2 October 2026 8 min read

CVE-2026-104286: FortiMail Zero-Day Is Being Exploited - Workaround and Compromise Assessment

Fortinet reports a critical, actively exploited path traversal vulnerability in FortiMail 7.2 through 8.0 (CVE-2026-104286, CVSS 9.8). A patch is not yet available. The workaround disables IBE or blocks Internet access to the management interface; indicators for assessing compromise are also available.

On October 1, 2026, Fortinet published advisory FG-IR-26-175 concerning a critical vulnerability in FortiMail. Using crafted HTTP or HTTPS requests, an unauthenticated attacker can write arbitrary files to the underlying system and thereby execute code. The vulnerability is identified as CVE-2026-104286 and has a CVSS score of 9.8. Fortinet confirms that it is already being exploited; the US agency CISA added it to its Known Exploited Vulnerabilities (KEV) catalog on the same day. As of October 2, no update is available, only a workaround.

Support with the workaround and compromise assessment

If you need help implementing the workaround, assessing compromise, or applying the update later, please use the contact form on adeptio.ch. I can also get back to you at short notice.

Badge Fortinet FortiMail 7.4 Administrator

Certified: Fortinet FortiMail 7.4 Administrator

I am certified by Fortinet as a FortiMail 7.4 Administrator. The examination covers deployment, administration, ongoing operation, and troubleshooting of FortiMail. View badge on Credly

Key facts at a glance

FeatureDetails
AdvisoryFG-IR-26-175, published October 1, 2026
CVECVE-2026-104286
RatingCVSS 3.1: 9.8 (critical), AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability typePath traversal (CWE-22) and insufficiently filtered NULL characters (CWE-158)
Prerequisiteno authentication, HTTP or HTTPS access to the web interface
Component according to the advisoryGUI
Exploitationconfirmed; CISA KEV since October 1, 2026
Updateannounced, not available as of October 2
Workarounddisable IBE or block Internet access to the management interface
Discovered byFortinet internally (Gwendal Guégniaud)

Timeline

All times are Central European Summer Time (CEST). Where no time is specified, no reliable time information is available.

  1. Wed, October 1

    Advisory FG-IR-26-175

    Fortinet publishes the advisory with affected versions, a workaround, and indicators. Exploitation is already known at this point; according to the advisory, no virtual patch for FortiGate IPS is available.

  2. Wed, October 1, 08:46

    Report by heise online

    heise reports on the ongoing attacks and the workaround; according to the report, updates to fix the vulnerability are still pending.

  3. Wed, October 1

    Added to the CISA catalog

    CISA adds CVE-2026-104286 to the Known Exploited Vulnerabilities catalog. According to BleepingComputer and The Hacker News, US federal agencies must implement updates or workarounds by October 4.

  4. As of Thu, October 2

    Still unpatched

    Fixed versions 8.0.2, 7.6.7, and 7.4.9 have been announced but not released. No information is available on the scale of the attacks, affected organizations, or the attackers' origin.

Affected versions

BranchAffectedSolution according to the advisory
FortiMail 8.08.0.0 through 8.0.1Update to 8.0.2 or later (announced)
FortiMail 7.67.6.0 through 7.6.6Update to 7.6.7 or later (announced)
FortiMail 7.47.4.0 through 7.4.8Update to 7.4.9 or later (announced)
FortiMail 7.27.2.0 through 7.2.9No fix in the 7.2 branch; upgrade to 7.4 or later

No update will be released for the 7.2 branch; these systems must upgrade to 7.4 or later. Planning the upgrade path from the release notes now will shorten the time to update once the fixed version is released. Until then, the workaround is the only option.

The CLI displays the current version with:

get system status

Immediate action: implement the workaround

Fortinet provides two options. According to the advisory, one of them is sufficient; where operations permit, both are advisable.

Option 1: Disable IBE

IBE (Identity-Based Encryption) is the feature FortiMail uses to deliver encrypted messages to external recipients: the recipient receives the message as an encrypted attachment (push) or retrieves it through the FortiMail web portal (pull). Fortinet identifies the IBE feature as the workaround, so the attacks use a code path in this feature. Disable it in the CLI:

config system encryption ibe
    set status disable
end
Options explained
OptionEffect
config system encryption ibeopens the global IBE settings
set status disabledisables IBE system-wide
endsaves the change and exits the configuration section

Check the status before and after with:

show system encryption ibe

Disabling it has implications for mail traffic. Fortinet does not describe them in the advisory. Before making the change, you should therefore clarify:

  1. Which policies use IBE: IBE is configured as an encryption action in content and policy profiles, such as for subject keywords like [secure] or data protection rules. These messages can no longer be delivered encrypted through IBE while it is disabled.

  2. How these messages should be handled: hold them, deliver them using another method (S/MIME, mandatory TLS), or provide feedback to the senders. Unencrypted delivery of messages that a policy is intended to encrypt is generally not permissible.

  3. Who is affected: External recipients retrieving messages in the IBE portal and users sending encrypted messages should be informed.

