Published · 2d agoSecurity5 min read
FortiMail zero-day indicators include an archive account pointed at an attacker IP
Attackers are exploiting CVE-2026-104286, a 9.8-rated unauthenticated file-write flaw in FortiMail, before any fixed build has shipped. Fortinet's own log samples include an archive account set to deliver to one of the attack IPs, and CISA has given federal agencies until October 4 to triage and mitigate.
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- On Thursday, CISA added CVE-2026-104286, a critical flaw in Fortinet FortiMail, to its Known Exploited Vulnerabilities catalog following reports of active exploitation.
- CVE-2026-104286 has a CVSS score of 9.8 and allows unauthenticated attackers to write arbitrary files on the underlying system.
- "An improper limitation of a pathname to a restricted directory ('path traversal') [CWE-22] and improper neutralization of NULL byte or NULL character [CWE-158] vulnerability may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests," Fortinet said in an advisory.
- The vulnerability affects the FortiMail management interface.
- Affected versions: FortiMail 8.0.0 through 8.0.1 (upgrade to upcoming 8.0.2 or above); 7.6.0 through 7.6.6 (upgrade to upcoming 7.6.7 or above); 7.4.0 through 7.4.8 (upgrade to upcoming 7.4.9 or above); 7.2.0 through 7.2.9 (upgrade to branch 7.4 or above).
Compiled by The WatchSomething wrong?How this is made
Why it matters
One of the log samples Fortinet published for CVE-2026-104286 records a configuration change. An archive account named archive234 was added from the FortiMail command line under the admin user, with 79.141.169.187 as the remote server, archive234 as the remote username and /uploads as the remote directory [13]. That address is one of the two IP addresses Fortinet lists as indicators of compromise [26]. BleepingComputer, which reproduced the entries, wrote: "This could indicate that the attacker configured the compromised FortiMail appliance to send archived data to a remote server." [14]
If that reading holds, the attacker's position on a compromised box includes a standing entry in the appliance configuration, alongside the files written to disk [13][11]. The log records the account being added. The reports do not say whether archived data reached 79.141.169.187, or whether credentials or encryption material on compromised appliances were accessed [13][14].
What it takes to reach the bug
Fortinet's advisory says the flaw "may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests." [3] It pairs a path traversal weakness, CWE-22, with improper neutralization of NULL bytes, CWE-158 [3]. BleepingComputer reports that the flaw affects the FortiMail management interface [4]. The CVSS score is 9.8 [2]. The score matters less than three facts: no credentials, requests over HTTP or HTTPS, and exploitation Fortinet itself has confirmed [3][22].
Fortinet's two workarounds narrow where that exposure sits. One disables IBE feature support with three CLI lines: config system encryption ibe, set status disable, end [7]. The other blocks internet access to the management interface or limits it to trusted private networks [7]. BleepingComputer presents the second as an alternative to the first [8]. If either measure is enough on its own, an appliance is exposed only when IBE is switched on and the management interface is reachable from untrusted networks [30]. The log samples include an IBE decryption failure, a caught exception for invalid Base64 encoding at position 0 [15]. That fits an exploit path through the IBE component [29].
From a file write to root commands
Fortinet describes a file write [2]. BleepingComputer describes attacks that use it "to execute unauthorized code or commands on vulnerable devices." [16] The indicator list shows what was written. Four files were added: /data/lib/liblog.so, /data/bin/webconsole, /data/bin/mailservice and /data/etc/ld.so.preload [11]. Three existing files were modified: /bin/smit, /data/etc/httpd.conf and /data/migadmin.tar.gz [12].
The logs show execution. A cron entry records a root shell command whose text starts with O=/migadmin [15]. The same name is on the modified archive, /data/migadmin.tar.gz [28]. The archive account was added through the CLI under the admin user, so whoever made that change was working with administrator rights on the box [13]. The remaining samples are an admin logout recorded with a null source and a failed login by an internal user [15].
Fixed builds are still listed as upcoming
Fortinet's version table covers four branches [5]. FortiMail 8.0.0 through 8.0.1 is to move to 8.0.2, 7.6.0 through 7.6.6 to 7.6.7, and 7.4.0 through 7.4.8 to 7.4.9, with all three targets marked upcoming [5]. BleepingComputer reports that security updates for 7.4, 7.6 and 8.0 are not yet available [6]. For 7.2.0 through 7.2.9 the instruction is to upgrade to the 7.4 branch or above [5]. BleepingComputer says 7.2 users can patch that way [6].
