Guide

Fortinet Warns Critical FortiMail Zero-Day Lets Attackers Write System Files Without Login

Attackers have been quietly breaking into Fortinet's FortiMail email security gateways through a flaw nobody had patched. Fortinet warned this week tha

Attackers have been quietly breaking into Fortinet's FortiMail email security gateways through a flaw nobody had patched. Fortinet warned this week that CVE-2026-104286, rated 9.8 out of 10 on the CVSS scale, is being exploited in zero-day attacks against the appliance's management interface.

The bug is a path traversal combined with a NULL-byte trick. By sending crafted HTTP or HTTPS requests, an unauthenticated attacker can write arbitrary files to the system. No password, no session, no user interaction. On a box that sits in front of a company's entire email flow, that is about as bad as it gets.

The vulnerable releases cover most of the product line: FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8 and 7.2.0 through 7.2.9. The flaw was found internally by Fortinet researcher Gwendal Guegniaud, which suggests the company caught it while investigating real intrusions.

Here is the uncomfortable part. Fixed builds for 7.4.9, 7.6.7 and 8.0.2 are still listed as upcoming, and customers on 7.2 are told to move up to 7.4 or later. Until patches land, Fortinet's workaround is to disable the IBE (Identity Based Encryption) feature or pull the management interface off the public internet entirely.

Fortinet also published indicators of compromise that show what the attackers do once inside: dropped libraries, modified binaries and a remote exfiltration configuration named "archive234." Admins should check logs for traffic from 79.141.169.187 and 45.129.0.192, two attacker IP addresses listed in the advisory.

CISA has added the flaw to its Known Exploited Vulnerabilities catalog and gave federal agencies until October 4 to mitigate it, an unusually tight window. The agency has been moving fast on edge and enterprise bugs lately, from the SharePoint flaw that led to webshell drops to a batch covering SharePoint, vCenter, macOS and IKE.

Email gateways are a favorite target for a reason. They see every message, hold credentials and sit at the network edge with an admin panel that too many organizations leave exposed. For FortiMail customers, the attackers got there first, and the full fix is still on its way.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free