Intel Hub

Threat intel

A critical FortiMail flaw is being exploited to write arbitrary files.

CVE-2026-104286 (CVSS 9.8) lets unauthenticated attackers write files to FortiMail appliances. CISA added it to KEV on October 1; federal deadline is October 4.

Fortinet has patched CVE-2026-104286, a critical FortiMail flaw that attackers are already exploiting. It carries a CVSS score of 9.8. CISA added it to its Known Exploited Vulnerabilities catalog on October 1, 2026, per The Hacker News.


The bug is a path traversal (CWE-22) combined with a failure to neutralize NULL characters (CWE-158). An unauthenticated attacker can send crafted HTTP or HTTPS requests and write arbitrary files to the underlying system. Fortinet's own Product Security team found it; Gwendal Guégniaud is credited as the reporter.


Why it matters: FortiMail sits on the mail path and is internet-facing in many deployments. An arbitrary file write with no authentication is a short step from persistent code execution on the appliance. Federal civilian agencies must patch or apply workarounds by October 4, 2026.


Affected versions: FortiMail 8.0.0 to 8.0.1, 7.6.0 to 7.6.6, 7.4.0 to 7.4.8, and 7.2.0 to 7.2.9. Fixed releases are 8.0.2, 7.6.7 and 7.4.9. Customers on 7.2 should move to the 7.4 branch.


Indicators of compromise reported by The Hacker News: source IPs 79.141.169[.]187 and 45.129.0[.]192. Modified or added files include liblog.so, webconsole, mailservice, ld.so.preload, smit, httpd.conf and migadmin.tar.gz. A modified ld.so.preload is a classic userland-rootkit loading point, so treat it as high-confidence.


Mitigation: upgrade to a fixed release now. If you can't patch immediately, disable the IBE feature via the CLI and restrict the management interface to trusted networks. Hunt for the files and IPs above, and review web server logs for path traversal sequences and encoded NULL bytes. If any indicator matches, treat the appliance as compromised and rebuild it rather than patching in place.

Sign-in required.

The full encrypted event log and the mitigation steps are available after sign-in.