SoftwareNews

FortiMail zero-day: what to do until the fixes ship

The FortiMail zero-day lets attackers write files with no login. Affected versions, the upcoming fixes, the IBE workaround and the October 4 CISA deadline.

Source-based. Written from the documents, reporting and reviews linked in the text. Nothing here was tested hands-on by The Ruling Desk. How we work

Illuminated white Fortinet lettering above a red-trimmed exhibition booth at a technology trade show
Photo: Dev Jadiya / Wikimedia Commons, CC BY-SA 4.0

A FortiMail zero-day, CVE-2026-104286, is being exploited to write files onto Fortinet's email security appliances without logging in, and as of October 2, 2026, the fixed builds are still listed as upcoming. Fortinet disclosed it on October 1, CISA added it to its exploited list the same day, and US federal agencies have until Sunday, October 4, to act. Here's which versions are affected, the two workarounds you can apply today, and the logs and files that show whether someone already got in.

Key takeaways

  • Confirmed exploited: Fortinet's advisory says the flaw "has been reported to be exploited in the wild." It scores 9.8 out of 10 and needs no password or user interaction.
  • Affected: FortiMail 8.0.0 to 8.0.1, 7.6.0 to 7.6.6, 7.4.0 to 7.4.8 and 7.2.0 to 7.2.9.
  • No fix to install yet: Fortinet names 8.0.2, 7.6.7 and 7.4.9 as the fixes but calls them "upcoming" as of October 2. The 7.2 branch gets no fix of its own; Fortinet says to move to 7.4 or later.
  • Workaround now: turn off Identity Based Encryption (IBE), or take the management interface off the internet.
  • The CISA deadline is October 4, 2026 for US federal civilian agencies, and it includes checking for compromise, not only mitigating.

What the FortiMail zero-day does

FortiMail is the appliance that sits in front of a company's mail server to filter spam, malware and data leaks. Fortinet's advisory FG-IR-26-175 describes two weaknesses working together in its web interface: a path traversal (CWE-22), where a crafted file path escapes the folder it should stay in, and poor handling of NULL bytes (CWE-158), the invisible character that can cut a file name short. With a crafted HTTP or HTTPS request, an unauthenticated attacker can write arbitrary files on the underlying system.

Writing files is close to running code. Fortinet lists the impact as "execute unauthorized code or commands," and its indicators show attackers adding programs and a preloaded library to the appliance. The company says it found the bug internally, credited to Gwendal Guégniaud of its product security team, and it rates the bug 9.8 on CVSS 3.

The workaround points at the entry point. Fortinet's main mitigation is to turn off IBE, the feature that lets FortiMail encrypt a message and have the recipient read it through a web portal, so the exploited path appears to run through that service. watchTowr's FAQ on CVE-2026-104286 reads it the same way and says appliances with IBE enabled are the most exposed.

Which FortiMail versions are affected and fixed

FortiMail branchAffected versionsFortinet's solution (as of October 2)
8.08.0.0 to 8.0.1Upgrade to upcoming 8.0.2 or later
7.67.6.0 to 7.6.6Upgrade to upcoming 7.6.7 or later
7.47.4.0 to 7.4.8Upgrade to upcoming 7.4.9 or later
7.27.2.0 to 7.2.9Upgrade to the 7.4 branch or later

The word "upcoming" matters. Some early write-ups list 8.0.2, 7.6.7 and 7.4.9 as if they were already out, but the advisory, which still shows only its October 1 first publication, calls them upcoming, and BleepingComputer reports that no patch was available when Fortinet published. Check Fortinet's support portal for the build before you schedule the upgrade, and apply a workaround in the meantime.

If you run 7.2, there is no 7.2.10 coming in the advisory. Your path is a branch upgrade to 7.4, which means waiting for 7.4.9 anyway, so plan that jump now and lean on the workaround until then.

A white Fortinet FortiGate 6501F firewall mounted below a black server in a rack, with network cables plugged into its front ports
A Fortinet FortiGate firewall, a different product from FortiMail. Photo: DiFronzo / Wikimedia Commons, CC BY 2.0

How to apply the FortiMail workaround

Fortinet gives two options in the advisory. Either one is a stopgap, not a fix.

  1. Turn off IBE. In the web interface, go to Encryption > IBE > IBE Service and switch it off. From the command line:

    config system encryption ibe
    set status disable
    end
    
  2. Lock down the management interface. Block access to the FortiMail management interface from the internet, or allow it only from a trusted private network.