That route has a gap. Every released 7.4 build up to 7.4.8 sits inside the affected range, as does every released 7.6 and 8.0 build [5]. A 7.2 appliance upgraded before 7.4.9 ships lands on an affected version [24]. On the table as published, no branch has a fixed release, and every FortiMail owner depends on the workarounds until 7.4.9, 7.6.7 or 8.0.2 is out [24].
The October 4 deadline
CISA added the flaw to its Known Exploited Vulnerabilities catalog on Thursday [1]. Federal civilian executive branch agencies have until October 4, 2026 to apply the patch or the workarounds [19]. BleepingComputer reports that CISA also requires those agencies to perform forensic triage [20]. With no fixed build available, the workarounds are the only way to meet the mitigation half of that order on time [24][19].
Fortinet offers the workarounds as mitigation until fixes ship [7]. They do not reverse changes already made to a compromised box [31]. The IBE workaround changes one setting under config system encryption ibe [7]. The archive account in the log samples is a separate configuration entry with its own remote destination [13]. Disabling IBE leaves that entry in place, and so does restricting the management interface [31]. The material for checking is in the advisory: two IP addresses, seven file paths and five sample log events [10][25][32].
Seven other exploited flaws, one set of FortiMail indicators
Fortinet's own Product Security team found the flaw [9]. Its advisory acknowledges exploitation in the wild [22]. Asked for more, the company pointed back to that advisory. "Fortinet published an advisory to provide guidance regarding CVE-2026-104286 (FG-IR-26-175), including workarounds to help customers mitigate risk," Fortinet told BleepingComputer [18]. It said it is communicating with government organizations, including CISA, on the advisory's content [23].
The Hacker News reported the FortiMail listing alongside other flaws under in-the-wild exploitation: Check Point (CVE-2026-85102 and CVE-2026-93616), Arista VeloCloud Orchestrator (CVE-2026-93952), F5 BIG-IP Access Policy Manager (CVE-2026-94127), Cisco Catalyst SD-WAN Manager (CVE-2026-76504), and Citrix NetScaler ADC and NetScaler Gateway (CVE-2026-88771 and CVE-2026-88772) [21]. The list runs to seven CVEs across five vendors besides Fortinet [27]. Concurrent exploitation across that many vendors is a pattern in the targets [21][27]. Calling it one campaign would take attribution, and Fortinet has not disclosed when the FortiMail exploitation began, how many systems were hit, or who is behind it, according to BleepingComputer [17].
For now the public record on the FortiMail attacker is two IP addresses, 79.141.169[.]187 and 45.129.0[.]192 [10].
What to watch
- Fortinet shipping FortiMail 7.4.9, 7.6.7 or 8.0.2: until one is out, every branch, including 7.2 via the 7.4 upgrade path, runs on workarounds alone.
- Any Fortinet or CISA disclosure of when exploitation began, how many appliances were hit, or who is behind it, and whether it ties to the other seven exploited CVEs reported alongside it.
- An advisory update saying whether data was sent to 79.141.169.187 through archive accounts, or whether credentials on compromised appliances should be treated as exposed.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
On Thursday, CISA added CVE-2026-104286, a critical flaw in Fortinet FortiMail, to its Known Exploited Vulnerabilities catalog following reports of active exploitation.
- [2]
CVE-2026-104286 has a CVSS score of 9.8 and allows unauthenticated attackers to write arbitrary files on the underlying system.
- [3]
"An improper limitation of a pathname to a restricted directory ('path traversal') [CWE-22] and improper neutralization of NULL byte or NULL character [CWE-158] vulnerability may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests," Fortinet said in an advisory.
- [4]
The vulnerability affects the FortiMail management interface.
- [5]
Affected versions: FortiMail 8.0.0 through 8.0.1 (upgrade to upcoming 8.0.2 or above); 7.6.0 through 7.6.6 (upgrade to upcoming 7.6.7 or above); 7.4.0 through 7.4.8 (upgrade to upcoming 7.4.9 or above); 7.2.0 through 7.2.9 (upgrade to branch 7.4 or above).
- [6]
FortiMail 7.2 users can patch by upgrading to the 7.4 branch or later; for affected 7.4, 7.6 and 8.0 installations, security updates are not yet available, with 7.4.9, 7.6.7 and 8.0.2 listed as upcoming versions containing the fix.
