Skip to content

Published · 2d agoSecurity5 min read

FortiMail zero-day indicators include an archive account pointed at an attacker IP

Attackers are exploiting CVE-2026-104286, a 9.8-rated unauthenticated file-write flaw in FortiMail, before any fixed build has shipped. Fortinet's own log samples include an archive account set to deliver to one of the attack IPs, and CISA has given federal agencies until October 4 to triage and mitigate.

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

2 publishersOperator

Not a builder's beat, but builders have a standing stake in it.See today for builders

Artwork accompanying FortiMail zero-day indicators include an archive account pointed at an attacker IP
Generated illustration

What happened

  • On Thursday, CISA added CVE-2026-104286, a critical flaw in Fortinet FortiMail, to its Known Exploited Vulnerabilities catalog following reports of active exploitation.
  • CVE-2026-104286 has a CVSS score of 9.8 and allows unauthenticated attackers to write arbitrary files on the underlying system.
  • "An improper limitation of a pathname to a restricted directory ('path traversal') [CWE-22] and improper neutralization of NULL byte or NULL character [CWE-158] vulnerability may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests," Fortinet said in an advisory.
  • The vulnerability affects the FortiMail management interface.
  • Affected versions: FortiMail 8.0.0 through 8.0.1 (upgrade to upcoming 8.0.2 or above); 7.6.0 through 7.6.6 (upgrade to upcoming 7.6.7 or above); 7.4.0 through 7.4.8 (upgrade to upcoming 7.4.9 or above); 7.2.0 through 7.2.9 (upgrade to branch 7.4 or above).

Compiled by The WatchSomething wrong?How this is made

Why it matters

One of the log samples Fortinet published for CVE-2026-104286 records a configuration change. An archive account named archive234 was added from the FortiMail command line under the admin user, with 79.141.169.187 as the remote server, archive234 as the remote username and /uploads as the remote directory [13]. That address is one of the two IP addresses Fortinet lists as indicators of compromise [26]. BleepingComputer, which reproduced the entries, wrote: "This could indicate that the attacker configured the compromised FortiMail appliance to send archived data to a remote server." [14]

If that reading holds, the attacker's position on a compromised box includes a standing entry in the appliance configuration, alongside the files written to disk [13][11]. The log records the account being added. The reports do not say whether archived data reached 79.141.169.187, or whether credentials or encryption material on compromised appliances were accessed [13][14].

What it takes to reach the bug

Fortinet's advisory says the flaw "may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests." [3] It pairs a path traversal weakness, CWE-22, with improper neutralization of NULL bytes, CWE-158 [3]. BleepingComputer reports that the flaw affects the FortiMail management interface [4]. The CVSS score is 9.8 [2]. The score matters less than three facts: no credentials, requests over HTTP or HTTPS, and exploitation Fortinet itself has confirmed [3][22].

Fortinet's two workarounds narrow where that exposure sits. One disables IBE feature support with three CLI lines: config system encryption ibe, set status disable, end [7]. The other blocks internet access to the management interface or limits it to trusted private networks [7]. BleepingComputer presents the second as an alternative to the first [8]. If either measure is enough on its own, an appliance is exposed only when IBE is switched on and the management interface is reachable from untrusted networks [30]. The log samples include an IBE decryption failure, a caught exception for invalid Base64 encoding at position 0 [15]. That fits an exploit path through the IBE component [29].

From a file write to root commands

Fortinet describes a file write [2]. BleepingComputer describes attacks that use it "to execute unauthorized code or commands on vulnerable devices." [16] The indicator list shows what was written. Four files were added: /data/lib/liblog.so, /data/bin/webconsole, /data/bin/mailservice and /data/etc/ld.so.preload [11]. Three existing files were modified: /bin/smit, /data/etc/httpd.conf and /data/migadmin.tar.gz [12].

The logs show execution. A cron entry records a root shell command whose text starts with O=/migadmin [15]. The same name is on the modified archive, /data/migadmin.tar.gz [28]. The archive account was added through the CLI under the admin user, so whoever made that change was working with administrator rights on the box [13]. The remaining samples are an admin logout recorded with a null source and a failed login by an internal user [15].

Fixed builds are still listed as upcoming

Fortinet's version table covers four branches [5]. FortiMail 8.0.0 through 8.0.1 is to move to 8.0.2, 7.6.0 through 7.6.6 to 7.6.7, and 7.4.0 through 7.4.8 to 7.4.9, with all three targets marked upcoming [5]. BleepingComputer reports that security updates for 7.4, 7.6 and 8.0 are not yet available [6]. For 7.2.0 through 7.2.9 the instruction is to upgrade to the 7.4 branch or above [5]. BleepingComputer says 7.2 users can patch that way [6].

