On 1 October 2026 Fortinet disclosed CVE-2026-104286, a critical FortiMail zero-day vulnerability that attackers were already exploiting and for which no fixed release existed that day on any affected branch (7.2, 7.4, 7.6 and 8.0). The same day CISA added it to its KEV catalogue of exploited vulnerabilities and gave US federal civilian agencies until 4 October to run forensic triage on their gateways and apply the mitigation, BleepingComputer reported.
As of 5 October, Fortinet's documentation carries release notes for 7.6.7 and 7.4.9, although the advisory still describes them as upcoming. Patch or no patch, the first job is to find out whether someone tampered with the gateway beforehand, because the upgrade will not tell you.
What does CVE-2026-104286 allow, and which FortiMail versions are affected?
CVE-2026-104286 is a critical FortiMail vulnerability that pairs a path traversal (CWE-22) with improper handling of the NULL byte (CWE-158) and affects the 7.2, 7.4, 7.6 and 8.0 branches. Fortinet's advisory of 1 October 2026 says an unauthenticated attacker can write arbitrary files to the underlying system through crafted HTTP or HTTPS requests. The CVSS score is 9.8 out of 10.
Field Effect places the vulnerable code in the part of the web interface that handles requests for IBE (Identity-Based Encryption), FortiMail's encrypted mail service. Writing a file is not the same as running code, but Fortinet's advisory classes the impact as execution of unauthorised code or commands.
Affected versions and fix for each branch, according to Fortinet's advisory and documentation:
- Branch 8.0 (8.0.0 to 8.0.1): fix announced in 8.0.2, which we could not confirm as published on 5 October.
- Branch 7.6 (7.6.0 to 7.6.6): fixed in 7.6.7, with release notes dated 2 October.
- Branch 7.4 (7.4.0 to 7.4.8): fixed in 7.4.9, with release notes dated 3 October.
- Branch 7.2 (7.2.0 to 7.2.9): no fix announced. The advisory says to move to branch 7.4 or above, and the target has to be 7.4.9 or later, because 7.4.0 to 7.4.8 are still vulnerable.
The vulnerability was found by Gwendal Guégniaud of Fortinet's Product Security team, according to Help Net Security. Fortinet went public with indicators before the patch was finished, which let customers check their gateways without waiting for the upgrade.
When did the FortiMail advisory come out, and is there a patch yet?
Fortinet published advisory FG-IR-26-175 on 1 October 2026 with no fixed releases, and release notes for 7.6.7 and 7.4.9 appeared in its documentation on 2 and 3 October. The known sequence is this:
- Date unknown: exploitation begins. Fortinet has not said when it started or how many customers were hit. The sample log entries in the STIX bundle published with the advisory are dated 20 July 2026.
- 1 October: Fortinet publishes the advisory with affected versions, a mitigation and indicators.
- 1 October: CISA adds the flaw to the KEV, and the Canadian Centre for Cyber Security publishes advisory AV26-989.
- 2 October: Spain's INCIBE-CERT publishes its own advisory, rated critical. That day TechTimes reports that the fixed releases are still not out.
- 2 and 3 October: Fortinet's document library publishes release notes for FortiMail 7.6.7 and 7.4.9. Both list path traversal (CWE-22) fixes, although neither cites the CVE identifier.
- 4 October: the US federal deadline expires.
- 5 October, at the time of writing: the advisory still describes 8.0.2, 7.6.7 and 7.4.9 as "upcoming". Check the advisory and Fortinet's support portal before scheduling the upgrade.
Three days is the most urgent tier of BOD 26-04, CISA's risk-based patching directive, in its variant with forensic triage. The directive binds only US federal civilian agencies, though a European security lead can use it as a reference when justifying a priority to the board.
How does the FortiMail path traversal with a NULL byte work?
A path traversal exploits an application that builds a file path from data in the request and does not check that the result stays inside the intended folder. The NULL byte adds a second trick, because some functions read it as the end of the string. The check sees one name and the file system ends up using another.
With this class of flaw, whoever reaches the interface may be able to drop a file where the system will load it later. The published indicators fit that logic, because the added files include /data/etc/ld.so.preload. On Linux, /etc/ld.so.preload lists libraries the dynamic loader injects into dynamically linked processes as they start. A rogue library on that list is loaded with them and, if the file sits on persistent storage, is still there after a reboot.
Roman Sannikov of iCounter told SC World that the mechanism goes a long way towards giving the attackers persistence on top of access. According to VulnTracker, quoted by TechTimes, the flaw can also take FortiMail out of service.
Who is exposed to CVE-2026-104286?
Judging by the mitigations in Fortinet's advisory, the exposed FortiMail gateways are those on an affected branch with IBE enabled and a web interface the attacker can reach. Fortinet's text names the webmail interface, while BleepingComputer, Help Net Security and Field Effect describe it as the management interface.
The FortiMail CLI reference gives disable as the default for IBE, so the service is off unless somebody turned it on. Each gateway should still be checked. There are no public figures for exposed devices or victims, and Fortinet has not attributed the attacks to any group.
Seemant Sehgal of BreachLock notes in SC World that management interfaces reachable from the internet are a frequent finding on perimeter appliances. Attack surface management finds those exposures, and vulnerability management shows which branch each gateway runs. Anyone still on 7.2 has an added difficulty, because the way out is a branch change, with the testing that requires on a system carrying the organisation's mail.
Why does a mail gateway matter more than other perimeter kit?
A mail gateway such as FortiMail matters more than other perimeter kit because it receives inbound mail before the mailboxes do, holds the quarantine and applies the filtering rules. The specialists SC World spoke to describe what someone in control of it can do: capture administrator credentials, read password reset links and change the filtering.
John Bambenek of Bambenek Consulting adds that almost every case of business email compromise he has examined involved mail forwarding rules.
FortiMail is also a closed appliance that takes no EDR agent, so what happens inside shows up mainly in the gateway's logs and in the traffic it generates. We covered that difficulty in our piece on agentless detection for network edge devices.
Which FortiMail indicators of compromise (IoCs) should you look for?
The indicators of compromise (IoCs) Fortinet published on 1 October 2026 for CVE-2026-104286 are files, IP addresses and log entries tied to the intrusions. BleepingComputer reproduces the files with their paths and SHA-256 hashes. This summary is a guide for the review; take the full value of each indicator of compromise from the advisory and its downloadable STIX bundle, which is where Fortinet publishes the hashes.
Files added or modified
/data/etc/ld.so.preloadand/data/lib/liblog.so, added. The first points to the second, which fits a persistence mechanism./data/bin/webconsoleand/data/bin/mailservice, added under names that blend in on a mail system./bin/smit,/data/etc/httpd.confand/data/migadmin.tar.gz, modified.
Log entries and IP addresses
Fortinet's advisory lists several log entries and two IP addresses, 79.141.169.187 and 45.129.0.192. The first entry is the creation of an archive account called archive234 with a remote destination at 79.141.169.187 and the /uploads folder. The second is a cron job, run as root, related to /migadmin. According to the advisory's STIX bundle, that job dumps the appliance configuration into an HTML file under /migadmin/www and deletes it after 24 hours.
Of the two entries, the archive account is the more serious. Archiving is a legitimate FortiMail feature that keeps a copy of messages, and the remote destination suggests it was used for data exfiltration with the product's own tooling. The STIX bundle contains two archive policies with pattern * tied to that account, meaning they apply to all mail. Because this is configuration, a comparison of file hashes is unlikely to catch it, and there is no reason to assume a firmware upgrade removes it.
A detection team can hunt for non-SMTP outbound connections from the gateway to destinations other than the vendor's update servers and known internal systems. Apart from mail delivery, a gateway's outbound traffic is fairly predictable, provided those logs are shipped to another system. Our guide on which logs to send to the SIEM covers how to prioritise them.
How do you mitigate CVE-2026-104286 before upgrading?
Fortinet's advisory of 1 October 2026 mitigates CVE-2026-104286 by disabling IBE and offers two network measures as alternatives, which can be combined with it:
- Disable IBE from the console with
config system encryption ibefollowed byset status disable, or from the GUI. First confirm that no user depends on mail encrypted through that service. - Take FortiMail's web access off the internet and limit it to trusted internal networks.
- Where a web application firewall sits in front of FortiMail, block POST requests to
/ibethat contain../.
If the review finds any of the indicators, treat the gateway as compromised. First preserve the logs and a copy of the configuration, and do not change the device until that is done. Then assume the credentials the gateway stores or sees in transit are compromised: administrator accounts, the credentials for the directory connection and any passwords reset by email during the period in doubt.
