Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes
- ID
- 31052
- Status
- summarized
- Published
- 02 Oct 2026, 1:49 PM
- Fetched
- 02 Oct 2026, 3:20 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/10/critical-fortimail-zero-day-flaw.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 2.5
- Created
- 02 Oct 2026, 3:21 PM
- Tags
- Audience
- developers
What happened
CISA added CVE-2026-104286 (CVSS 9.8), a path-traversal (CWE-22) plus NULL-byte (CWE-158) flaw in Fortinet FortiMail, to its Known Exploited Vulnerabilities catalog on October 1, 2026 after confirming active exploitation. Crafted HTTP/HTTPS requests let unauthenticated attackers write arbitrary files on the underlying system; affected branches are 8.0.0-8.0.1, 7.6.0-7.6.6, 7.4.0-7.4.8, and 7.2.0-7.2.9, with fixes not yet shipped for several of them. Fortinet's listed indicators of compromise include two IPs (79.141.169.187, 45.129.0.192) and newly added files such as /data/etc/ld.so.preload and /data/bin/webconsole.
Why it matters
This is only actionable if you or a client actually run a FortiMail gateway, and the operational catch is that some branches have no patch yet: 7.2.x must move to the 7.4 branch, while 8.0.x, 7.6.x, and 7.4.x are told to wait for 8.0.2, 7.6.7, and 7.4.9 respectively. Until then the documented workarounds are disabling the IBE feature via 'config system encryption ibe / set status disable' and removing the management interface from internet exposure. The added /data/etc/ld.so.preload file is a persistence mechanism worth grepping for on any affected appliance, and FCEB agencies were given a patch deadline of October 4, 2026. Everyone else in this audience can skip it.
Discussion angle
The patch gap: Fortinet confirmed in-the-wild exploitation but shipped no fix for several affected branches, leaving admins choosing between a branch upgrade, a feature-disable workaround, or waiting. Worth discussing how you'd triage that call for a client's mail gateway versus a typical patched-today CVE.