| | |

Your Email Gateway Is the Way In: FortiMail Zero-Day CVE-2026-104286 Is Under Attack, There’s No Patch, and CISA’s Deadline Is Tomorrow

Attackers are writing files onto Fortinet FortiMail email security gateways without logging in. Fixed builds for the main branches are still pending, CISA wants it handled by October 4, and the obvious upgrade path for 7.2 customers still lands on a vulnerable release.

DataWater Threat Intelligence Desk | Published October 3, 2026 | 8-minute read

Threat level: Critical

What: CVE-2026-104286, an unauthenticated arbitrary file write in Fortinet FortiMail (path traversal plus NULL-byte handling), CVSS 9.8. Fortinet advisory FG-IR-26-175.

Status: Exploited in the wild. Added to CISA’s Known Exploited Vulnerabilities catalog on October 1, 2026.

Deadline: Federal civilian agencies must patch or mitigate by Sunday, October 4, 2026.

Fix: Fixed releases 7.4.9, 7.6.7 and 8.0.2 announced as “upcoming.” Until they ship: disable IBE and pull the management interface off the internet. Then hunt.

Key takeaways

  • CVE-2026-104286 lets anyone who can reach a FortiMail appliance over HTTP or HTTPS write arbitrary files to it, with no credentials.
  • Every supported branch is affected: FortiMail 7.2.0–7.2.9, 7.4.0–7.4.8, 7.6.0–7.6.6 and 8.0.0–8.0.1.
  • The vulnerable code sits in Identity-Based Encryption (IBE), reachable through the /ibe web endpoint.
  • Workaround today: disable IBE and restrict management-interface access to trusted networks.
  • Fortinet has published IoCs, including two attacker IPs and seven added or modified files. Check for them before you change anything.

Executive Summary

The appliance you bought to stop malicious email is now the thing attackers are breaking into.

On October 1, Fortinet published advisory FG-IR-26-175 disclosing CVE-2026-104286 in FortiMail, its email security gateway. The flaw combines a path traversal weakness (CWE-22) with improper neutralization of NULL bytes (CWE-158). Put together, an unauthenticated attacker can send a crafted web request and write files anywhere on the appliance’s filesystem. Fortinet confirmed the bug is being exploited in the wild.

CISA added it to the KEV catalog the same day and gave federal civilian agencies until October 4, a three-day window, to patch or apply workarounds.

The complication: when the advisory went out, fixed builds for the 7.4, 7.6 and 8.0 branches were listed as upcoming, not released. Reporting through October 3 indicates that is still the case for at least part of the install base. For most FortiMail customers, the only protection right now is a configuration change.

The bottom line: disable IBE or wall off the management interface today, check for Fortinet’s indicators of compromise, and schedule the upgrade the moment fixed builds appear.

Why This Matters to CISOs and Security Leaders

FortiMail sees every message. In gateway mode, all inbound mail passes through the appliance before it reaches an employee. An attacker who controls that box can read, alter or reroute mail, harvest credentials and plant convincing internal-looking phishing.

Arbitrary file write is a short path to code execution. The indicators Fortinet published include an added ld.so.preload file and a shared library, a classic technique for loading attacker code into every process on a Linux system. That is persistence, not vandalism.

It is another edge device in a month full of them. FortiMail joins Check Point, F5 BIG-IP APM, Arista VeloCloud, Cisco Catalyst SD-WAN Manager and Citrix NetScaler on the list of perimeter products exploited in recent weeks. DataWater covered the Check Point and F5 wave and the NetScaler zero-days. The pattern is the same: attackers go for appliances that sit outside your EDR.

Executive insight

CISA’s three-day deadline and its forensic-triage expectation under BOD 26-04 assume some appliances are already compromised. A workaround applied today closes the door; it does not tell you whether someone came in on Wednesday.

