FortiMail CVE-2026-104286 (CVSS 9.8) file-write zero-day
Unauthenticated FortiMail management interface file write

FortiMail CVE-2026-104286 (CVSS 9.8) file-write zero-day

Fortinet has confirmed active exploitation of a critical FortiMail flaw that lets an unauthenticated attacker write arbitrary files on the appliance. CVE-2026-104286 scores 9.8. CISA put it on the Known Exploited Vulnerabilities catalog on 1 October 2026 and told federal agencies to mitigate by 4 October.

What happened

The bug combines a path traversal with bad handling of a NULL byte in the management interface. A crafted HTTP or HTTPS request is enough. No login is required. Fortinet found it internally, then confirmed it was already being used.

Published indicators include the addresses 79.141.169.187 and 45.129.0.192, plus added files under /data/lib and /data/bin, a new /data/etc/ld.so.preload, and changes to /bin/smit, httpd.conf, and migadmin.tar.gz. Those paths are persistence, not noise.

Who is affected

Internet-reachable FortiMail management interfaces on these branches:

  • 8.0.0 through 8.0.1 (fix was listed as upcoming 8.0.2)
  • 7.6.0 through 7.6.6 (upcoming 7.6.7)
  • 7.4.0 through 7.4.8 (upcoming 7.4.9)
  • 7.2.0 through 7.2.9 (move to the 7.4 branch or later)

What to do now

If the fixed build is not installed yet, disable Identity-Based Encryption and stop exposing the management interface to the internet. Fortinet's workaround is config system encryption ibe then set status disable. After that, hunt the published file indicators before you call the box clean. A patched appliance can still be backdoored from the window before the workaround.

Source: The Hacker News, 2 October 2026. Fortinet advisory: FG-IR-26-175.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

NetScaler CVE-2026-88779 (CVSS 8.7) crashes SAML appliances
Citrix NetScaler SAML memory overflow zero-day