Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
Fortinet disclosed a critical zero-day vulnerability in the FortiMail email gateway on October 1, 2026. CVE-2026-104286 carries a CVSS 9.8 rating and allows unauthenticated arbitrary file write. Patches are available only for the 7.2 branch, while three of four branches — 7.4, 7.6, and 8.0 — remain exposed with only manual workarounds. CISA has added the flaw to the KEV catalog with a deadline of October 4 for federal agencies.
- CVE-2026-104286 is a path traversal vulnerability with null-byte injection in FortiMail's IBE component, exploitable via HTTP/HTTPS without credentials.
- Fortinet confirms active zero-day exploitation; CISA added the flaw to the KEV catalog on October 1 with a BOD 26-04 deadline of October 4, 2026.
- Patches exist only for the 7.2 branch (upgrade to 7.4+); versions 7.4, 7.6, and 8.0 await future undated releases.
- Fortinet published 7 SHA-256 hashes and 2 IP addresses as indicators of compromise, along with logs showing the creation of a suspicious account pointing to a remote server.
The Flaw in the IBE Engine: Traversal and Null-Byte Against Management
The vulnerability resides in the IBE (Identity Based Encryption) component of the FortiMail management interface. According to the Fortinet advisory cited by BleepingComputer, the combination of CWE-22 (Path Traversal) and CWE-158 (Improper Neutralization of NULL Byte) allows a remote attacker to write arbitrary files via crafted HTTP or HTTPS requests, without authentication.
Arbitrary file write on an email gateway system exposes risks of service integrity compromise. The primary source does not detail post-exploitation escalation techniques. Potential impact includes alteration of system configuration or behavior.
"An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] and Improper Neutralization of NULL Byte or NULL Character [CWE-158] vulnerability may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests" — Fortinet advisory, reported by BleepingComputer
The Patch Gap: One Branch Covered, Three Without a Timeline
Fortinet has released patches exclusively for the 7.2 branch, versions 7.2.0-7.2.9, with instructions to upgrade to 7.4+. For versions 7.4.0-7.4.8, 7.6.0-7.6.6, and 8.0.0-8.0.1, no fix exists. The expected remedial versions are 7.4.9, 7.6.7, and 8.0.2, but Fortinet has not communicated release dates.
The attack surface is broad: four product branches with deployments distributed across enterprise and government infrastructures. The lack of a timeline for three-quarters of affected versions forces operators to rely on manual workarounds with operational impact.
The disclosure pattern documented by BleepingComputer shows coordination with government agencies in parallel with patch distribution. Fortinet told BleepingComputer: "Consistent with Fortinet's commitment to responsible PSIRT disclosure and public-private partnerships, we are communicating with relevant government organizations, including CISA, on the content of this advisory."
IOCs and Compromise Traces: 'archive234' Account and IPs Published by Fortinet
The Fortinet advisory includes 7 SHA-256 hashes of files added or modified on compromised systems, and 2 IP addresses: 79.141.169.187 and 45.129.0.192. Logs show the configuration of an account named 'archive234' pointing to the remote server 79.141.169.187.
These indicators allow organizations to verify whether their systems were targeted by observed exploitation. The source does not specify the completeness of the exploitation chain: whether arbitrary file write was in all cases followed by code execution, or whether some attacks stopped at reconnaissance phases. The brief indicates "potential code execution," not confirmed as a certain consequence in every instance.
The lack of attribution to specific threat actors limits the ability to profile the intent behind observed attacks. CISA classifies the exploitation status as active, without further contextualization on post-exploitation tactics.
What to Do Now
For organizations running FortiMail on affected versions, the source documents four actions.
Disable IBE: Execute the CLI commands documented in the Fortinet advisory to disable the Identity Based Encryption component. This action has functional impact on identity-based encryption flows and requires evaluation of operational dependencies.
Restrict Management Access: Restrict the management interface to trusted networks, removing Internet exposure. The source cites this alternative as a workaround where IBE disabling is not applicable due to service constraints.
Forensic Triage with IOCs: Check for the presence of the 7 published SHA-256 hashes and 2 IP addresses in network logs, with specific attention to the creation of the 'archive234' account and connections to 79.141.169.187.
Upgrade for Branch 7.2: For these deployments, the only available remediation is upgrading to version 7.4 or later. The source does not specify compatibility testing details or recommended maintenance windows.
CISA-Fortinet Coordination and the Federal Deadline
CISA added CVE-2026-104286 to the KEV catalog on October 1, 2026, with BOD 26-04 mandating forensic triage and mitigation by October 4 for federal agencies. The KEV dataset on GitHub confirms the addition date and operational deadline with the dueDate field set to 2026-10-04.
The binding operational directive applies exclusively to Federal Civilian Executive Branch agencies and does not extend direct obligations to the private sector. However, inclusion in the KEV catalog signals national priority and influences enterprise risk management practices.
The vulnerability discovery is attributed to Gwendal Guégniaud of the Fortinet Product Security team, with internal disclosure preceding coordinated publication with CISA. This responsible disclosure path did not eliminate the exposure window for unpatched versions.
Editorial Close
The disclosure of CVE-2026-104286 exposes a recurring tension in the security supply chain: the speed of government coordination outpaces patch distribution. Fortinet has actively communicated with CISA, published detailed IOCs, and provided operational workarounds, but three-quarters of affected versions remain unpatched with an indefinite timeline.
For security teams, the priority is immediate exposure verification via published IOCs, followed by assessment of workaround applicability. The forced upgrade from branch 7.2 represents the only complete remediation path currently available, with other versions awaiting releases that Fortinet has not yet calendared.
Information verified against cited sources and current as of publication.
Sources
- https://www.bleepingcomputer.com/news/security/fortinet-warns-of-critical-fortimail-flaw-exploited-in-zero-day-attacks/
- https://www.cisa.gov/news-events/alerts/2026/10/01/cisa-adds-one-known-exploited-vulnerability-catalog
- https://github.com/cisagov/kev-data/commit/a25b61fbc5e3125030a15e09adba33f427cc0e25
- https://www.thehackerwire.com/vulnerability/CVE-2026-104286/
- https://securityonline.info/fortimail-vulnerability-cve-2026-104286/
- https://mallory.ai/stories/01a0f989-853e-766b-b032-563001a93da2
- https://www.bleepingcomputer.com/tutorials/
- https://www.bleepingcomputer.com/download/
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.