Fortinet FortiMail Zero-Day CVE-2026-104286 Actively Exploited—Disable IBE Now
Fortinet is warning customers about a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks. The flaw allows unauthenticated attackers to write arbitrary files to vulnerable appliances, potentially enabling malicious code or command execution.
The vulnerability affects the FortiMail management interface and has a CVSS score of 9.8.
Critical FortiMail vulnerability allows arbitrary file writing
Fortinet describes CVE-2026-104286 as involving improper pathname restrictions to restricted directories, also known as path traversal, and improper invalidation of NULL bytes or NULL characters. The issues are tracked under CWE-22 and CWE-158.
“This vulnerability could allow an unauthenticated attacker to write arbitrary files to the underlying system via a crafted HTTP or HTTPS request,” Fortinet said in its security advisory published Thursday.
Fortinet’s Product Security team member Gwendal Guégniaud discovered the vulnerability internally.
Affected FortiMail versions
The vulnerability affects the following FortiMail releases:
- FortiMail 8.0.0 through 8.0.1
- FortiMail 7.6.0 through 7.6.6
- FortiMail 7.4.0 through 7.4.8
- FortiMail 7.2.0 through 7.2.9
Fortinet says CVE-2026-104286 is actively exploited and is asking customers to apply the available workarounds until a security update can be installed.
FortiMail patch and workaround guidance
FortiMail 7.2 customers can address the vulnerability by upgrading to the 7.4 branch or later. Security updates are not yet available for affected FortiMail 7.4, 7.6, and 8.0 installations. Fortinet lists the following future releases as containing the fix:
- FortiMail 7.4.9
- FortiMail 7.6.7
- FortiMail 8.0.2
Until a patched version is available, administrators can mitigate the vulnerability by disabling support for the IBE feature with the following command:
config system encryption ibe
set status disable
end
Administrators should also disable access to the FortiMail management interface from the Internet or restrict access to trusted private networks.
Fortinet releases indicators of compromise
Fortinet published indicators of compromise (IOCs) associated with the attacks, including files that were added or modified on compromised systems.
| File | Situation | SHA-256 |
|---|---|---|
/data/lib/liblog.so |
Added | 8015f34dc84922b03688399d7f9fe7a00361789f7e420c7e2a2cdb23e75cef84 |
/bin/smit |
Fixed | 77324ac428bde86d351fc5fc06f6d64a6bfe737dfb2743df1d4c5ac2418a5b6a |
/data/bin/webconsole |
Added | 7a6cea9f5c9e2e9994d4e3c4da73f86cf5acd05ea5d312c066c9d1dafd69ee38 |
/data/bin/mailservice |
Added | 4000276a150a165d3c2537d1e19fb393c4de8333076a16655e28059cae82157b |
/data/etc/httpd.conf |
Fixed | 703e97c64e61e41dc3aaba580d82bb2aa7b6a11b54ee6fb467ed5d5a3bffdef5 |
/data/etc/ld.so.preload |
Added | 8953ec7960b09f544a880b072ad4e6cfda7a8303f486251d3478dcfdfbac23b6 |
/data/migadmin.tar.gz |
Fixed | d6fe51c22b91776f4c961ea58bcac5917f15d560a619d7ce726d3d51795609d3 |
Fortinet also identified 79[.]141.169.187 and 45[.]129.0.192 as IP addresses associated with the attack.
Logs that may indicate a compromised FortiMail appliance
The advisory includes log entries that administrators can use to identify potentially compromised systems.
One entry shows an archive account named archive234 configured from the command line, with 79.141.169.187 set as the remote server and /uploads as the remote directory. This may indicate that an attacker configured a compromised FortiMail appliance to send archived data to a remote server.
Other suspicious entries include a cron job running /migadmin, administrator logout events, IBE decryption errors caused by invalid Base64 encoding, and failed login attempts.
Fortinet shared the following example log events:
type=event subtype=system pri=debug user=system ui=cron msg="(root) CMD (/bin/sh -c 'O=/migadmin ...
type=kevent subtype=admin pri=information user=admin ui=(null) action=logout status=success reason=unknown msg="User admin logged out from (null)."
type=kevent subtype=config pri=information user=admin ui=cli module=unknown submodule=unknown msg="Added 'archive234' to 'archive account' : rotation-size[50] rotation-time[1] rotation-hour[14] destination[remote] remote-ip[79.141.169.187] remote-username[archive234] remote-password[***] remote-directory[/uploads] (user: admin, from: cli)"
FortiMail::IBE::DecrypterMediaIn::DecrypterMediaIn(FortiMail::MediaIn&, const FortiMail::IBE::KeyFinder&, const FortiMail::EmailAddress&, const FortiMail::Buffer&, FortiMail::IBE::DecrypterMediaIn::Version): Caught BufferException(2), BufferImpl.cpp:973, 'Invalid Base64 Encoding at pos 0. Character=0x2a'
Internal user *@domain.tld failed to log in.
CISA adds CVE-2026-104286 to its exploited vulnerabilities catalog
Fortinet did not say when the flaw was first exploited, how many systems were compromised, or who was behind the attacks.
When BleepingComputer asked for more information about the exploit, Fortinet directed customers to its advisory and said it was coordinating with government agencies, including CISA.
“Fortinet has published an advisory providing guidance regarding CVE-2026-104286 (FG-IR-26-175), including workarounds to help reduce risk for customers,” Fortinet told BleepingComputer.
“In line with Fortinet’s commitment to responsible PSIRT disclosure and public-private partnerships, we are communicating with relevant government agencies, including CISA, regarding the content of this recommendation.”
CISA has added CVE-2026-104286 to its catalog of known exploited vulnerabilities and is asking federal agencies to conduct forensic triage and mitigate the flaw by October 4.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a two-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, correct, and revalidate at machine speed.
Source: www.bleepingcomputer.com



