Yaamlabs
Vulnerabilities

FortiMail zero-day: disable IBE now, fixes still pending

CVE-2026-104286 lets unauthenticated attackers write files on FortiMail. Affected versions, the IBE workaround, Fortinet's IOCs and the CISA deadline.

By Yaali. October 2, 2026, 5 min read, Vulnerabilities, Patching, Threat intel.

Cover illustration of an email gateway appliance with envelopes flowing into it and a stray file slipping through its casing, with the Yaamlabs logo and the text: FortiMail flaw lets attackers plant files without a login, 9.8, CVSS, exploited before any fix shipped

Fortinet disclosed CVE-2026-104286 on October 1, a critical flaw in FortiMail, its secure email gateway, rated CVSS 9.8. An attacker with no account can send crafted HTTP or HTTPS requests to the appliance and write arbitrary files to its underlying operating system. Fortinet says the flaw is being exploited, and CISA added it to the Known Exploited Vulnerabilities (KEV) catalog the same day.

Affected releases are FortiMail 8.0.0 to 8.0.1, 7.6.0 to 7.6.6, 7.4.0 to 7.4.8 and 7.2.0 to 7.2.9. The fixed builds, 8.0.2, 7.6.7 and 7.4.9, were still listed as "upcoming" in Fortinet's advisory when it was published, so for most owners the only protection today is a configuration change. US federal agencies have until October 4 to mitigate and carry out forensic triage.

Attack path for CVE-2026-104286: an unauthenticated request with a traversal path and a NULL byte reaches the FortiMail web interface, writes files outside the web directory, and Fortinet's indicators show a preloaded library, new binaries, a modified httpd.conf and an archive account sending mail to 79.141.169.187

How it works

Fortinet's advisory classes the bug as two weaknesses together. CWE-22 is path traversal: the web service builds a file path from part of a request and fails to stop sequences such as ../ from climbing out of the directory it is meant to stay in. CWE-158 is improper handling of a NULL byte, the zero character that C code treats as the end of a string. Putting a NULL byte in a file name is an old way to make a check see one name (ending in an allowed extension, for example) while the lower-level file call writes another. Combined, they let a request choose where on disk its content lands.

Fortinet places the flaw in the GUI component, the web server that serves the management interface. Its workaround is to switch off Identity Based Encryption (IBE). IBE lets FortiMail send encrypted mail to outside recipients who have no certificate or special software. In "pull" mode the message stays on the FortiMail unit, and the recipient follows a link to a portal on the appliance to register and read it. Fortinet has not said which request handler is vulnerable or whether units that never enabled IBE are exposed, so treat every appliance on an affected version as vulnerable.

An arbitrary file write on an appliance is close to code execution. Fortinet's indicators show what attackers did with it: they added /data/etc/ld.so.preload and /data/lib/liblog.so. On Linux, ld.so.preload lists libraries the dynamic linker loads into every program that starts, so a library named there runs inside every new process on the system. They also modified /bin/smit, added two binaries and changed the web server's httpd.conf.

What attackers are doing

Fortinet confirms exploitation in the wild but has not named an actor, said when attacks began or given a number of victims. CISA's KEV entry marks known ransomware use as unknown.

The indicators Fortinet published describe more than a foothold. Among them is an email archive account named archive234, configured from the command line with 79.141.169.187 as the remote server and /uploads as the remote directory. FortiMail archive accounts can copy mail to an external server, so as BleepingComputer notes, this suggests the attackers set compromised appliances to ship archived email out. For a mail gateway that is the worst case: everything passing through the box for the organisation's protected domains could have been copied. Fortinet lists a second address, 45.129.0.192, alongside the first.

What to do

Fixed and pending FortiMail releases per branch, then four steps: disable IBE today, close the management interface to the internet, check for Fortinet's indicators of compromise, and rebuild and rotate secrets if any are found

1. Disable IBE today

From the FortiMail CLI, run:

config system encryption ibe
    set status disable
end

The same setting is under Encryption > IBE > IBE Encryption in the web console. Recipients of encrypted mail will not be able to reach the IBE portal while it is off, so tell whoever owns encrypted mail to outside parties before you change it.

2. Take the management interface off the internet

Fortinet's other workaround is to block internet access to the management interface or limit it to trusted private networks. On the upstream firewall, allow HTTPS to the FortiMail admin address only from your admin jump hosts. Keep SMTP (TCP 25) open as normal, because that is not the interface Fortinet names. Doing both steps is better than relying on one.

3. Upgrade when the builds ship

Move to 8.0.2, 7.6.7 or 7.4.9 as soon as Fortinet releases them, and watch advisory FG-IR-26-175 for the release. FortiMail 7.2 gets no fix: Fortinet tells 7.2 owners to migrate to the 7.4 branch or later. If you do that migration now, the 7.4 release you land on (7.4.0 to 7.4.8) is still vulnerable, so keep IBE disabled until 7.4.9 is installed.

4. Check for Fortinet's indicators

Fortinet lists these files as added or modified by attackers:

  • Added: /data/lib/liblog.so, /data/bin/webconsole, /data/bin/mailservice, /data/etc/ld.so.preload
  • Modified: /bin/smit, /data/etc/httpd.conf, /data/migadmin.tar.gz

Fortinet does not say how to inspect these paths from the FortiMail CLI; if you cannot check them yourself, open a case with Fortinet's Technical Assistance Center (TAC). Two checks need no special access. Review the archive account configuration and the event log for any archive account you did not create, archive234 in particular, and any remote archive server you do not recognise. Then search firewall and proxy logs for traffic between your FortiMail units and 79.141.169.187 or 45.129.0.192, in either direction. Because the attackers could write to the appliance, records kept outside it are the more reliable ones.

5. If you find a match

Treat the appliance as fully compromised. Isolate it, collect logs for investigation, then rebuild it from a clean image on a fixed release and restore a configuration you have checked by hand rather than the running one. Assume mail that passed through it was read. Rotate the admin passwords, the keys and certificates the unit holds (TLS certificates and DomainKeys Identified Mail (DKIM) signing keys), and the credentials it uses for LDAP and other connected services.

The wider lesson

Email gateways sit at the edge, process every message for the organisation and are often run by a messaging team on a slower patch cycle than the firewall. This one was exploited before Fortinet had a fixed build ready for any branch. For edge appliances like this, the management interface and optional portals such as IBE should face only the networks that need them from the day they are installed, so that a zero-day in the web interface starts out with a small audience.

Our attack surface management work finds management interfaces and portals like these that face the internet, and our security operations team can run the indicator checks and log review with you. Open the chat and Yaali, our AI agent, will pass your question to an engineer.


Sources: Fortinet PSIRT advisory FG-IR-26-175, CISA KEV catalog, BleepingComputer, runZero, Cybersecurity News, Suped, Rapid7, Fortinet IBE configuration guide, Fortinet CLI reference: system encryption ibe.

Read next

Back to the blog, or tell us about your system in the chat. Yaali, our AI agent, answers first and brings in an engineer.