The Timeline

Date (2026) What happened
Before Oct 1 Exploitation underway; Fortinet’s own product security team identifies the flaw
Thursday, Oct 1 Fortinet publishes FG-IR-26-175 with workarounds and IoCs; fixed builds listed as upcoming
Thursday, Oct 1 CISA adds CVE-2026-104286 to the KEV catalog
Oct 2–3 Security researchers report fixed builds for 7.4, 7.6 and 8.0 still pending
Sunday, Oct 4 CISA patch-or-mitigate deadline for federal civilian agencies

The patch is “upcoming.” The attackers are not.

Vulnerability & Exploit Analysis

What CVE-2026-104286 is

A file-path validation flaw in FortiMail’s Identity-Based Encryption service. By inserting a NULL byte into a crafted path, an attacker can get the appliance to accept a path that escapes the directory it is supposed to be confined to, then write a file there. No login and no user interaction are required. Fortinet rates it CVSS 9.8. It was discovered internally by Gwendal Guégniaud of Fortinet’s Product Security team.

Affected and fixed versions

Branch Vulnerable Fix
FortiMail 8.0 8.0.0 – 8.0.1 8.0.2 or later (announced as upcoming)
FortiMail 7.6 7.6.0 – 7.6.6 7.6.7 or later (announced as upcoming)
FortiMail 7.4 7.4.0 – 7.4.8 7.4.9 or later (announced as upcoming)
FortiMail 7.2 7.2.0 – 7.2.9 No 7.2 fix; migrate to a fixed 7.4+ release
What nobody is talking about
Fortinet’s guidance for 7.2 customers is to move to the 7.4 branch. But until 7.4.9 actually ships, the newest 7.4 build available is 7.4.8, which is on the vulnerable list. A 7.2 customer who upgrades today without also disabling IBE has done the work and is still exposed. Apply the workaround regardless of which branch you are on.

Exposure

Internet-scan figures shared publicly put globally exposed FortiMail interfaces in the low thousands (one ZoomEye count cited roughly 3,900). Treat any third-party count as a floor, not a ceiling: what matters is whether your FortiMail management or IBE interface is reachable from the internet.

Threat Intelligence Breakdown

Attribution: Fortinet has not named a threat actor. Historically, Fortinet edge flaws have been exploited by both state-linked espionage groups and ransomware affiliates, and both should be in your threat model.

Indicators of compromise published by Fortinet:

Type Indicator Change
IP address 79.141.169[.]187 Attacker infrastructure
IP address 45.129.0[.]192 Attacker infrastructure
File /data/lib/liblog.so Added
File /data/bin/webconsole Added
File /data/bin/mailservice Added
File /data/etc/ld.so.preload Added
File /bin/smit Modified
File /data/etc/httpd.conf Modified
File /data/migadmin.tar.gz Modified

How to read these: the added binaries and the preload file point to attackers installing their own components and making them load automatically. A modified web server config suggests an effort to keep remote access through the appliance’s web interface. If you find any of these, assume full appliance compromise.

Enterprise Impact: What’s Actually at Risk

Email confidentiality: A compromised gateway can expose message content, attachments and encrypted-mail workflows for the whole organization.

Phishing from the inside: Control of the mail gateway means attackers can make malicious mail look like it passed your filters, or wave through mail your filters would have blocked.

Credentials and lateral movement: Mail appliances often integrate with LDAP or Active Directory. Service-account credentials stored on the box should be treated as exposed if the appliance is compromised.

Regulatory exposure: Email typically carries regulated data. If triage finds compromise, disclosure clocks under state breach laws, SEC rules or sector regulators may start. Document every action and timestamp now.

Cyber insurance: A KEV-listed flaw on an edge device left unmitigated past its deadline is a fact insurers will ask about.

What Security Leaders Should Do Next

Today

  1. Find every FortiMail appliance, including DR, regional and test units, and record its version.
  2. Preserve evidence first. Export logs and capture configuration before making changes, so a later investigation has something to work with.
  3. Disable IBE if your organization does not rely on it:
config system encryption ibe
set status disable
end
  1. Remove internet access to the FortiMail management interface, or restrict it to trusted private networks. If you depend on IBE and cannot disable it, network restriction must be enforced on every exposed interface, not just the primary one.

