<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

Critical Fortinet FortiMail Zero-Day Under Active Attack

Fortinet alerts on critical zero-day vulnerability in FortiMail, urging immediate action to disable IBE support and check logs for suspicious IPs.
Content Team

Fortinet is warning customers about a critical zero-day in FortiMail that attackers are already exploiting. Tracked as CVE-2026-104286 with a CVSS score of 9.8 (Critical), the flaw lets unauthenticated attackers write arbitrary files to affected devices using crafted HTTP or HTTPS requests — no login required. Fortinet rates the impact as code execution.

CISA added the flaw to its Known Exploited Vulnerabilities catalog on October 1, the same day Fortinet published its advisory, and gave federal civilian agencies until October 4 to act. Four branches are affected: 8.0.0 to 8.0.1, 7.6.0 to 7.6.6, 7.4.0 to 7.4.8, and 7.2.0 to 7.2.9. None has a fixed build yet.

Fortinet lists 8.0.2, 7.6.7, and 7.4.9 as upcoming releases, and tells 7.2 users to move to branch 7.4 or later. Every 7.4 build shipped so far sits inside the affected range, so that route only helps once 7.4.9 arrives.

Until then, disable IBE support from the CLI, or cut the management interface off the internet. Then go hunting. Fortinet published hashes for seven added or modified files, including a planted ld.so.preload, two attacker IPs (79.141.169.187 and 45.129.0.192), and a log entry adding an archive account named archive234 that reports to the first. The IPs alone won't tell you whether a box is already compromised.

Source: Cybersecurity News

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo