Vulnerability DatabaseCVE-2026-104286

CVE-2026-104286: 
Fortimail vulnerability analysis and mitigation

Overview

CVE-2026-104286 is a critical path traversal vulnerability (CWE-22) in Fortinet FortiMail that allows unauthenticated remote attackers to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. The vulnerability also involves improper neutralization of NULL byte or NULL character (CWE-158). Affected versions include FortiMail 7.2.0–7.2.9, 7.4.0–7.4.8, 7.6.0–7.6.6, and 8.0.0–8.0.1. Disclosed on October 1, 2026, it was simultaneously added to CISA's Known Exploited Vulnerabilities (KEV) catalog, confirming active in-the-wild exploitation. It carries a CVSS v3.1 base score of 9.8 (Critical) (FortiGuard Advisory, CISA KEV, GitHub Advisory).

Technical details

The vulnerability stems from insufficient validation of user-supplied path components in HTTP/HTTPS request handling within FortiMail's IBE (Identity-Based Encryption) feature, classified as CWE-22 (Path Traversal) and CWE-158 (Improper Neutralization of NULL Byte). An unauthenticated attacker can craft HTTP or HTTPS requests containing path traversal sequences (e.g., ../ or NULL byte-encoded variants) to escape the restricted web root and write arbitrary files to sensitive locations on the underlying operating system. No authentication or user interaction is required, and the attack is fully network-accessible with low complexity. The attack chain progresses from arbitrary file write to code execution, as evidenced by post-exploitation artifacts including a dropped shared library (/data/lib/liblog.so) and a modified ld.so.preload file (FortiGuard Advisory, GitHub Advisory).

Impact

Successful exploitation enables an unauthenticated attacker to write arbitrary files anywhere on the FortiMail system, which in observed attacks has led to full system compromise including deployment of backdoors, web shells, and malicious shared libraries. The confirmed impact includes unauthorized code execution, potential exfiltration of email data and credentials processed by the mail gateway, and service disruption. Given FortiMail's role as an email security gateway, compromise could also facilitate interception of sensitive communications and lateral movement into internal networks (FortiGuard Advisory, CISA KEV).

Exploitability

CVE-2026-104286 is actively exploited in the wild as a zero-day and was added to CISA's KEV catalog on October 1, 2026, with a remediation due date of October 4, 2026 — an unusually short window reflecting the severity of active exploitation (CISA KEV). Exploitation has been reported by watchTowr and BleepingComputer, with Fortinet confirming in-the-wild exploitation in its advisory (FortiGuard Advisory, BleepingComputer). The NVD SSVC assessment classifies exploitation as "active" and the vulnerability as "automatable," indicating it can be exploited at scale without manual intervention. No public proof-of-concept code has been confirmed, but the vulnerability is being weaponized by unknown threat actors. The EPSS score is currently 0.0 (newly published), though active exploitation makes this a high-priority remediation target (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing FortiMail instances using tools like Shodan or Censys, filtering for FortiMail web interfaces (typically on ports 443/80). Confirm version via HTTP response headers or login page banners to identify vulnerable versions (7.2.0–7.2.9, 7.4.0–7.4.8, 7.6.0–7.6.6, 8.0.0–8.0.1).
  2. Craft malicious HTTP request: Construct a crafted HTTP or HTTPS request targeting the IBE (Identity-Based Encryption) feature endpoint, embedding path traversal sequences (e.g., ../../) or NULL byte characters to escape the restricted directory context.
  3. Arbitrary file write: Submit the crafted request to write a malicious file to a sensitive system location — in observed attacks, attackers wrote a malicious shared library to /data/lib/liblog.so and modified /data/etc/ld.so.preload to force its loading.
  4. Achieve code execution: The injected shared library is loaded by system processes via the modified ld.so.preload, granting the attacker persistent code execution on the FortiMail appliance.
  5. Establish persistence: Deploy additional backdoors such as /data/bin/webconsole or /data/bin/mailservice, and modify httpd.conf to maintain access. Configure data exfiltration via archive accounts pointing to attacker-controlled infrastructure (e.g., 79.141.169.187) (FortiGuard Advisory).

