AI Weekly Malaysia

Back to items Summaries

Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes

ID
31052
Status
summarized
Published
02 Oct 2026, 1:49 PM
Fetched
02 Oct 2026, 3:20 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/10/critical-fortimail-zero-day-flaw.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
2.5
Created
02 Oct 2026, 3:21 PM
Tags
Audience
developers

What happened

CISA added CVE-2026-104286 (CVSS 9.8), a path-traversal (CWE-22) plus NULL-byte (CWE-158) flaw in Fortinet FortiMail, to its Known Exploited Vulnerabilities catalog on October 1, 2026 after confirming active exploitation. Crafted HTTP/HTTPS requests let unauthenticated attackers write arbitrary files on the underlying system; affected branches are 8.0.0-8.0.1, 7.6.0-7.6.6, 7.4.0-7.4.8, and 7.2.0-7.2.9, with fixes not yet shipped for several of them. Fortinet's listed indicators of compromise include two IPs (79.141.169.187, 45.129.0.192) and newly added files such as /data/etc/ld.so.preload and /data/bin/webconsole.

Why it matters

This is only actionable if you or a client actually run a FortiMail gateway, and the operational catch is that some branches have no patch yet: 7.2.x must move to the 7.4 branch, while 8.0.x, 7.6.x, and 7.4.x are told to wait for 8.0.2, 7.6.7, and 7.4.9 respectively. Until then the documented workarounds are disabling the IBE feature via 'config system encryption ibe / set status disable' and removing the management interface from internet exposure. The added /data/etc/ld.so.preload file is a persistence mechanism worth grepping for on any affected appliance, and FCEB agencies were given a patch deadline of October 4, 2026. Everyone else in this audience can skip it.

Discussion angle

The patch gap: Fortinet confirmed in-the-wild exploitation but shipped no fix for several affected branches, leaving admins choosing between a branch upgrade, a feature-disable workaround, or waiting. Worth discussing how you'd triage that call for a client's mail gateway versus a typical patched-today CVE.

Top