We found no published instructions from Fortinet for cleaning an affected gateway. The conservative option, which Field Effect also raises, is to rebuild from a trusted image and review the configuration line by line before restoring it.
Last week we described the same problem with another vendor: patching NetScaler does not evict whoever was already inside. The same applies to FortiMail, because the upgrade will not tell you whether someone got in first.
When does a FortiMail compromise become a notifiable data breach?
A FortiMail compromise becomes a personal data breach under the GDPR once the organisation confirms that mail was copied to an outside server. The GDPR requires notifying the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to the people affected. Entities under NIS2 must also send an early warning within 24 hours when the incident is significant.
Working out which mailboxes and which period were affected takes digital forensics. Coordinating that with the notification deadlines is part of incident response.
What is still unknown about CVE-2026-104286?
As of 5 October 2026 these points are still open:
- An update of advisory FG-IR-26-175 with the fixed versions, and confirmation of 8.0.2.
- Public technical analysis or exploit code, which would widen the pool of attackers able to use the flaw.
- An attribution, the start date of the attacks or new indicators.
In the meantime, copy the gateway's logs to another system, because after the upgrade they will be the remaining evidence of what happened beforehand.
This article is informational and defensive, written from the public information available as of 5 October 2026. It contains no exploit code. The paths, console commands, addresses and indicators cited come from Fortinet's advisory, its STIX bundle and the linked sources: check them against the original and test them before applying them in production. Versions, dates and attributions may change.
Frequently asked questions
What is CVE-2026-104286?
▾
CVE-2026-104286 is a critical vulnerability in Fortinet FortiMail, rated CVSS 9.8, that combines a path traversal with improper handling of the NULL byte. It lets an attacker with no credentials write files to the system through HTTP or HTTPS requests to the web interface. Fortinet disclosed it on 1 October 2026, when it was already being exploited.
Is there a patch for the FortiMail zero-day?
▾
No patch for the FortiMail zero-day CVE-2026-104286 existed on 1 October 2026, the day of the advisory. Fortinet announced fixes in 8.0.2, 7.6.7 and 7.4.9 and told users on the 7.2 branch to move to branch 7.4 or later. As of 5 October 2026 Fortinet's documentation carries release notes for 7.6.7 and 7.4.9, while advisory FG-IR-26-175 still calls them "upcoming"; we could not confirm 8.0.2. Consult the advisory and the support portal for the current status.
How can we tell whether a FortiMail gateway has been compromised?
▾
Fortinet's advisory ties a FortiMail compromise through CVE-2026-104286 to four kinds of indicator: files such as ld.so.preload or liblog.so under /data, archive accounts with a remote destination that nobody in the organisation created, cron jobs that reference /migadmin, and connections from the gateway to 79.141.169.187 or 45.129.0.192.
What mitigation does Fortinet recommend for CVE-2026-104286?
▾
Fortinet recommends disabling the IBE encrypted mail service, from the console or the GUI. As alternatives it says to stop FortiMail's web interface (webmail, in the advisory's wording) being reachable from the internet and, where a web application firewall sits in front, to block POST requests to /ibe that contain "../". Before disabling IBE, confirm that no user depends on that encryption.
Is upgrading FortiMail to the fixed release enough?
▾
Upgrading FortiMail is not enough if the gateway was tampered with before the patch. The indicators Fortinet published include files that point to a persistence mechanism and an archive account directed at an external server. The account is product configuration and there is no reason to assume the upgrade removes it, so it has to be looked for, and the credentials the gateway stored or saw in transit changed afterwards.
Do we know who is behind the FortiMail attacks and how many victims there are?
▾
As of 5 October 2026 there is no public attribution for the FortiMail attacks and no victim count, and Fortinet has not said when they began. The sample log entries published with the advisory are dated 20 July 2026. What has been published is limited to the files, IP addresses and log entries seen on compromised systems.
Why did CISA allow only three days when no patch existed?
▾
CISA allowed three days, until 4 October 2026, because the deadline covers mitigation and forensic triage, two tasks that do not depend on the update. Three days is the most urgent tier of directive BOD 26-04, issued on 10 June 2026 for US federal civilian agencies. European companies are not bound by it but can use it as a benchmark for priority.