Published on October 2, 2026
[CVE-2026-104286] Critical Fortinet FortiMail Zero-Day Vulnerability Actively Exploited in Attacks
Severity
Critical
Detail
Fortinet has disclosed a critical zero-day vulnerability affecting FortiMail that is being actively exploited in the wild. Tracked as CVE-2026-104286, the vulnerability could allow an unauthenticated attacker to write arbitrary files to the underlying operating system through specially crafted HTTP or HTTPS requests.
The vulnerability results from a combination of Path Traversal (CWE-22) and Improper Neutralization of NULL Byte or NULL Character (CWE-158) weaknesses. Successful exploitation could allow attackers to place malicious files on affected appliances, potentially leading to complete system compromise.
Fortinet confirmed that the vulnerability is being actively exploited but has not disclosed details regarding the threat actors, victims, or attack campaigns involved. At the time of disclosure, security fixes for several affected branches were not yet available, making immediate implementation of vendor-recommended workarounds essential
| CVE ID | Summary | CVSS |
| CVE-2026-104286 | A path traversal and NULL byte handling vulnerability that allows an unauthenticated attacker to write arbitrary files to the underlying FortiMail system via crafted HTTP or HTTPS requests. | 9.8 (Critical) |
Affected Products
The vulnerability affects the following FortiMail versions:
- FortiMail 8.0.0 through 8.0.1
- FortiMail 7.6.0 through 7.6.6
- FortiMail 7.4.0 through 7.4.8
- FortiMail 7.2.0 through 7.2.9
Indicators of Compromise (IoCs)
The table below lists IoCs associated with the reported malicious activity.
| Type | Indicator | Description |
| File | /data/lib/liblog.so | Suspicious file added by attacker |
| File | /data/bin/webconsole | Suspicious file added by attacker |
| File | /data/bin/mailservice | Suspicious file added by attacker |
| File | /data/etc/ld.so.preload | Suspicious file added by attacker |
| IPv4 | 79[.]141[.]169[.]187 | Suspicious remote host |
| IPv4 | 45[.]129[.]0[.]192 | Suspicious remote host |
| Username | archive234 | Suspicious archive account observed during exploitation |
Recommendation
Organizations should implement the following measures immediately to reduce the risk of exploitation:
- Disable the Identity-Based Encryption (IBE) feature using the FortiMail CLI
- Restrict access to the FortiMail management interface and prevent direct internet exposure.
- Allow management access only from trusted internal or administrative networks.
- Review systems for the published indicators of compromise and investigate any matches.
- Preserve logs and forensic evidence if compromise is suspected.
- Monitor Fortinet advisories and apply security updates as soon as fixed releases become available.
- Upgrade to FortiMail 8.0.2, 7.6.7, 7.4.9, or later when released. FortiMail 7.2 customers should migrate to the 7.4 branch or later.
Source
https://nvd.nist.gov/vuln/detail/cve-2026-104286
https://cybersecuritynews.com/fortimail-0-day-vulnerability-exploited/
https://fortiguard.fortinet.com/psirt/FG-IR-26-175
