FortiMail zero-day CVE-2026-104286 exploited; CISA sets Oct 4
Fortinet says CVE-2026-104286, a CVSS 9.8 path-traversal flaw in FortiMail, is exploited in the wild; patch to 7.4.9/7.6.7/8.0.2 and hunt the published IOCs.
Fortinet is warning that CVE-2026-104286, a CVSS 9.8 flaw in FortiMail, is being exploited in the wild as a zero-day. An unauthenticated attacker can write arbitrary files to the appliance over crafted HTTP/HTTPS, the pre-auth foothold that turns a mail gateway into an attacker's. CISA added it to the KEV catalog on October 1; federal agencies must triage and mitigate by October 4.
What the bug does
Per the Fortinet advisory FG-IR-26-175, the flaw chains a path traversal (CWE-22) with improper neutralization of a NULL byte (CWE-158): "an unauthenticated attacker" can "write arbitrary files on the underlying system via crafted HTTP or HTTPS requests." The advisory credits Gwendal Guégniaud of Fortinet's own Product Security team with finding it — internal discovery, but exploitation beat the fix.
Affected versions
Fortinet lists the vulnerable branches and fixes:
- 8.0.0–8.0.1 → upgrade to 8.0.2
- 7.6.0–7.6.6 → upgrade to 7.6.7
- 7.4.0–7.4.8 → upgrade to 7.4.9
- 7.2.0–7.2.9 → migrate to a fixed 7.4+ build
Exploitation status
Fortinet states the flaw "has been reported to be exploited in the wild," and CISA's KEV add on October 1 reflects confirmed exploitation, not speculation. The advisory ships indicators of compromise. The reported network and account artifacts, per FG-IR-26-175:
IP: 79.141.169.187
IP: 45.129.0.192
Account: archive234
Fortinet also lists file hashes for implanted/modified components (including a tampered ld.so.preload and a dropped liblog.so) — pull the full hash set from the advisory rather than from any secondary writeup, and do not paraphrase them into your detections.
Action checklist
- Patch now to 8.0.2, 7.6.7, or 7.4.9. Move 7.2.x appliances to a fixed 7.4+ build.
- If you cannot patch immediately, apply Fortinet's workarounds: disable Identity-Based Encryption (IBE) via the CLI, and take the FortiMail management interface off the internet or restrict it to a trusted network.
- Hunt for compromise on any internet-exposed FortiMail: check for the
archive234account, connections to the two IPs above, and the file hashes from FG-IR-26-175. A pre-auth file write means assume persistence until proven otherwise. - Rotate secrets handled by the gateway if you find any IOC hit.
Context
This is another pre-auth hole in an internet-facing Fortinet security appliance — the same class as the FortiSandbox unauth RCE we covered earlier this year. Mail gateways sit in front of everything and terminate untrusted traffic by design; a 9.8 that needs no credentials there is a gift to any actor already scanning for Fortinet management surfaces. Treat the October 4 KEV deadline as the outer bound, not the target.