CVE-2026-104286: FortiMail Zero-Day Is Being Exploited - Workaround and Compromise Assessment
Fortinet reports a critical, actively exploited path traversal vulnerability in FortiMail 7.2 through 8.0 (CVE-2026-104286, CVSS 9.8). A patch is not yet available. The workaround disables IBE or blocks Internet access to the management interface; indicators for assessing compromise are also available.
On October 1, 2026, Fortinet published advisory FG-IR-26-175 concerning a critical vulnerability in FortiMail. Using crafted HTTP or HTTPS requests, an unauthenticated attacker can write arbitrary files to the underlying system and thereby execute code. The vulnerability is identified as CVE-2026-104286 and has a CVSS score of 9.8. Fortinet confirms that it is already being exploited; the US agency CISA added it to its Known Exploited Vulnerabilities (KEV) catalog on the same day. As of October 2, no update is available, only a workaround.
Support with the workaround and compromise assessment
If you need help implementing the workaround, assessing compromise, or applying the update later, please use the contact form on adeptio.ch. I can also get back to you at short notice.
Certified: Fortinet FortiMail 7.4 Administrator
I am certified by Fortinet as a FortiMail 7.4 Administrator. The examination covers deployment, administration, ongoing operation, and troubleshooting of FortiMail. View badge on Credly
Key facts at a glance
| Feature | Details |
|---|---|
| Advisory | FG-IR-26-175, published October 1, 2026 |
| CVE | CVE-2026-104286 |
| Rating | CVSS 3.1: 9.8 (critical), AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Vulnerability type | Path traversal (CWE-22) and insufficiently filtered NULL characters (CWE-158) |
| Prerequisite | no authentication, HTTP or HTTPS access to the web interface |
| Component according to the advisory | GUI |
| Exploitation | confirmed; CISA KEV since October 1, 2026 |
| Update | announced, not available as of October 2 |
| Workaround | disable IBE or block Internet access to the management interface |
| Discovered by | Fortinet internally (Gwendal Guégniaud) |
Timeline
All times are Central European Summer Time (CEST). Where no time is specified, no reliable time information is available.
-
Wed, October 1
Advisory FG-IR-26-175
Fortinet publishes the advisory with affected versions, a workaround, and indicators. Exploitation is already known at this point; according to the advisory, no virtual patch for FortiGate IPS is available.
-
Wed, October 1, 08:46
Report by heise online
heise reports on the ongoing attacks and the workaround; according to the report, updates to fix the vulnerability are still pending.
-
Wed, October 1
Added to the CISA catalog
CISA adds CVE-2026-104286 to the Known Exploited Vulnerabilities catalog. According to BleepingComputer and The Hacker News, US federal agencies must implement updates or workarounds by October 4.
-
As of Thu, October 2
Still unpatched
Fixed versions 8.0.2, 7.6.7, and 7.4.9 have been announced but not released. No information is available on the scale of the attacks, affected organizations, or the attackers' origin.
Affected versions
| Branch | Affected | Solution according to the advisory |
|---|---|---|
| FortiMail 8.0 | 8.0.0 through 8.0.1 | Update to 8.0.2 or later (announced) |
| FortiMail 7.6 | 7.6.0 through 7.6.6 | Update to 7.6.7 or later (announced) |
| FortiMail 7.4 | 7.4.0 through 7.4.8 | Update to 7.4.9 or later (announced) |
| FortiMail 7.2 | 7.2.0 through 7.2.9 | No fix in the 7.2 branch; upgrade to 7.4 or later |
No update will be released for the 7.2 branch; these systems must upgrade to 7.4 or later. Planning the upgrade path from the release notes now will shorten the time to update once the fixed version is released. Until then, the workaround is the only option.
The CLI displays the current version with:
get system status
Immediate action: implement the workaround
Fortinet provides two options. According to the advisory, one of them is sufficient; where operations permit, both are advisable.
