Fortinet is warning of a critical FortiMail flaw, CVE-2026-104286, actively exploited in zero-day attacks to run unauthorised code or commands. CVSS 9.8. The issue combines path traversal (CWE-22) and improper NULL-byte neutralization (CWE-158) in the management interface: an unauthenticated attacker can write arbitrary files on the underlying system via crafted HTTP/HTTPS requests. Discovery is credited to Gwendal Guégniaud on Fortinet's Product Security team.
Affected versions: FortiMail 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8 and 7.2.0–7.2.9. For 7.2, upgrade to the 7.4 branch or later. For 7.4/7.6/8.0, patches are not yet available — Fortinet lists upcoming 7.4.9, 7.6.7 and 8.0.2. Until then: disable IBE (`config system encryption ibe` / `set status disable`) or remove/restrict internet access to the management interface.
Fortinet published IOCs: added/modified files including `/data/lib/liblog.so`, `/bin/smit`, `/data/bin/webconsole`, `/data/bin/mailservice`, `/data/etc/httpd.conf`, `/data/etc/ld.so.preload` with SHA-256 hashes, plus IPs `79.141.169.187` and `45.129.0.192`. Log patterns include archive account `archive234` to remote `/uploads`, cron against `/migadmin`, IBE Base64 errors and failed logins. CISA added the CVE to KEV and requires forensic triage plus mitigation by 4 October 2026.
Nordic organisations running FortiMail for secure email must prioritise this immediately: an email gateway with unauthenticated file write is initial access to both mail flow and the underlying OS. Inventory version, apply the workaround the same day, hunt IOCs and plan upgrades to forthcoming builds.
Concrete steps
1. Inventory every FortiMail; apply IBE-disable or lock down internet management now. 2. Hunt listed file hashes, ld.so.preload, archive234 and IOC IPs. 3. Preserve forensics before upgrading — CISA requires triage. 4. Upgrade 7.2→7.4+; follow 7.4.9/7.6.7/8.0.2 when they ship. 5. Rotate admin credentials after suspected compromise.
Evidence Rail
- Confirmed: Fortinet FG-IR-26-175; active exploitation; CISA KEV + 4 October deadline; IOC table.
- Reported: BleepingComputer; coordination with government agencies.
- Unconfirmed: Attribution, count of compromised systems, first exploit date.
Organisations in Sweden, Norway, Denmark and Finland that expose affected systems to the internet or rely on them in critical workflows should treat this disclosure as an operational priority. Map access, patch windows and accountable owners within 24 hours. Document compensating controls if immediate upgrade is impossible, and ensure SOC receives hunting guidance the same day. For leadership: tie the risk to business continuity, regulatory duties and insurance terms — not only to the IT ticket queue. Log remediation timestamps so due diligence can be shown later.
In Brief
- FortiMail management path traversal CVSS 9.8 under active zero-day.
- Workaround: disable IBE or restrict management until patch.
- CISA requires forensic triage by 4 October.
For Nordic organisations rapid inventory, documented patch status and clear escalation to leadership are essential — both for incident readiness and to show due diligence to regulators and insurers.
For Nordic organisations rapid inventory, documented patch status and clear escalation to leadership are essential — both for incident readiness and to show due diligence to regulators and insurers.
Organisations in Sweden, Norway, Denmark and Finland that expose affected systems to the internet or rely on them in critical workflows should treat this disclosure as an operational priority. Map access, patch windows and accountable owners within 24 hours. Document compensating controls if immediate upgrade is impossible, and ensure SOC receives hunting guidance the same day. For leadership: tie the risk to business continuity, regulatory duties and insurance terms — not only to the IT ticket queue. Log remediation timestamps so due diligence can be shown later.