That route has a gap. Every released 7.4 build up to 7.4.8 sits inside the affected range, as does every released 7.6 and 8.0 build [5]. A 7.2 appliance upgraded before 7.4.9 ships lands on an affected version [24]. On the table as published, no branch has a fixed release, and every FortiMail owner depends on the workarounds until 7.4.9, 7.6.7 or 8.0.2 is out [24].

The October 4 deadline

CISA added the flaw to its Known Exploited Vulnerabilities catalog on Thursday [1]. Federal civilian executive branch agencies have until October 4, 2026 to apply the patch or the workarounds [19]. BleepingComputer reports that CISA also requires those agencies to perform forensic triage [20]. With no fixed build available, the workarounds are the only way to meet the mitigation half of that order on time [24][19].

Fortinet offers the workarounds as mitigation until fixes ship [7]. They do not reverse changes already made to a compromised box [31]. The IBE workaround changes one setting under config system encryption ibe [7]. The archive account in the log samples is a separate configuration entry with its own remote destination [13]. Disabling IBE leaves that entry in place, and so does restricting the management interface [31]. The material for checking is in the advisory: two IP addresses, seven file paths and five sample log events [10][25][32].

Seven other exploited flaws, one set of FortiMail indicators

Fortinet's own Product Security team found the flaw [9]. Its advisory acknowledges exploitation in the wild [22]. Asked for more, the company pointed back to that advisory. "Fortinet published an advisory to provide guidance regarding CVE-2026-104286 (FG-IR-26-175), including workarounds to help customers mitigate risk," Fortinet told BleepingComputer [18]. It said it is communicating with government organizations, including CISA, on the advisory's content [23].

The Hacker News reported the FortiMail listing alongside other flaws under in-the-wild exploitation: Check Point (CVE-2026-85102 and CVE-2026-93616), Arista VeloCloud Orchestrator (CVE-2026-93952), F5 BIG-IP Access Policy Manager (CVE-2026-94127), Cisco Catalyst SD-WAN Manager (CVE-2026-76504), and Citrix NetScaler ADC and NetScaler Gateway (CVE-2026-88771 and CVE-2026-88772) [21]. The list runs to seven CVEs across five vendors besides Fortinet [27]. Concurrent exploitation across that many vendors is a pattern in the targets [21][27]. Calling it one campaign would take attribution, and Fortinet has not disclosed when the FortiMail exploitation began, how many systems were hit, or who is behind it, according to BleepingComputer [17].

For now the public record on the FortiMail attacker is two IP addresses, 79.141.169[.]187 and 45.129.0[.]192 [10].

What to watch

  • Fortinet shipping FortiMail 7.4.9, 7.6.7 or 8.0.2: until one is out, every branch, including 7.2 via the 7.4 upgrade path, runs on workarounds alone.
  • Any Fortinet or CISA disclosure of when exploitation began, how many appliances were hit, or who is behind it, and whether it ties to the other seven exploited CVEs reported alongside it.
  • An advisory update saying whether data was sent to 79.141.169.187 through archive accounts, or whether credentials on compromised appliances should be treated as exposed.

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    On Thursday, CISA added CVE-2026-104286, a critical flaw in Fortinet FortiMail, to its Known Exploited Vulnerabilities catalog following reports of active exploitation.

    ReportedSource: The Hacker NewsView cited source
  2. [2]

    CVE-2026-104286 has a CVSS score of 9.8 and allows unauthenticated attackers to write arbitrary files on the underlying system.

    ReportedSource: The Hacker NewsView cited source
  3. [3]

    "An improper limitation of a pathname to a restricted directory ('path traversal') [CWE-22] and improper neutralization of NULL byte or NULL character [CWE-158] vulnerability may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests," Fortinet said in an advisory.

    ReportedSource: Fortinet advisory, quoted by The Hacker NewsView cited source

Sources & coverage · 2 publishers

The reporting this story was synthesized from, earliest first. Every link goes to the original.

Additional citations

  • The Hacker News
  • Fortinet advisory, quoted by The Hacker News
  • BleepingComputer
  • Fortinet advisory via The Hacker News
  • Fortinet advisory log sample, reproduced by BleepingComputer
  • Fortinet advisory log samples, reproduced by BleepingComputer
  • Fortinet statement to BleepingComputer
  • The Hacker News, citing CISA