Indicators of compromise

  • File System:
    • [ADDED] /data/lib/liblog.so — MD5: 64c90a00c7fda4d5c7973ed64c25783a, SHA256: 8015f34dc84922b03688399d7f9fe7a00361789f7e420c7e2a2cdb23e75cef84
    • [MODIFIED] /bin/smit — MD5: 5241738a3e9988404239e12243f6d35b, SHA256: 77324ac428bde86d351fc5fc06f6d64a6bfe737dfb2743df1d4c5ac2418a5b6a
    • [ADDED] /data/bin/webconsole — MD5: ae0ea6502d3fa5f0664bceb73189eb54, SHA256: 7a6cea9f5c9e2e9994d4e3c4da73f86cf5acd05ea5d312c066c9d1dafd69ee38
    • [ADDED] /data/bin/mailservice — MD5: f90fa81a5f521d785f2b2f765e3ab897, SHA256: 4000276a150a165d3c2537d1e19fb393c4de8333076a16655e28059cae82157b
    • [MODIFIED] /data/etc/httpd.conf — MD5: 61af1c4bce1c2eebc8ff689ca5337791, SHA256: 703e97c64e61e41dc3aaba580d82bb2aa7b6a11b54ee6fb467ed5d5a3bffdef5
    • [ADDED] /data/etc/ld.so.preload — MD5: 8eb64f25d2a8e18e05aae058629473cf, SHA256: 8953ec7960b09f544a880b072ad4e6cfda7a8303f486251d3478dcfdfbac23b6
    • [MODIFIED] /data/migadmin.tar.gz — MD5: 49a7156a7d043cc8f9f680579db22f86, SHA256: d6fe51c22b91776f4c961ea58bcac5917f15d560a619d7ce726d3d51795609d3
  • Network:
    • Outbound connections to 79.141.169.187 (attacker-controlled archive/exfiltration server)
    • Outbound connections to 45.129.0.192
    • Unusual HTTPS POST requests to IBE-related endpoints with path traversal sequences in parameters
  • Logs:
    • type=event subtype=system pri=debug user=system ui=cron msg="(root) CMD (/bin/sh -c 'O=/migadmin ..." — indicates cron-based persistence
    • type=kevent subtype=config ... msg="Added 'archive234' to 'archive account' ... remote-ip[79.141.169.187]" — unauthorized archive account creation pointing to attacker IP
    • type=kevent subtype=admin ... action=logout status=success reason=unknown msg="User admin logged out from (null)." — anomalous admin session activity
    • FortiMail IBE decryption errors: FortiMail::IBE::DecrypterMediaIn ... Caught BufferException(2) ... Invalid Base64 Encoding — may indicate exploitation attempts
    • Internal user *@domain.tld failed to log in — potential credential probing (FortiGuard Advisory)

Mitigation and workarounds

Fortinet has released patched versions and organizations should upgrade immediately: FortiMail 8.0 → 8.0.2 or later; FortiMail 7.6 → 7.6.7 or later; FortiMail 7.4 → 7.4.9 or later; FortiMail 7.2 → upgrade to branch 7.4 or above (no 7.2.x patch available). As an immediate workaround, disable the IBE feature via CLI: config system encryption ibe → set status disable → end. Alternatively, restrict or block internet access to the FortiMail management interface, limiting access to trusted private networks only. CISA's BOD 26-04 requires federal agencies to apply mitigations by October 4, 2026, and also mandates forensic triage of potentially compromised systems (FortiGuard Advisory, CISA KEV).

Community reactions

Fortinet's PSIRT published advisory FG-IR-26-175 on October 1, 2026, confirming active exploitation and urging immediate mitigation (FortiGuard Advisory). BleepingComputer reported on the zero-day attacks, generating significant community discussion on Reddit (r/SecOpsDaily), Mastodon, and Bluesky (BleepingComputer). Security researchers at watchTowr published an FAQ on the vulnerability, and runZero published a blog post on detection and asset identification. The CISA KEV tracker Mastodon account flagged the addition immediately, and the security community broadly characterized this as a high-urgency incident given the three-day remediation window imposed by CISA's BOD 26-04.

Additional resources


Source: This report was generated using AI

Related Fortimail vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-104286CRITICAL9.8
  • Fortimail logoFortimail
  • cpe:2.3:a:fortinet:fortimail
YesNoOct 01, 2026
CVE-2025-53681HIGH7.2
  • Fortimail logoFortimail
  • cpe:2.3:a:fortinet:fortimail
NoYesMay 12, 2026
CVE-2025-54972MEDIUM4.3
  • Fortimail logoFortimail
  • cpe:2.3:a:fortinet:fortimail
NoYesNov 18, 2025
CVE-2024-47569MEDIUM4.3
  • FortiOS logoFortiOS
  • cpe:2.3:o:fortinet:fortios
NoYesOct 14, 2025
CVE-2025-55717MEDIUM4
  • Fortimail logoFortimail
  • cpe:2.3:a:fortinet:fortimail
NoYesMar 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management