Critical Fortinet FortiMail Zero-Day Under Active Attack
Want more insights like this?
Fortinet is warning customers about a critical zero-day in FortiMail that attackers are already exploiting. Tracked as CVE-2026-104286 with a CVSS score of 9.8 (Critical), the flaw lets unauthenticated attackers write arbitrary files to affected devices using crafted HTTP or HTTPS requests — no login required. Fortinet rates the impact as code execution.
CISA added the flaw to its Known Exploited Vulnerabilities catalog on October 1, the same day Fortinet published its advisory, and gave federal civilian agencies until October 4 to act. Four branches are affected: 8.0.0 to 8.0.1, 7.6.0 to 7.6.6, 7.4.0 to 7.4.8, and 7.2.0 to 7.2.9. None has a fixed build yet.
Fortinet lists 8.0.2, 7.6.7, and 7.4.9 as upcoming releases, and tells 7.2 users to move to branch 7.4 or later. Every 7.4 build shipped so far sits inside the affected range, so that route only helps once 7.4.9 arrives.
Until then, disable IBE support from the CLI, or cut the management interface off the internet. Then go hunting. Fortinet published hashes for seven added or modified files, including a planted ld.so.preload, two attacker IPs (79.141.169.187 and 45.129.0.192), and a log entry adding an archive account named archive234 that reports to the first. The IPs alone won't tell you whether a box is already compromised.
Source: Cybersecurity News