Dev.to Security πŸ” Cybersecurity πŸ‘ 0 πŸ“– 5 min read

FortiMail Zero-Day CVE-2026-104286 Exploited Before Any Patch Ships

TL;DR what: CVE-2026-104286, a path traversal and NULL byte flaw in Fortinet FortiMail, is being exploited in the wild and was added to CISA's KEV catalog on October 1, 2026. impact: An unauthenticated attacker can

TL;DR

  • what: CVE-2026-104286, a path traversal and NULL byte flaw in Fortinet FortiMail, is being exploited in the wild and was added to CISA's KEV catalog on October 1, 2026.
  • impact: An unauthenticated attacker can write arbitrary files to the appliance with crafted HTTP or HTTPS requests, and observed intrusions planted an ld.so.preload library hook plus rogue binaries.
  • fix: Fortinet lists 8.0.2, 7.6.7 and 7.4.9 as upcoming fixes and says 7.2 must move to the 7.4 branch, and until then its mitigation is to disable IBE and keep the management interface off the internet.
  • who: Any organization running FortiMail 7.2.0 through 8.0.1, especially deployments with IBE enabled or the management interface reachable from the internet.

Attackers are exploiting a critical, unauthenticated flaw in Fortinet FortiMail before any fixed build is available. CVE-2026-104286 carries a CVSS score of 9.8. It allows a remote attacker with no credentials to write arbitrary files to the underlying system by sending crafted HTTP or HTTPS requests. On Thursday, October 1, 2026, CISA added it to the Known Exploited Vulnerabilities catalog and gave Federal Civilian Executive Branch agencies until October 4 to apply the patch or the workarounds. That is a three-day window. Fortinet lists every fixed release as upcoming, so for now its workaround is the only protection it has published.

What the Flaw Is

Fortinet describes the bug as two weaknesses combined: improper limitation of a pathname to a restricted directory (CWE-22, path traversal) and improper neutralization of a NULL byte (CWE-158). Fortinet has not released a technical root cause. However, the pairing follows a familiar pattern. Traversal sequences move the write outside the intended directory, and an embedded NULL byte cuts off whatever suffix or extension the application appends. The result is that the attacker chooses both the location and the name of the file.

The workarounds show where the exposure sits. Fortinet's interim guidance is to disable Identity-Based Encryption (IBE) support and to remove internet access to the FortiMail management interface. That points to a vulnerable path in the web-facing services, with IBE as a primary entry route. On an appliance, an arbitrary file write is effectively code execution. The indicators Fortinet published confirm that attackers used it that way.

Affected Versions and Fix Status

  • FortiMail 8.0.0 through 8.0.1: fix is upcoming 8.0.2 or above
  • FortiMail 7.6.0 through 7.6.6: fix is upcoming 7.6.7 or above
  • FortiMail 7.4.0 through 7.4.8: fix is upcoming 7.4.9 or above
  • FortiMail 7.2.0 through 7.2.9: no 7.2 fix, must move to the 7.4 branch or later

⚠️ No patched build exists yet β€” Fortinet's advisory says the fixes for 8.0, 7.6 and 7.4 are upcoming. The 7.2 branch will not get a fix at all. Its customers must migrate to 7.4, and that branch is itself waiting on 7.4.9. Until releases ship, the vendor's mitigation is to disable IBE and restrict management interface access to trusted private networks. Those mitigations block new exploitation attempts. They do not remove anything an attacker has already written to the device.

What Attackers Left Behind

Fortinet published two source IP addresses and seven file system changes tied to the exploitation activity:

  • Source IPs: 79.141.169[.]187 and 45.129.0[.]192
  • /data/lib/liblog.so (added)
  • /data/bin/webconsole (added)
  • /data/bin/mailservice (added)
  • /data/etc/ld.so.preload (added)
  • /bin/smit (modified)
  • /data/etc/httpd.conf (modified)
  • /data/migadmin.tar.gz (modified)

Taken together, these files describe a persistence kit, not a one-off proof of concept. Adding an ld.so.preload entry makes the dynamic linker load a chosen library into every dynamically linked process on the system. Paired with the new liblog.so, that gives the attacker a hook inside every running service, which is the standard method for userland rootkits that hide files, processes and connections. The binary names webconsole and mailservice are chosen to blend in with legitimate appliance processes. The change to httpd.conf suggests the web server configuration was altered, likely to expose a handler or path the attacker controls. The tampered migadmin.tar.gz is the most concerning item. Our assessment is that it holds the management web interface, so modifying it is a way to make the implant survive service restarts or a rebuild of the web UI. Fortinet has not described the purpose of each file. These readings are RedEye analysis.

Why a Mail Gateway Is a High-Value Target

FortiMail sits inline on an organization's inbound and outbound email. A compromised gateway can read message content and attachments in transit, change or suppress messages, and harvest whatever directory or LDAP credentials the appliance uses for recipient lookups. It is also a trusted host on the internal network, which makes it a clean pivot point.

IBE makes the exposure harder to avoid. IBE delivers encrypted mail to external recipients through a web portal, so it has to be reachable from the internet to work. Organizations that depend on it face a direct trade-off. If they disable the feature, encrypted delivery to outside parties stops until a fixed build ships. If they keep it on, an exploited attack path stays open.

Discovery and Attribution

Fortinet credits Gwendal GuΓ©gniaud of its own Product Security team with finding and reporting the flaw. The advisory names no threat actor and gives no victim count or date when exploitation began. The two IP addresses are the only network indicators. Exploitation infrastructure on edge devices rotates quickly, so the absence of those IPs from logs is weak evidence that a device is clean.

Part of a Wider Edge Device Wave

FortiMail is not an isolated case. Exploitation in the wild has also been reported recently against Check Point (CVE-2026-85102 and CVE-2026-93616), Arista VeloCloud Orchestrator (CVE-2026-93952), F5 BIG-IP Access Policy Manager (CVE-2026-94127), Cisco Catalyst SD-WAN Manager (CVE-2026-76504), and Citrix NetScaler ADC and NetScaler Gateway (CVE-2026-88771 and CVE-2026-88772). That is eight CVEs across six vendors, all on internet-facing infrastructure that usually runs with little endpoint visibility. Attackers are deliberately targeting appliances where EDR cannot run and where patch cycles depend on vendor release schedules.

RedEye Assessment β€” Any FortiMail appliance that ran an affected version with IBE enabled or the management interface reachable from the internet should be treated as potentially compromised until shown otherwise. Fortinet's workaround closes the entry path, but it does nothing about an ld.so.preload hook or a modified admin archive that is already in place. A device that looks healthy and passes mail normally can still be hosting an implant inside every process. Upgrading to a fixed build later will not by itself prove a device is clean.

Originally published on RedEye Threat Intelligence.

πŸ“° Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β€” full credit and traffic to the original publisher.