versions are released, administrators can mitigate the flaw by disabling IBE (Identity-Based Encryption) feature support using the following commands:
Alternatively, restricting access to the **FortiMail** management interface from the internet or limiting access to trusted private networks can also serve as effective workarounds.
### Indicators of Compromise (IOCs)
**Fortinet** has also published Indicators of Compromise (**IOCs**) to help organizations detect potential breaches. These include specific files that may have been added or modified on compromised systems:
| File | Status | SHA-256 |
| :-------------------- | :------- | :--------------------------------------------------------------- |
| `/data/lib/liblog.so` | Added | `8015f34dc84922b03688399d7f9fe7a00361789f7e420c7e2a2cdb23e75cef84` |
| `/bin/smit` | Modified | `77324ac428bde86d351fc5fc06f6d64a6bfe737dfb2743df1d4c5ac2418a5b6a` |
| `/data/bin/webconsole`| Added | `7a6cea9f5c9e2e9994d4e3c4da73f86cf5acd05ea5d312c066c9d1dafd69ee38` |
| `/data/bin/mailservice`| Added | `4000276a150a165d3c2537d1e19fb393c4de83330370a16655e28059cae82157b` |
| `/data/etc/httpd.conf`| Modified | `703e97c64e61e41dc3aaba580d82bb2aa7b6a11b54ee6fb467ed5d5a3bffdef5` |
| `/data/etc/ld.so.preload`| Added | `8953ec7960b09f544a880b072ad4e6cfda7a8303f486251d3478dcfdfbac23b6` |
| `/data/migadmin.tar.gz`| Modified | `d6fe51c22b91776f4c961ea58bcac5917f15d560a619d7ce726d3d51795609d3` |
Associated IP addresses identified in the attacks include `79[.]141.169.187` and `45[.]129.0.192`.
### Log Entry Clues
The advisory also provides specific log entries that can help administrators identify compromised appliances. One notable entry indicates an archive account named `archive234` being configured from the command line, with `79.141.169.187` as the remote server and `/uploads` as the remote directory. This suggests attackers may be exfiltrating archived data.
Other suspicious log events include:
### Coordination with CISA
While **Fortinet** has not disclosed details on the scale or origin of the attacks, it has confirmed coordination with governmental agencies, including the **Cybersecurity and Infrastructure Security Agency (CISA)**. **CISA** has added **CVE-2026-104286** to its Known Exploited Vulnerabilities Catalog, mandating federal agencies to conduct forensic triage and apply mitigations by October 4th. This highlights the severe and immediate threat posed by this zero-day vulnerability.