CVE-2026-104286: 
Fortimail Analisi e mitigazione delle vulnerabilità

Panoramica

CVE-2026-104286 is a critical path traversal vulnerability (CWE-22) in Fortinet FortiMail that allows unauthenticated remote attackers to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. The vulnerability also involves improper neutralization of NULL byte or NULL character (CWE-158). Affected versions include FortiMail 7.2.0–7.2.9, 7.4.0–7.4.8, 7.6.0–7.6.6, and 8.0.0–8.0.1. Disclosed on October 1, 2026, it was simultaneously added to CISA's Known Exploited Vulnerabilities (KEV) catalog, confirming active in-the-wild exploitation. It carries a CVSS v3.1 base score of 9.8 (Critical) (FortiGuard Advisory, CISA KEV, GitHub Advisory).

Dettagli tecnici

The vulnerability stems from insufficient validation of user-supplied path components in HTTP/HTTPS request handling within FortiMail's IBE (Identity-Based Encryption) feature, classified as CWE-22 (Path Traversal) and CWE-158 (Improper Neutralization of NULL Byte). An unauthenticated attacker can craft HTTP or HTTPS requests containing path traversal sequences (e.g., ../ or NULL byte-encoded variants) to escape the restricted web root and write arbitrary files to sensitive locations on the underlying operating system. No authentication or user interaction is required, and the attack is fully network-accessible with low complexity. The attack chain progresses from arbitrary file write to code execution, as evidenced by post-exploitation artifacts including a dropped shared library (/data/lib/liblog.so) and a modified ld.so.preload file (FortiGuard Advisory, GitHub Advisory).

Impatto

Successful exploitation enables an unauthenticated attacker to write arbitrary files anywhere on the FortiMail system, which in observed attacks has led to full system compromise including deployment of backdoors, web shells, and malicious shared libraries. The confirmed impact includes unauthorized code execution, potential exfiltration of email data and credentials processed by the mail gateway, and service disruption. Given FortiMail's role as an email security gateway, compromise could also facilitate interception of sensitive communications and lateral movement into internal networks (FortiGuard Advisory, CISA KEV).

Sfruttabilità

CVE-2026-104286 is actively exploited in the wild as a zero-day and was added to CISA's KEV catalog on October 1, 2026, with a remediation due date of October 4, 2026 — an unusually short window reflecting the severity of active exploitation (CISA KEV). Exploitation has been reported by watchTowr and BleepingComputer, with Fortinet confirming in-the-wild exploitation in its advisory (FortiGuard Advisory, BleepingComputer). The NVD SSVC assessment classifies exploitation as "active" and the vulnerability as "automatable," indicating it can be exploited at scale without manual intervention. No public proof-of-concept code has been confirmed, but the vulnerability is being weaponized by unknown threat actors. The EPSS score is currently 0.0 (newly published), though active exploitation makes this a high-priority remediation target (GitHub Advisory).

Passaggi di sfruttamento

  1. Reconnaissance: Identify internet-facing FortiMail instances using tools like Shodan or Censys, filtering for FortiMail web interfaces (typically on ports 443/80). Confirm version via HTTP response headers or login page banners to identify vulnerable versions (7.2.0–7.2.9, 7.4.0–7.4.8, 7.6.0–7.6.6, 8.0.0–8.0.1).
  2. Craft malicious HTTP request: Construct a crafted HTTP or HTTPS request targeting the IBE (Identity-Based Encryption) feature endpoint, embedding path traversal sequences (e.g., ../../) or NULL byte characters to escape the restricted directory context.
  3. Arbitrary file write: Submit the crafted request to write a malicious file to a sensitive system location — in observed attacks, attackers wrote a malicious shared library to /data/lib/liblog.so and modified /data/etc/ld.so.preload to force its loading.
  4. Achieve code execution: The injected shared library is loaded by system processes via the modified ld.so.preload, granting the attacker persistent code execution on the FortiMail appliance.
  5. Establish persistence: Deploy additional backdoors such as /data/bin/webconsole or /data/bin/mailservice, and modify httpd.conf to maintain access. Configure data exfiltration via archive accounts pointing to attacker-controlled infrastructure (e.g., 79.141.169.187) (FortiGuard Advisory).

