Hackers exploit FortiMail zero-day before a patch exists

Published

Fortinet says attackers are already exploiting a critical flaw in FortiMail, its email security gateway, and the fixed software has not shipped yet. The bug, tracked as CVE-2026-104286 and rated 9.8 on CVSS v3, lets an attacker with no login write arbitrary files to the appliance using crafted HTTP or HTTPS requests. Fortinet rates its impact as executing unauthorized code or commands.

The vendor published advisory FG-IR-26-175 on October 1, stating that the flaw has been reported to be exploited in the wild. The same day, CISA added it to its Known Exploited Vulnerabilities catalog, which puts US federal civilian agencies on a remediation clock.

Every supported branch is affected

Fortinet describes the bug as a path traversal (CWE-22), where crafted file paths reach directories they should not, combined with improper handling of NULL bytes (CWE-158). The advisory names the GUI as the affected component. Vulnerable releases are:

The flaw was found internally by Gwendal Guégniaud of Fortinet's Product Security team. Fortinet has not said who is exploiting it or how many customers have been hit.

No patch yet, so turn IBE off

Because the fixed builds are still listed as upcoming, the workaround is the only immediate defence. Fortinet tells customers to disable Identity Based Encryption (IBE) support with this CLI sequence: config system encryption ibe, then set status disable, then end. Alternatively, cut the FortiMail management interface off from the internet or restrict it to trusted private networks. Since exploitation was already under way before the advisory, admins of internet-facing appliances should also check them against the indicators below.

What a compromised appliance looks like

Fortinet's advisory is generous with forensics. It lists files the attackers added, including /data/lib/liblog.so, /data/bin/webconsole, /data/bin/mailservice and /data/etc/ld.so.preload, and files they modified, including /bin/smit, /data/etc/httpd.conf and /data/migadmin.tar.gz.

The sample log entries show what intruders did once inside. One records an archive account named "archive234" being added through the CLI with a remote destination at 79[.]141[.]169[.]187 and an /uploads directory, pointing mail archiving at an outside server. Another shows a cron job running a shell command as root. Fortinet also lists an IBE decryption error reading "Invalid Base64 Encoding at pos 0" among its log indicators, a useful search string for defenders.

Indicators of compromise

The full list, with MD5 and SHA256 hashes for every added and modified file, is in the vendor advisory.

Fortinet gear has been a steady target this year, from exploited FortiSandbox flaws to earlier KEV additions for FortiOS. An email gateway touches every message an organization sends and receives, which makes it one of the most valuable boxes on a network to own quietly. Until 8.0.2, 7.6.7 and 7.4.9 ship, switching IBE off is the cheapest insurance an admin can buy.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions