Fortinet has issued a warning regarding a critical vulnerability in its FortiMail email security platform, identified as CVE-2026-104286, which is actively being exploited in zero-day attacks. The flaw, rated with a CVSS score of 9.8, affects the FortiMail management interface and could allow an unauthenticated attacker to execute arbitrary code or commands.
The vulnerability is described as an "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')" (CWE-22) and "Improper Neutralization of NULL Byte or NULL Character" (CWE-158). This combination could enable an attacker to write arbitrary files to the underlying system by crafting specific HTTP or HTTPS requests.
Gwendal Gugniaud of Fortinet's Product Security team discovered the issue internally. Affected FortiMail versions include 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9. Fortinet has confirmed active exploitation and is urging customers to implement temporary mitigations while awaiting security updates.
For FortiMail 7.2 users, upgrading to the 7.4 branch or a later version is recommended. Security updates for FortiMail 7.4, 7.6, and 8.0 installations are not yet available, but Fortinet has indicated that fixes will be included in upcoming versions 7.4.9, 7.6.7, and 8.0.2.
As a workaround, administrators can disable IBE (Identity-Based Encryption) feature support using the command: `config system encryption ibe set status disable end`. Alternatively, access to the FortiMail management interface can be restricted from the internet or limited to trusted private networks.
Fortinet has also provided Indicators of Compromise (IOCs) to help identify potential breaches. These include specific file modifications and additions, along with their SHA-256 hashes: `/data/lib/liblog.so` (added), `/bin/smit` (modified), `/data/bin/webconsole` (added), `/data/bin/mailservice` (added), `/data/etc/httpd.conf` (modified), `/data/etc/ld.so.preload` (added), and `/data/migadmin.tar.gz` (modified).
Two IP addresses, 79.141.169.187 and 45.129.0.192, have been linked to the attacks. Log entries provided by Fortinet as IOCs show activities such as a cron job executing a command related to `/migadmin`, an administrator logout, an IBE decryption error, and failed login attempts. One specific log entry indicates the configuration of an archive account named `archive234` with `79.141.169.187` as the remote server and `/uploads` as the remote directory, suggesting an attempt to exfiltrate archived data.
Fortinet has not publicly disclosed the initial exploitation date, the number of compromised systems, or the identity of the attackers. The company has stated it is coordinating with government agencies, including CISA, on the advisory's content. CISA has added CVE-2026-104286 to its Known Exploited Vulnerability catalog, mandating federal agencies to perform forensic triage and mitigate the flaw by October 4th.