Option 1: Disable IBE
IBE (Identity-Based Encryption) is the feature FortiMail uses to deliver encrypted messages to external recipients: the recipient receives the message as an encrypted attachment (push) or retrieves it through the FortiMail web portal (pull). Fortinet identifies the IBE feature as the workaround, so the attacks use a code path in this feature. Disable it in the CLI:
config system encryption ibe
set status disable
end
Check the status before and after with:
show system encryption ibe
Disabling it has implications for mail traffic. Fortinet does not describe them in the advisory. Before making the change, you should therefore clarify:
-
Which policies use IBE: IBE is configured as an encryption action in content and policy profiles, such as for subject keywords like
[secure]or data protection rules. These messages can no longer be delivered encrypted through IBE while it is disabled. -
How these messages should be handled: hold them, deliver them using another method (S/MIME, mandatory TLS), or provide feedback to the senders. Unencrypted delivery of messages that a policy is intended to encrypt is generally not permissible.
-
Who is affected: External recipients retrieving messages in the IBE portal and users sending encrypted messages should be informed.
Option 2: Block Internet access to the management interface
The second option blocks Internet access to the management interface or restricts it to trusted private networks, such as a management network or VPN. This can be implemented on an upstream firewall or through the interface access settings in FortiMail (Administrative Access).
Webmail, users’ quarantine access, and the IBE portal also use HTTPS. If they are on the same interface as management, a blanket HTTPS block will also block these services. In this case, option 1 is the more direct approach. SMTP on port 25 is not affected by either option; mail flow continues.
Assessing compromise
Because the vulnerability was exploited before the advisory, the workaround does not rule out an earlier attack. Fortinet publishes indicators in the advisory that can be used to assess a system.
Files
Fortinet found the following files on compromised systems. The advisory also provides hash values; the list in the advisory is authoritative for comparison.
| Path |
|---|
/data/lib/liblog.so |
/data/etc/ld.so.preload |
/bin/smit |
/data/bin/webconsole |
/data/bin/mailservice |
/data/etc/httpd.conf |
/data/migadmin.tar.gz |
An entry in /data/etc/ld.so.preload preloads the specified library into every process. Together with liblog.so, this indicates a persistent backdoor that survives a restart.
IP addresses
| Address |
|---|
79.141.169.187 |
45.129.0.192 |
These addresses should be searched for in the logs of FortiMail, the upstream firewall, and reverse proxy, and blocked until further notice.
Log entries
The advisory identifies three patterns in FortiMail system logs:
-
Cron entries for user
rootthat launch a shell related to/migadmin, such astype=event subtype=system pri=debug user=system ui=cron msg="(root) CMD (/bin/sh -c 'O=/migadmin.... -
Configuration of archive accounts with remote IP
79.141.169.187. An archive account can store copies of messages at an external destination. -
Base64 decoding errors in the IBE decrypter and conspicuous failed login attempts.
Matches for any of these indicators mean the system is considered compromised. Before making any changes, logs and configuration should be secured so that forensic analysis remains possible. An update alone does not remove an established backdoor. Remediation includes reinstalling from a trusted source, restoring a verified configuration, and changing all credentials stored on the system: administrator accounts, LDAP bind accounts, SMTP authentication credentials, and certificate private keys. Archive accounts and forwarding rules should be checked for unknown destinations, as they may be used to exfiltrate message contents.
Context
Mail gateways sit at the network perimeter and process an organization’s entire message traffic. A vulnerability that executes code without authentication gives an attacker access to message contents, stored credentials, and key material. This is not the first case involving FortiMail: in May 2025, CVE-2025-32756 (FG-IR-25-254, CVSS 9.6) affected FortiMail as well as FortiVoice; at that time, the vulnerability was demonstrably exploited on FortiVoice systems.
At the end of September, Kiteworks also urged its customers to shut down their systems as a precaution following a warning from law enforcement agencies; the circumstances remain unclear (Kiteworks: shutdown recommendation on September 26). No connection between the two cases is known.
What to do now
-
Determine the version using
get system statusand compare it with the table of affected versions. -
Check indicators and secure logs before making changes to the system.
-
Implement the workaround: Disable IBE or block Internet access to the management interface, after clarifying the impact on encrypted deliveries.
-
Block IP addresses and search for them retrospectively in firewall logs.
-
Plan the update: Install the fixed version as soon as it is released; upgrade systems on 7.2 to 7.4 or later.
-
Monitor the advisory: Fortinet will update FG-IR-26-175 as new information becomes available; the revision history is at the end of the advisory.
Comments
Comments are loaded from GitHub / Giscus.