thehackernews.com 2 Oct 2026, 05:49 UTC

Fortinet FortiMail Zero Day Exploited in Attacks, CISA Warns

CyberSIXT Evidence Panel
CISA KEV Listed in KEV
Patch Patch Status Unknown

FORTINET has disclosed a critical zero-day affecting Fortinet FortiMail that has been observed being exploited in the wild. The flaw, tracked as CVE-2026-104286 with a CVSS score of 9.8, allows unauthenticated attackers to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. Fortinet attributes this to an improper restriction of pathnames (path traversal) and inadequate neutralisation of NULL bytes, enabling the attacker to place or modify files without authentication.

Affected versions include FortiMail 8.0.0–8.0.1; 7.6.0–7.6.6; 7.4.0–7.4.8; and 7.2.0–7.2.9. Fortinet indicates fixes will come in upcoming releases (8.0.2+, 7.6.7+, 7.4.9+), but in the meantime workarounds are advised.

Residual indicators of compromise listed by Fortinet include newly added or modified files and specific IP addresses such as 79.141.169[.]187 and 45.129.0[.]192, with several system files changed or added (for example, /data/lib/liblog[.]so, /data/bin/webconsole, /data/bin/mailservice, /data/etc/ld.so[.]preload, /data/etc/httpd[.]conf, and /data/migadmin.tar[.]gz). As a temporary defence, Fortinet suggests disabling IBE via the CLI and restricting FortiMail management interface access to private networks.

The U.S. CISA added this vulnerability to the Known Exploited Vulnerabilities catalog, and FCEB agencies have been urged to apply patches or workarounds by 4 October 2026. Fortinet credits Gwendal Guégniaud for the discovery.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline