FortiMail Zero-Day Exploited to Write Arbitrary Files
AI-generated image

FortiMail Zero-Day Exploited to Write Arbitrary Files

CISA warns that CVE-2026-104286, a critical FortiMail path traversal flaw, is actively exploited and allows unauthenticated arbitrary file writes.

Fortinet FortiMail has a critical zero-day vulnerability that is being actively exploited, according to a Thursday notice from the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The agency added the flaw to its Known Exploited Vulnerabilities (KEV) catalog, a list of security weaknesses that attackers are already using in real attacks. The vulnerability is tracked as CVE-2026-104286 and carries a CVSS severity score of 9.8 out of 10, which puts it in the critical range. In practical terms, the weakness lets someone without any login credentials write files onto the underlying system of a FortiMail email security appliance or virtual machine.

Fortinet describes the problem as a combination of two issues: an improper limitation of a pathname to a restricted directory, known as path traversal or CWE-22, and an improper neutralization of a NULL byte or NULL character, known as CWE-158. Path traversal means an attacker can point the software toward files and folders outside the area it is supposed to access. A NULL byte is an invisible character that some programs use to mark the end of a text string; by inserting one, an attacker may trick the system into ignoring part of a file path. Together, these weaknesses allow an unauthenticated attacker to write arbitrary files on the underlying system by sending specially crafted HTTP or HTTPS requests. That means no password or account access is required to carry out the write.

The advisory lists the following affected product lines: FortiMail 8.0.0 through 8.0.1, with an upgrade to upcoming 8.0.2 or above; FortiMail 7.6.0 through 7.6.6, with an upgrade to upcoming 7.6.7 or above; FortiMail 7.4.0 through 7.4.8, with an upgrade to upcoming 7.4.9 or above; and FortiMail 7.2.0 through 7.2.9, with an upgrade to branch 7.4 or above. Because fixes for some versions were not yet released at the time of the advisory, Fortinet has shared temporary workarounds. Customers can disable what Fortinet calls IBE feature support, an encryption feature in the product, by entering the following command sequence in the command line interface: config system encryption ibe, set status disable, end. Administrators should also disable access to the FortiMail management interface from the internet or restrict it to trusted private networks only, because the attack uses HTTP or HTTPS requests and an internet-facing management page is the primary way an attacker could reach the vulnerable code.

Fortinet credited Gwendal Guégniaud of the Fortinet Product Security team with discovering and reporting the flaw. The company also published indicators of compromise (IOCs), which are specific signs that a system may have been attacked. The listed IP addresses are 79.141.169[.]187 and 45.129.0[.]192. The listed files include added entries at /data/lib/liblog.so, /data/bin/webconsole, /data/bin/mailservice, and /data/etc/ld.so.preload, as well as modified entries at /bin/smit, /data/etc/httpd.conf, and /data/migadmin.tar.gz. Administrators can search for these filenames and connections to those addresses to check whether their systems were affected before patching.

Because the vulnerability is being used in the wild, CISA says Federal Civilian Executive Branch (FCEB) agencies should apply the patch or workarounds by October 4, 2026. That deadline is meant to push government systems to act quickly, but it also serves as a useful signal for private organizations that time is short. The FortiMail alert arrives alongside a wider wave of actively exploited vulnerabilities. The source article lists additional flaws under in-the-wild exploitation in products from Check Point (CVE-2026-85102 and CVE-2026-93616), Arista VeloCloud Orchestrator (CVE-2026-93952), F5 BIG-IP Access Policy Manager (CVE-2026-94127), Cisco Catalyst SD-WAN Manager (CVE-2026-76504), and Citrix NetScaler ADC and NetScaler Gateway (CVE-2026-88771 and CVE-2026-88772). Each of these is a separate security issue in a different product, but the pattern shows attackers are targeting internet-facing management and security appliances at the same time.

For website owners and businesses, the main lesson is that any internet-facing security or mail appliance must be treated as a high-value target and updated or isolated as soon as a vendor advisory appears. In an email security gateway, the ability to write files without authentication can be used to add malicious programs, alter configuration, or tamper with mail handling, which is why CISA treats this as critical. For organizations that run internet-facing mail or web infrastructure and need help applying vendor mitigations or reviewing network exposure, AEU-I offers security-first IT and infrastructure consulting that can support that work.

How to Protect Yourself

  1. If your business uses FortiMail, ask your IT person or hosting provider to check the version and install the update or workaround now.
  2. Make sure the FortiMail control panel is not reachable from the public internet; it should only be available from your office network or a secure VPN.
  3. Watch your email server logs for the two IP addresses in the advisory, and ask your IT support to block them.
  4. Turn off the FortiMail IBE feature using the steps in Fortinet's notice if you do not need it, until the patch is available.
  5. Have someone regularly check that the files Fortinet listed, like /data/bin/webconsole, do not appear on your system unless they should.

Vulnerabilities & Fixes

Terms Explained

  • CVE Common Vulnerabilities and Exposures, a public list that gives each known security weakness a unique number so everyone can refer to it clearly.
  • CVSS Common Vulnerability Scoring System, a score from zero to ten that rates how serious a security flaw is.
  • KEV Known Exploited Vulnerabilities, a list kept by CISA of security weaknesses that attackers are already using in real attacks.
  • Path traversal A type of weakness that lets an attacker point a program to files or folders outside the area it is supposed to use.
  • NULL byte An invisible character that some programs treat as the end of a text string, which attackers can insert to bypass checks.
  • Unauthenticated Meaning no login name or password is needed to perform the action.
  • IOC Indicator of compromise, a specific sign such as an IP address or a file name that may show an attack has occurred.
  • IBE A FortiMail encryption feature that the advisory allows administrators to disable as a temporary protection.

Related AEU services

  • AEU-I IT and security consulting