Back

Fortinet Reports Active Exploitation of Critical FortiMail Zero-Day

At a glance

  • Fortinet identified a critical FortiMail vulnerability under active attack.
  • The flaw is tracked as CVE-2026-104286 with a CVSS score of 9.8.
  • CISA requires federal agencies to mitigate the issue by October 4, 2026.

Fortinet has issued a security advisory regarding a critical vulnerability in its FortiMail product, which is currently being exploited in zero-day attacks. The company identified the flaw as CVE-2026-104286 and classified it as a high-severity risk.

The vulnerability affects several FortiMail versions, including 8.0.0-8.0.1, 7.6.0-7.6.6, 7.4.0-7.4.8, and 7.2.0-7.2.9. Fortinet stated that fixes will be provided in upcoming releases 8.0.2, 7.6.7, and 7.4.9, and recommended that users of version 7.2 upgrade to the 7.4 branch or later.

According to Fortinet, the flaw involves both a path traversal issue and improper handling of NULL bytes, which allows unauthenticated attackers to write arbitrary files using specially crafted HTTP or HTTPS requests. The company has advised customers to take temporary mitigation steps until patches are available.

Fortinet recommends disabling the IBE feature via the command line or restricting management interface access to trusted private networks as interim protective measures. The company also published indicators of compromise to help users detect potential exploitation.

What the numbers show

  • CVE-2026-104286 has a CVSS score of 9.8.
  • CISA set an October 4, 2026 deadline for federal agency mitigation.
  • Fortinet identified two attack-related IP addresses: 79.141.169.187 and 45.129.0.192.

Indicators of compromise released by Fortinet include files such as /data/lib/liblog.so, /data/bin/webconsole, /data/bin/mailservice, /data/etc/ld.so.preload, and modified files like /bin/smit, /data/etc/httpd.conf, and /data/migadmin.tar.gz. These details are intended to assist organizations in identifying affected systems.

Fortinet has shared the IP addresses 79.141.169.187 and 45.129.0.192 as being associated with the ongoing attacks. Organizations are encouraged to monitor for connections involving these addresses as part of their security response.

The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-104286 to its Known Exploited Vulnerabilities catalog. Federal agencies are required to take mitigation actions by October 4, 2026, according to CISA's directive.

Fortinet continues to monitor the situation and has stated that further updates will be provided as patches are released. Users are advised to follow the company's guidance and apply recommended mitigations until permanent fixes become available.

* This article is based on publicly available information at the time of writing.