Within 48 hours

  1. Hunt for the published IoCs: search firewall and proxy logs for the two attacker IPs and check appliances for the listed files.
  2. Review IBE and web access logs for unusual requests to /ibe, especially encoded or malformed paths.
  3. If anything matches, treat it as an incident: isolate the appliance, rebuild from a clean image, and rotate every credential and certificate it held, including directory-integration service accounts.

When fixed builds ship

  1. Upgrade to 7.4.9, 7.6.7, 8.0.2 or later, and confirm the exact build on every appliance.
  2. Keep the management interface off the internet permanently. It should never have been the only control.
  3. Add mail gateways to your edge-device program with a named owner, a pre-approved emergency change path and remote log shipping.

Get zero-day alerts before they hit the headlines

DataWater’s executive threat briefing: the exploited CVEs, the deadlines and the first three actions to take.

Read more briefings

Winners and Losers

Better positioned More exposed
Teams with management interfaces already restricted to internal networks Appliances administered directly over the internet
Organizations that do not use IBE and can disable it in minutes Organizations whose secure-mail workflow depends on IBE
Teams that preserved logs before changing configs Teams that rebooted and reconfigured first
7.2 customers who disabled IBE before migrating 7.2 customers who upgraded to 7.4.8 and called it done

Final Executive Takeaway

This is a no-patch zero-day on the system that inspects all of your email.

You cannot upgrade your way out of it yet. You can turn off the vulnerable feature, close the network path and check whether anyone already used it.

Mitigate today. Hunt for the IoCs. Upgrade the hour the fix ships.

Frequently Asked Questions

What is CVE-2026-104286?

CVE-2026-104286 is a critical vulnerability in Fortinet FortiMail rated CVSS 9.8. It combines a path traversal flaw with improper NULL-byte handling, allowing an unauthenticated attacker to write arbitrary files to the appliance through crafted HTTP or HTTPS requests. Fortinet confirmed it is exploited in the wild.

Which FortiMail versions are affected by CVE-2026-104286?

FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9.

Is there a patch for the FortiMail zero-day?

Fortinet has named FortiMail 7.4.9, 7.6.7 and 8.0.2 as the fixed releases, but listed them as upcoming at disclosure, and reporting through October 3, 2026 indicates they were not yet available for all branches. FortiMail 7.2 will not get its own fix; those customers must move to a fixed 7.4 or later release. Check Fortinet advisory FG-IR-26-175 for current status.

How do I mitigate CVE-2026-104286 without a patch?

Disable Identity-Based Encryption with the CLI commands config system encryption ibe, set status disable, end, and block internet access to the FortiMail management interface or limit it to trusted private networks.

What is the CISA deadline for CVE-2026-104286?

CISA added the flaw to its Known Exploited Vulnerabilities catalog on October 1, 2026, and gave federal civilian agencies until October 4, 2026 to patch or apply mitigations.

How do I know if my FortiMail appliance was compromised?

Check for connections to 79.141.169[.]187 and 45.129.0[.]192, and look for the files Fortinet listed: added /data/lib/liblog.so, /data/bin/webconsole, /data/bin/mailservice and /data/etc/ld.so.preload, and modified /bin/smit, /data/etc/httpd.conf and /data/migadmin.tar.gz. Any match means you should isolate and rebuild the appliance and rotate its credentials.

Does upgrading FortiMail 7.2 to 7.4 fix the vulnerability?

Only if you land on 7.4.9 or later. FortiMail 7.4.8 and earlier are vulnerable, so until 7.4.9 is released, 7.2 customers who migrate should also disable IBE and restrict the management interface.

Sources

Fortinet PSIRT advisory FG-IR-26-175; CISA Known Exploited Vulnerabilities catalog (added October 1, 2026); The Hacker News; Help Net Security; BleepingComputer; Field Effect; public ZoomEye exposure data. Reflects public reporting as of October 3, 2026. Check the Fortinet advisory for the latest fixed builds and indicators.

Similar Posts