Full Report
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerability, tracked as CVE-2026-104286 (CVSS score: 9.8), allows unauthenticated attackers to write arbitrary files on the underlying system. "An improper
Analysis Summary
# Vulnerability: Fortinet FortiMail Unauthenticated Arbitrary File Write
## CVE Details
- **CVE ID:** CVE-2026-104286
- **CVSS Score:** 9.8 (Critical)
- **CWE:** CWE-22 (Path Traversal) and CWE-158 (Improper Neutralization of NULL Byte)
## Affected Systems
- **Products:** Fortinet FortiMail
- **Versions:**
- 8.0.0 through 8.0.1
- 7.6.0 through 7.6.6
- 7.4.0 through 7.4.8
- 7.2.0 through 7.2.9
- **Configurations:** Systems with the Identity Based Encryption (IBE) feature enabled and management interfaces exposed to the internet.
## Vulnerability Description
This flaw exists due to improper limitation of pathnames to restricted directories combined with improper handling of NULL byte characters in HTTP/HTTPS requests. An unauthenticated remote attacker can exploit this to perform arbitrary file writes on the underlying operating system, potentially leading to full system compromise.
## Exploitation
- **Status:** Exploited in the wild (Added to CISA KEV catalog).
- **Complexity:** Low
- **Attack Vector:** Network (Remote)
## Impact
- **Confidentiality:** High
- **Integrity:** High
- **Availability:** High
## Remediation
### Patches
Fortinet recommends upgrading to the following versions as they become available:
- **FortiMail 8.0.x:** Upgrade to 8.0.2 or above.
- **FortiMail 7.6.x:** Upgrade to 7.6.7 or above.
- **FortiMail 7.4.x:** Upgrade to 7.4.9 or above.
- **FortiMail 7.2.x:** Upgrade to branch 7.4 or above.
### Workarounds
If patches cannot be immediately applied:
1. **Disable IBE Feature:** Execute the following CLI command:
`config system encryption ibe`
`set status disable`
`end`
2. **Restrict Access:** Disable internet-facing access to the FortiMail management interface or restrict access to trusted private networks only.
## Detection
### Indicators of Compromise (IoCs)
**Attacker IP Addresses:**
- 79.141.169[.]187
- 45.129.0[.]192
**Added/Modified Files:**
- `/data/lib/liblog.so` (added)
- `/data/bin/webconsole` (added)
- `/data/bin/mailservice` (added)
- `/data/etc/ld.so.preload` (added)
- `/bin/smit` (modified)
- `/data/etc/httpd.conf` (modified)
- `/data/migadmin.tar.gz` (modified)
## References
- **Vendor Advisory:** hxxps://fortiguard[.]fortinet[.]com/psirt/FG-IR-26-175
- **CISA KEV Catalog:** hxxps://www[.]cisa[.]gov/known-exploited-vulnerabilities-catalog
- **News Source:** hxxps://thehackernews[.]com/2026/10/critical-fortimail-zero-day-flaw.html