Full Report
Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices. [...]
Analysis Summary
# Vulnerability: Critical FortiMail Remote Code Execution via Path Traversal
## CVE Details
- **CVE ID:** CVE-2026-104286
- **CVSS Score:** 9.8 (Critical)
- **CWE:** CWE-22 (Improper Limitation of a Pathname to a Restricted Directory) and CWE-158 (Improper Neutralization of NULL Byte)
## Affected Systems
- **Products:** Fortinet FortiMail
- **Versions:**
- FortiMail 8.0.0 through 8.0.1
- FortiMail 7.6.0 through 7.6.6
- FortiMail 7.4.0 through 7.4.8
- FortiMail 7.2.0 through 7.2.9
- **Configurations:** Systems with the management interface exposed or the Identity Based Encryption (IBE) feature enabled.
## Vulnerability Description
This vulnerability exists in the FortiMail management interface. It stems from a combination of path traversal (CWE-22) and NULL byte injection (CWE-158) flaws. An unauthenticated attacker can send specially crafted HTTP or HTTPS requests to bypass directory restrictions and write arbitrary files to the underlying system. This capability allows for unauthorized command execution or full system compromise.
## Exploitation
- **Status:** Exploited in the wild (Zero-day)
- **Complexity:** Low
- **Attack Vector:** Network (Remote)
## Impact
- **Confidentiality:** High (Potential for full data exfiltration)
- **Integrity:** High (Ability to write arbitrary files and modify system binaries)
- **Availability:** High (Potential for full system takeover or disruption)
## Remediation
### Patches
Official security updates are not yet available for most versions. The recommended upgrade paths are:
- **FortiMail 8.0.x:** Upgrade to **8.0.2** (Upcoming)
- **FortiMail 7.6.x:** Upgrade to **7.6.7** (Upcoming)
- **FortiMail 7.4.x:** Upgrade to **7.4.9** (Upcoming)
- **FortiMail 7.2.x:** Upgrade immediately to the **7.4 branch or later** versions containing the fix.
### Workarounds
1. **Disable IBE Feature:** Execute the following CLI commands:
config system encryption ibe
set status disable
end
2. **Restrict Management Access:** Disable access to the FortiMail management interface from the Internet. Limit access only to trusted private networks/VPNs.
## Detection
### Indicators of Compromise (IOCs)
**File Hashes (SHA-256):**
- `8015f34dc84922b03688399d7f9fe7a00361789f7e420c7e2a2cdb23e75cef84` (/data/lib/liblog.so - Added)
- `77324ac428bde86d351fc5fc06f6d64a6bfe737dfb2743df1d4c5ac2418a5b6a` (/bin/smit - Modified)
- `7a6cea9f5c9e2e9994d4e3c4da73f86cf5acd05ea5d312c066c9d1dafd69ee38` (/data/bin/webconsole - Added)
- `8953ec7960b09f544a880b072ad4e6cfda7a8303f486251d3478dcfdfbac23b6` (/data/etc/ld.so.preload - Added)
**Malicious IP Addresses:**
- `79[.]141.169.187`
- `45[.]129.0.192`
### Detection Methods
Review system logs for:
- Unauthorized creation of an archive account (e.g., `archive234`).
- CLI log entries showing data being routed to remote IPs via `remote-ip`.
- Unexpected cron jobs executing commands related to `/migadmin`.
- Log entries showing `Caught BufferException(2)` with `Invalid Base64 Encoding`.
## References
- **Vendor Advisory:** hxxps://fortiguard[.]fortinet[.]com/psirt/FG-IR-26-175
- **CISA KEV Catalog:** hxxps://www[.]cisa[.]gov/known-exploited-vulnerabilities-catalog
- **BleepingComputer Article:** hxxps://www[.]bleepingcomputer[.]com/news/security/fortinet-warns-of-critical-fortimail-flaw-exploited-in-zero-day-attacks/