Indicatori di compromesso

  • File System:
    • [ADDED] /data/lib/liblog.so — MD5: 64c90a00c7fda4d5c7973ed64c25783a, SHA256: 8015f34dc84922b03688399d7f9fe7a00361789f7e420c7e2a2cdb23e75cef84
    • [MODIFIED] /bin/smit — MD5: 5241738a3e9988404239e12243f6d35b, SHA256: 77324ac428bde86d351fc5fc06f6d64a6bfe737dfb2743df1d4c5ac2418a5b6a
    • [ADDED] /data/bin/webconsole — MD5: ae0ea6502d3fa5f0664bceb73189eb54, SHA256: 7a6cea9f5c9e2e9994d4e3c4da73f86cf5acd05ea5d312c066c9d1dafd69ee38
    • [ADDED] /data/bin/mailservice — MD5: f90fa81a5f521d785f2b2f765e3ab897, SHA256: 4000276a150a165d3c2537d1e19fb393c4de8333076a16655e28059cae82157b
    • [MODIFIED] /data/etc/httpd.conf — MD5: 61af1c4bce1c2eebc8ff689ca5337791, SHA256: 703e97c64e61e41dc3aaba580d82bb2aa7b6a11b54ee6fb467ed5d5a3bffdef5
    • [ADDED] /data/etc/ld.so.preload — MD5: 8eb64f25d2a8e18e05aae058629473cf, SHA256: 8953ec7960b09f544a880b072ad4e6cfda7a8303f486251d3478dcfdfbac23b6
    • [MODIFIED] /data/migadmin.tar.gz — MD5: 49a7156a7d043cc8f9f680579db22f86, SHA256: d6fe51c22b91776f4c961ea58bcac5917f15d560a619d7ce726d3d51795609d3
  • Network:
    • Outbound connections to 79.141.169.187 (attacker-controlled archive/exfiltration server)
    • Outbound connections to 45.129.0.192
    • Unusual HTTPS POST requests to IBE-related endpoints with path traversal sequences in parameters
  • Logs:
    • type=event subtype=system pri=debug user=system ui=cron msg="(root) CMD (/bin/sh -c 'O=/migadmin ..." — indicates cron-based persistence
    • type=kevent subtype=config ... msg="Added 'archive234' to 'archive account' ... remote-ip[79.141.169.187]" — unauthorized archive account creation pointing to attacker IP
    • type=kevent subtype=admin ... action=logout status=success reason=unknown msg="User admin logged out from (null)." — anomalous admin session activity
    • FortiMail IBE decryption errors: FortiMail::IBE::DecrypterMediaIn ... Caught BufferException(2) ... Invalid Base64 Encoding — may indicate exploitation attempts
    • Internal user *@domain.tld failed to log in — potential credential probing (FortiGuard Advisory)

Mitigazione e soluzioni alternative

Fortinet has released patched versions and organizations should upgrade immediately: FortiMail 8.0 → 8.0.2 or later; FortiMail 7.6 → 7.6.7 or later; FortiMail 7.4 → 7.4.9 or later; FortiMail 7.2 → upgrade to branch 7.4 or above (no 7.2.x patch available). As an immediate workaround, disable the IBE feature via CLI: config system encryption ibe → set status disable → end. Alternatively, restrict or block internet access to the FortiMail management interface, limiting access to trusted private networks only. CISA's BOD 26-04 requires federal agencies to apply mitigations by October 4, 2026, and also mandates forensic triage of potentially compromised systems (FortiGuard Advisory, CISA KEV).

Reazioni della comunità

Fortinet's PSIRT published advisory FG-IR-26-175 on October 1, 2026, confirming active exploitation and urging immediate mitigation (FortiGuard Advisory). BleepingComputer reported on the zero-day attacks, generating significant community discussion on Reddit (r/SecOpsDaily), Mastodon, and Bluesky (BleepingComputer). Security researchers at watchTowr published an FAQ on the vulnerability, and runZero published a blog post on detection and asset identification. The CISA KEV tracker Mastodon account flagged the addition immediately, and the security community broadly characterized this as a high-urgency incident given the three-day remediation window imposed by CISA's BOD 26-04.

Risorse aggiuntive


Fonte: Questo report è stato generato utilizzando l'intelligenza artificiale

Imparentato Fortimail Vulnerabilità:

CVE ID

Severità

Punteggio

Tecnologie

Nome del componente

Exploit CISA KEV

Ha la correzione

Data di pubblicazione

CVE-2026-104286CRITICAL9.8
  • Fortimail logoFortimail
  • cpe:2.3:a:fortinet:fortimail
SìNoOct 01, 2026
CVE-2025-53681HIGH7.2
  • Fortimail logoFortimail
  • cpe:2.3:a:fortinet:fortimail
NoSìMay 12, 2026
CVE-2025-54972MEDIUM4.3
  • Fortimail logoFortimail
  • cpe:2.3:a:fortinet:fortimail
NoSìNov 18, 2025
CVE-2024-47569MEDIUM4.3
  • FortiOS logoFortiOS
  • cpe:2.3:a:fortinet:fortimail
NoSìOct 14, 2025
CVE-2025-55717MEDIUM4
  • Fortimail logoFortimail
  • cpe:2.3:a:fortinet:fortimail
NoSìMar 10, 2026

Valutazione gratuita delle vulnerabilità

Benchmark della tua posizione di sicurezza del cloud

Valuta le tue pratiche di sicurezza cloud in 9 domini di sicurezza per confrontare il tuo livello di rischio e identificare le lacune nelle tue difese.

Richiedi valutazione

Richiedi una demo personalizzata

Pronti a vedere Wiz in azione?

"La migliore esperienza utente che abbia mai visto offre piena visibilità ai carichi di lavoro cloud."
David EstlickCISO (CISO)
"Wiz fornisce un unico pannello di controllo per vedere cosa sta succedendo nei nostri ambienti cloud."
Adam FletcherResponsabile della sicurezza
"Sappiamo che se Wiz identifica qualcosa come critico, in realtà lo è."
Greg PoniatowskiResponsabile della gestione delle minacce e delle vulnerabilità