- [7]
Fortinet urged customers to apply workarounds until fixes are available: disable IBE feature support with the CLI command 'config system encryption ibe / set status disable / end', and disable access to the FortiMail management interface from the internet or restrict it to trusted private networks.
- [8]
As an alternative workaround to disabling IBE, administrators can disable access to the FortiMail management interface from the internet or restrict access to trusted private networks.
- [9]
A researcher on Fortinet's Product Security team discovered the vulnerability internally and was credited with it.
- [10]
Fortinet's indicators of compromise include the IP addresses 79.141.169[.]187 and 45.129.0[.]192.
- [11]
Files added on compromised systems: /data/lib/liblog.so, /data/bin/webconsole, /data/bin/mailservice, /data/etc/ld.so.preload.
- [12]
Files modified on compromised systems: /bin/smit, /data/etc/httpd.conf, /data/migadmin.tar.gz.
- [13]
A log entry in Fortinet's advisory shows an archive account named archive234 added from the CLI by user admin, with destination remote, remote-ip 79.141.169.187, remote-username archive234 and remote-directory /uploads.
- [14]
"This could indicate that the attacker configured the compromised FortiMail appliance to send archived data to a remote server."
- [15]
Other log samples include a cron job running a root shell command beginning 'O=/migadmin', an admin logout event logged from (null), an IBE decryption error (caught BufferException, 'Invalid Base64 Encoding at pos 0'), and a failed login by an internal user.
- [16]
The vulnerability is being actively exploited in zero-day attacks "to execute unauthorized code or commands on vulnerable devices."
- [17]
Fortinet has not disclosed when the flaw was first exploited, how many systems were compromised, or who is behind the attacks.
- [18]
"Fortinet published an advisory to provide guidance regarding CVE-2026-104286 (FG-IR-26-175), including workarounds to help customers mitigate risk," Fortinet told BleepingComputer.
- [19]
Federal Civilian Executive Branch agencies are recommended to apply the patch or workarounds by October 4, 2026.
- [20]
CISA requires federal agencies to perform forensic triage and mitigate the flaw.
- [21]
Flaws in Check Point (CVE-2026-85102 and CVE-2026-93616), Arista VeloCloud Orchestrator (CVE-2026-93952), F5 BIG-IP Access Policy Manager (CVE-2026-94127), Cisco Catalyst SD-WAN Manager (CVE-2026-76504), and Citrix NetScaler ADC and NetScaler Gateway (CVE-2026-88771 and CVE-2026-88772) have come under in-the-wild exploitation.
- [22]
Fortinet has acknowledged that the vulnerability has been exploited in the wild.
- [23]
Fortinet said it is communicating with relevant government organizations, including CISA, on the content of the advisory.
- [24]
As published, no affected FortiMail branch has a released fixed build: every released 7.4 build through 7.4.8 is affected and 7.4.9, 7.6.7 and 8.0.2 are all upcoming, so a 7.2 appliance moved to the 7.4 branch lands on an affected version until 7.4.9 ships.
Derived - [25]
Fortinet's indicators list seven file paths.
Derived - [26]
The remote server in the archive234 account, 79.141.169.187, is one of the two IP addresses Fortinet lists as indicators of compromise.
Derived - [27]
The other exploited flaws listed alongside FortiMail total seven CVEs across five vendors.
Derived - [28]
The root cron command in the logs and the modified file /data/migadmin.tar.gz both reference migadmin.
Derived - [29]
An IBE decryption error in the log samples, together with disabling IBE as a workaround, is consistent with an exploit path through the IBE component.
Derived - [30]
If disabling IBE and restricting the management interface are each sufficient on their own, an appliance is exposed only when IBE is enabled and the management interface is reachable from untrusted networks.
Derived - [31]
Neither workaround changes the archive234 account: the IBE workaround edits the encryption IBE setting and the interface restriction limits access, while the archive account is a separate configuration entry with its own remote destination.
Derived - [32]
Fortinet's advisory includes five sample log events.
Derived
Sources & coverage · 2 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- bleepingcomputer.com3d agoFortinet warns of critical FortiMail flaw exploited in zero-day attacks
Additional citations
- The Hacker News
- Fortinet advisory, quoted by The Hacker News
- BleepingComputer
- Fortinet advisory via The Hacker News
- Fortinet advisory log sample, reproduced by BleepingComputer
- Fortinet advisory log samples, reproduced by BleepingComputer
- Fortinet statement to BleepingComputer
- The Hacker News, citing CISA