Events Join us at the AWS Summit in Dubai on 30th September
Read

Attackers Are Inside the Mail Gateway: FortiMail Zero-Day Exploited Before a Patch Exists

Attackers are writing files to FortiMail appliances through an unauthenticated flaw. No patch exists yet, only a solution and published IOCs.

TL;DR: On Wednesday, the company that sells email security to much of the Fortune 500 told its customers to go switch a feature off. By the next morning, the US cyber agency had added the bug to its catalog of flaws under active attack and given federal agencies until October 4 to deal with it. For most organizations running FortiMail, there is still nothing to install.

What Happened?

A critical flaw in FortiMail, the vendor’s email security gateway, is being exploited in the wild. It is tracked as CVE-2026-104286 and carries a CVSS score of 9.8, close to the ceiling.

The bug lives in the web management interface, specifically the component behind identity-based encryption. It combines a path traversal weakness with sloppy handling of null characters. An attacker with no account and no password can send a crafted HTTP or HTTPS request and write files anywhere on the underlying system. The vendor lists the impact as running unauthorized code or commands.

Four branches are affected: 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9. The repaired builds for the first three are described as upcoming, which means they do not exist yet. Customers on 7.2 are told to move to the 7.4 branch or later. There is no virtual patch either.

The vendor’s product security team found the flaw internally. It was already being used in attacks when they found it. Nobody has said who is behind the campaign, when it started, or how many appliances were taken.

The Impact

The published indicators tell a sharper story than the severity score does.

On compromised appliances, attackers added four files and modified three more. One addition was an ld.so.preload entry, which quietly forces a planted library into running processes. The attackers also rewrote the web server configuration.

Then came the part that should worry mail administrators most. The attackers created an archive account from the command line and pointed it at a server they controlled, writing to a directory called /uploads. A mail gateway reads every message the organization sends and receives. Turning its own archive function into an outbound feed is a clean way to steal mail without deploying anything that looks like malware.

Two factors make this worse than a normal critical bug. The appliance is built to face the internet, so exposure is the default, not a misconfiguration. And because it was attacked before anyone knew the flaw existed, applying the workaround today says nothing about what happened last week.

CVE-2026-104286 · FG-IR-26-175

FortiMail indicators of compromise

Published by the vendor on October 1, 2026. Check every FortiMail appliance against this list before you change anything, because applying the workaround does not tell you whether someone already got in.

Files added or modified7 artifacts
Added/data/lib/liblog.so
MD5 64c90a00c7fda4d5c7973ed64c25783a SHA256 8015f34dc84922b03688399d7f9fe7a00361789f7e420c7e2a2cdb23e75cef84
Added/data/bin/webconsole
MD5 ae0ea6502d3fa5f0664bceb73189eb54 SHA256 7a6cea9f5c9e2e9994d4e3c4da73f86cf5acd05ea5d312c066c9d1dafd69ee38
Added/data/bin/mailservice
MD5 f90fa81a5f521d785f2b2f765e3ab897 SHA256 4000276a150a165d3c2537d1e19fb393c4de8333076a16655e28059cae82157b
Added/data/etc/ld.so.preload
MD5 8eb64f25d2a8e18e05aae058629473cf SHA256 8953ec7960b09f544a880b072ad4e6cfda7a8303f486251d3478dcfdfbac23b6
Modified/bin/smit
MD5 5241738a3e9988404239e12243f6d35b SHA256 77324ac428bde86d351fc5fc06f6d64a6bfe737dfb2743df1d4c5ac2418a5b6a
Modified/data/etc/httpd.conf
MD5 61af1c4bce1c2eebc8ff689ca5337791 SHA256 703e97c64e61e41dc3aaba580d82bb2aa7b6a11b54ee6fb467ed5d5a3bffdef5
Modified/data/migadmin.tar.gz
MD5 49a7156a7d043cc8f9f680579db22f86 SHA256 d6fe51c22b91776f4c961ea58bcac5917f15d560a619d7ce726d3d51795609d3
Network indicators2 addresses
79[.]141.169.187
Also appears as the remote destination for the rogue mail archive account.
45[.]129.0.192
Listed in the advisory with no further context. Search firewall, proxy and NetFlow records.
Log entries to hunt4 patterns
type=kevent subtype=config user=admin ui=cli msg=”Added ‘archive234’ to ‘archive account’ … remote-ip[79.141.169.187] remote-username[archive234] remote-directory[/uploads]”
A mail archive account pointed at attacker infrastructure. The clearest single sign of compromise.
type=event subtype=system pri=debug user=system ui=cron msg=”(root) CMD (/bin/sh -c ‘O=/migadmin …
A scheduled task running as root out of the migration admin path.
FortiMail::IBE::DecrypterMediaIn … Caught BufferException(2), BufferImpl.cpp:973, ‘Invalid Base64 Encoding at pos 0. Character=0x2a’
Hex 0x2a is an asterisk. These decode errors line up with the malformed requests that trigger the bug.
type=kevent subtype=admin action=logout status=success reason=unknown msg=”User admin logged out from (null).”
Admin session activity with a null source. Weak on its own, useful next to the others.
Read these together, not alone. A single hit is not proof, and a clean sweep is not an all clear. Attackers rotate tooling, logs roll over, and the published list only covers what the vendor has seen so far. Any confirmed match is an incident response, not a patch job.

Source: vendor PSIRT advisory FG-IR-26-175, published October 1, 2026.

How to Avoid This

  • Disable identity-based encryption with the three-line CLI command, or pull the management interface off the public internet and limit it to a trusted private network. Either one closes the door today.
  • Treat every appliance between 7.2.0 and 8.0.1 as vulnerable until the vendor says otherwise.
  • Hunt before you change anything. Preserve logs, configuration backups, and forensic images first, because a reboot or an upgrade can erase the evidence you need.
  • Check your archive accounts and remote destinations by hand. An account nobody remembers creating is the loudest signal in the whole advisory.
  • Then make the rule permanent. Management interfaces on security appliances don’t belong on the public internet, and that decision shouldn’t wait for the next advisory.