Turning off FortiMail IBE has a cost. Fortinet's IBE documentation explains that recipients read encrypted messages by registering and logging in to a web portal, so with the service off, that encrypted delivery stops working until you turn it back on. If your company depends on it, the management lockdown is the option to start with, but it still leaves anyone already on your network able to reach the interface.

How to check for signs of compromise

Do this before you change anything, so the evidence survives. The advisory lists these indicators, each file with its MD5 and SHA-256 hashes:

FileWhat Fortinet says happened
/data/lib/liblog.soAdded
/data/bin/webconsoleAdded
/data/bin/mailserviceAdded
/data/etc/ld.so.preloadAdded
/bin/smitModified
/data/etc/httpd.confModified
/data/migadmin.tar.gzModified

In the logs, look for:

  • Connections from 79.141.169.187 or 45.129.0.192, the two attacker IP addresses Fortinet published.
  • A root cron job running /bin/sh -c 'O=/migadmin ... in the system event log.
  • An "admin logged out from (null)" event, which Fortinet lists among the indicators.
  • A new archive account with a remote destination, such as the example in the advisory, archive234, set to send to 79.141.169.187. Archive accounts copy mail to a storage location, so we read this one as a sign the attackers may have arranged for mail to be copied to their server. Fortinet hasn't said what data was taken.
  • IBE decryption errors mentioning "Invalid Base64 Encoding" and failed logins by internal users with a wildcard address like *@domain.tld.

watchTowr adds three steps to that list: preserve logs and forensic images before you clean anything, compare the appliance against Fortinet's indicators, and rotate administrator credentials. If you find a match, treat the box as compromised, not just vulnerable.

Why the October 4 deadline matters

CISA added CVE-2026-104286 to its Known Exploited Vulnerabilities catalog on October 1. The catalog entry sets a due date of October 4, 2026, three days later, under Binding Operational Directive 26-04, and its required action includes forensic triage alongside Fortinet's mitigations. Known ransomware use is listed as "Unknown" as of October 2.

The deadline only binds US federal civilian agencies. Because no fixed build is out yet, meeting it means the workaround plus a compromise check, which is the same order every FortiMail admin should follow.

What happens next

The open question is when 8.0.2, 7.6.7 and 7.4.9 land; watch the advisory's timeline for a revision. BleepingComputer reports that Fortinet says it is coordinating with government agencies, including CISA. As of October 2, Fortinet hasn't said who is behind the attacks or how many appliances were hit.

It's the third exploited zero-day in an edge appliance we've covered this week. The Cisco SD-WAN zero-day and the NetScaler zero-days follow the same order: check for compromise, mitigate, then patch. The Hacker News has a summary of the FortiMail flaw with the indicators in one place.

Bottom line

If you run FortiMail 7.2 through 8.0.1, this FortiMail zero-day is confirmed exploited by Fortinet and CISA, and there is no fixed build to install yet as of October 2. Check the appliance against Fortinet's files, IP addresses and log entries first, then turn off IBE or take the management interface off the internet. Upgrade to 8.0.2, 7.6.7 or 7.4.9 the day they ship; on 7.2, plan the move to 7.4. Federal agencies have until October 4.

FAQ

Is CVE-2026-104286 being exploited?

Yes. Fortinet's advisory says it has been reported as exploited in the wild, and CISA added it to its Known Exploited Vulnerabilities catalog on October 1, 2026. Neither has said how many appliances were attacked or by whom.

Is there a patch for the FortiMail vulnerability?

Not yet, as of October 2, 2026. Fortinet names 8.0.2, 7.6.7 and 7.4.9 as the fixed versions but labels them "upcoming." Until they ship, its advisory says to apply a workaround.

What should I do if I'm on FortiMail 7.2?

Fortinet doesn't plan a 7.2 fix in the advisory. It says to upgrade to the 7.4 branch or later, and the 7.4 fix, 7.4.9, is also still upcoming. Use a workaround now and plan the branch upgrade.

Does turning off IBE break anything?

It stops Identity Based Encryption, so recipients can't read encrypted messages through FortiMail's portal while it's off. If you need IBE, Fortinet's other option is to block the management interface from the internet and allow only trusted private networks.

Filed under Software

Newsletter

New articles, in your inbox.

Free. Unsubscribe in one click. Your email is kept by beehiiv, our newsletter service, and used only for this newsletter.