Security7 publishers2 min readPublished
Fortinet tells FortiMail admins to disable IBE while an exploited CVSS 9.8 flaw awaits fixes
Fortinet says attackers are exploiting a CVSS 9.8 unauthenticated file-write flaw in FortiMail, and no fixed release has shipped yet. Until builds arrive, its two workarounds are the only protection, including for 7.2 users told to move to a 7.4 branch that is still unpatched.
The Watch · Security desk

What happened
- BleepingComputer reports the bug is in the FortiMail management interface and is being used to run unauthorized code or commands on vulnerable devices.
- Fortinet published its advisory on October 1, 2026, and CISA added the flaw to its KEV catalog the same day, giving federal civilian agencies until October 4.
- Fixes are due in FortiMail 7.4.9, 7.6.7 and 8.0.2, none of them released yet, and Fortinet tells 7.2 users to move to the 7.4 branch or above.
- Until then, Fortinet says admins can disable IBE from the CLI, or block internet access to the management interface and allow only trusted private networks.
- Fortinet published indicators of compromise, including two attacker IP addresses, lists of added and modified files, and log entries for checking appliances.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- decision FortiMail 7.2 operators have two jobs at once: apply a workaround now, and plan a branch migration that will not remove the flaw until 7.4.9 or a later fixed build exists.
- cost Customers who turn IBE off lose identity-based encryption until a fix ships. The other workaround, keeping the management interface off the internet, leaves IBE running.
- exposure Appliances that were reachable before a workaround went in may already have the added files or an attacker's archive account, and CISA's order requires federal agencies to do forensic triage as well as mitigation.
Fortinet classes the 9.8-rated bug as a path traversal combined with improper handling of NULL bytes [1]. It said the flaw "may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests" [2]. Fortinet found it internally and credited Gwendal Guégniaud of its Product Security team [8].
The version table makes the 7.2 advice harder to follow. Every build from 7.2.0 through 7.2.9 is affected, and Fortinet's only route out is the 7.4 branch or above [4]. A 7.2 appliance moved to 7.4 today lands on 7.4.8 or earlier, which is still inside the affected range [2]. The same goes for 7.6 and 8.0 [1]. BleepingComputer wrote that 7.2 users "can patch the vulnerability by upgrading to the 7.4 branch or later" [18]. Going by Fortinet's own version numbers, that is only true once 7.4.9, 7.6.7 or 8.0.2 ships [1].
Fortinet's sample log entries include an IBE decryption error caused by invalid Base64 encoding [12]. IBE, FortiMail's identity-based encryption feature, is what the first workaround turns off [6][7].
The file indicators show what attackers leave on a box. Four files are added: `/data/lib/liblog.so`, `/data/bin/webconsole`, `/data/bin/mailservice` and `/data/etc/ld.so.preload` [9]. Three are modified: `/bin/smit`, `/data/etc/httpd.conf` and `/data/migadmin.tar.gz` [9]. A cron entry in the logs runs a command tied to `/migadmin` [12]. Another entry shows an archive account named archive234 added from the CLI, with 79.141.169.187 as the remote server and /uploads as the remote directory [10]. That address is one of the two attacker IPs Fortinet published [4]. "This could indicate that the attacker configured the compromised FortiMail appliance to send archived data to a remote server," BleepingComputer wrote [11].
CISA's deadline falls three days after the listing [3]. When BleepingComputer asked for more detail on the exploitation, Fortinet referred customers to the advisory [15]. "Fortinet published an advisory to provide guidance regarding CVE-2026-104286 (FG-IR-26-175), including workarounds to help customers mitigate risk," Fortinet told BleepingComputer [14]. It said it is communicating with government organizations, including CISA [15].
Fortinet has not disclosed when exploitation began, how many systems were compromised, or who is behind the attacks [13]. The Hacker News reported the flaw in the same piece as in-the-wild exploitation of bugs in Check Point, Arista VeloCloud Orchestrator, F5 BIG-IP Access Policy Manager, Cisco Catalyst SD-WAN Manager and Citrix NetScaler ADC and Gateway [19]. With no actor named, the only links to those cases are timing and the type of product [13][19]. The only attacker infrastructure Fortinet has published for this campaign is two IP addresses [9].
What to watch
- Release of FortiMail 7.4.9, 7.6.7 or 8.0.2. Until one ships, moving a 7.2 appliance to 7.4 does not fix the flaw.
- A Fortinet or CISA attribution or exploitation start date. Either would show whether the FortiMail intrusions are part of the wider run of attacks on network appliances.
- New indicators beyond the two published IP addresses, such as other archive accounts or remote servers found in customer logs.