Option 2: Block Internet access to the management interface

The second option blocks Internet access to the management interface or restricts it to trusted private networks, such as a management network or VPN. This can be implemented on an upstream firewall or through the interface access settings in FortiMail (Administrative Access).

Webmail, users’ quarantine access, and the IBE portal also use HTTPS. If they are on the same interface as management, a blanket HTTPS block will also block these services. In this case, option 1 is the more direct approach. SMTP on port 25 is not affected by either option; mail flow continues.

Assessing compromise

Because the vulnerability was exploited before the advisory, the workaround does not rule out an earlier attack. Fortinet publishes indicators in the advisory that can be used to assess a system.

Files

Fortinet found the following files on compromised systems. The advisory also provides hash values; the list in the advisory is authoritative for comparison.

Path
/data/lib/liblog.so
/data/etc/ld.so.preload
/bin/smit
/data/bin/webconsole
/data/bin/mailservice
/data/etc/httpd.conf
/data/migadmin.tar.gz

An entry in /data/etc/ld.so.preload preloads the specified library into every process. Together with liblog.so, this indicates a persistent backdoor that survives a restart.

IP addresses

Address
79.141.169.187
45.129.0.192

These addresses should be searched for in the logs of FortiMail, the upstream firewall, and reverse proxy, and blocked until further notice.

Log entries

The advisory identifies three patterns in FortiMail system logs:

  1. Cron entries for user root that launch a shell related to /migadmin, such as type=event subtype=system pri=debug user=system ui=cron msg="(root) CMD (/bin/sh -c 'O=/migadmin....

  2. Configuration of archive accounts with remote IP 79.141.169.187. An archive account can store copies of messages at an external destination.

  3. Base64 decoding errors in the IBE decrypter and conspicuous failed login attempts.

Matches for any of these indicators mean the system is considered compromised. Before making any changes, logs and configuration should be secured so that forensic analysis remains possible. An update alone does not remove an established backdoor. Remediation includes reinstalling from a trusted source, restoring a verified configuration, and changing all credentials stored on the system: administrator accounts, LDAP bind accounts, SMTP authentication credentials, and certificate private keys. Archive accounts and forwarding rules should be checked for unknown destinations, as they may be used to exfiltrate message contents.

Context

Mail gateways sit at the network perimeter and process an organization’s entire message traffic. A vulnerability that executes code without authentication gives an attacker access to message contents, stored credentials, and key material. This is not the first case involving FortiMail: in May 2025, CVE-2025-32756 (FG-IR-25-254, CVSS 9.6) affected FortiMail as well as FortiVoice; at that time, the vulnerability was demonstrably exploited on FortiVoice systems.

At the end of September, Kiteworks also urged its customers to shut down their systems as a precaution following a warning from law enforcement agencies; the circumstances remain unclear (Kiteworks: shutdown recommendation on September 26). No connection between the two cases is known.

What to do now

  1. Determine the version using get system status and compare it with the table of affected versions.

  2. Check indicators and secure logs before making changes to the system.

  3. Implement the workaround: Disable IBE or block Internet access to the management interface, after clarifying the impact on encrypted deliveries.

  4. Block IP addresses and search for them retrospectively in firewall logs.

  5. Plan the update: Install the fixed version as soon as it is released; upgrade systems on 7.2 to 7.4 or later.

  6. Monitor the advisory: Fortinet will update FG-IR-26-175 as new information becomes available; the revision history is at the end of the advisory.

Sources

  1. Fortinet PSIRT: FG-IR-26-175

    Advisory with description, CVSS vector, affected versions, workaround, and indicators (files, hashes, IP addresses, log entries).

    https://fortiguard.fortinet.com/psirt/FG-IR-26-175
  2. heise online: FortiMail: Attacks on zero-day vulnerability underway, workaround available

    Report from October 1, 2026, with the workaround and a note about missing updates.

    https://www.heise.de/news/FortiMail-Angriffe-auf-Zero-Day-Luecke-laufen-Workaround-verfuegbar-11473599.html
  3. CISA: CISA Adds One Known Exploited Vulnerability to Catalog
  4. BleepingComputer: Fortinet warns of critical FortiMail flaw exploited in zero-day attacks
  5. The Hacker News: Critical FortiMail Zero-Day Flaw Exploited in Attacks
  6. watchTowr: Fortinet FortiMail FAQ: CVE-2026-104286

    Context on the IBE code path and recommendation to secure evidence before remediation.

    https://watchtowr.com/intelligence/fortinet-fortimail-cve-2026-104286-faq/
  7. Fortinet PSIRT: FG-IR-25-254

    Advisory for CVE-2025-32756 (May 2025), stack overflow in FortiVoice, FortiMail, and other products.

    https://fortiguard.fortinet.com/psirt/FG-IR-25-254
  8. Fortinet Document Library: FortiMail

    Release notes and Administration Guide, including the CLI reference for system encryption ibe.

    https://docs.fortinet.com/product/fortimail
  9. Credly: Fortinet FortiMail 7.4 Administrator

Comments

Comments are loaded from GitHub / Giscus.