Close Menu
NCIJ Network NCIJ Network
    What's Hot

    How Mike Morath’s Agency Linked Texas Schools to Alpha’s AI Tool — ProPublica

    October 2, 2026

    Disinformation is just one symptom of the authorities’ failure to regulate social media | Social media

    October 2, 2026

    Saudi-led coalition accuses Houthis of striking Medina power station

    October 2, 2026
    Facebook X (Twitter) Instagram
    Trending
    • How Mike Morath’s Agency Linked Texas Schools to Alpha’s AI Tool — ProPublica
    • Disinformation is just one symptom of the authorities’ failure to regulate social media | Social media
    • Saudi-led coalition accuses Houthis of striking Medina power station
    • Burnham wants to change British elections. Voters think they’re fine as is. – POLITICO
    • Whatever AI Safety Is, It’s Not This
    • A Coding Guide to Google Research’s Kauldron: Configs That Are Plain Data, Components Wired by String, and a JAX Trainer You Can Read End to End
    • Hacker Conversations: Rob Juncker, a Knock at the Door and a Moral Compass
    • Frank Holmes: They Will Print $100 Trillion
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, October 2
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Fortinet warns of critical FortiMail flaw exploited in zero-day attacks

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 2, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices.

    The vulnerability is rated critical, with a CVSS score of 9.8, and affects the FortiMail management interface.

    “An Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) [CWE-22] and Improper Neutralization of NULL Byte or NULL Character [CWE-158] vulnerability may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests,” Fortinet said in an advisory published Thursday.

    Gwendal Guégniaud of Fortinet’s Product Security team discovered the vulnerability internally, and it affects FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, and FortiMail 7.2.0 through 7.2.9.

    Fortinet says the flaw is being actively exploited and is urging customers to apply the shared workarounds until a security update can be installed.

    FortiMail 7.2 users can patch the vulnerability by upgrading to the 7.4 branch or later. For affected FortiMail 7.4, 7.6, and 8.0 installations, security updates are not yet available, with Fortinet listing FortiMail 7.4.9, 7.6.7, and 8.0.2 as upcoming versions containing the fix.

    Until patched versions are available, Fortinet says admins can mitigate the flaw by disabling IBE feature support using the following commands:

    
    config system encryption ibe
    set status disable
    end

    As an alternative workaround, administrators can disable access to the FortiMail management interface from the Internet or restrict access to trusted private networks.

    Fortinet also published indicators of compromise (IOCs) associated with the attacks, including several files that were added or modified on compromised systems.









    File Status SHA-256
    /data/lib/liblog.so Added 8015f34dc84922b03688399d7f9fe7a00361789f7e420c7e2a2cdb23e75cef84
    /bin/smit Modified 77324ac428bde86d351fc5fc06f6d64a6bfe737dfb2743df1d4c5ac2418a5b6a
    /data/bin/webconsole Added 7a6cea9f5c9e2e9994d4e3c4da73f86cf5acd05ea5d312c066c9d1dafd69ee38
    /data/bin/mailservice Added 4000276a150a165d3c2537d1e19fb393c4de8333076a16655e28059cae82157b
    /data/etc/httpd.conf Modified 703e97c64e61e41dc3aaba580d82bb2aa7b6a11b54ee6fb467ed5d5a3bffdef5
    /data/etc/ld.so.preload Added 8953ec7960b09f544a880b072ad4e6cfda7a8303f486251d3478dcfdfbac23b6
    /data/migadmin.tar.gz Modified d6fe51c22b91776f4c961ea58bcac5917f15d560a619d7ce726d3d51795609d3

    Fortinet also listed 79[.]141.169.187 and 45[.]129.0.192 as IP addresses associated with the attacks.

    The advisory also includes log entries that administrators can use to identify potentially compromised appliances.

    One of those entries shows an archive account named archive234 being configured from the command line with 79.141.169.187 as the remote server and /uploads as the remote directory. This could indicate that the attacker configured the compromised FortiMail appliance to send archived data to a remote server.

    Other log entries include a cron job executing a command related to /migadmin, an administrator logout event, an IBE decryption error due to invalid Base64 encoding, and failed login attempts.

    Example log events shared by Fortinet are listed below:

    
    type=event subtype=system pri=debug user=system ui=cron msg="(root) CMD (/bin/sh -c 'O=/migadmin ...
    - type=kevent subtype=admin pri=information user=admin ui=(null) action=logout status=success reason=unknown msg="User admin logged out from (null)."
    - type=kevent subtype=config pri=information user=admin ui=cli module=unknown submodule=unknown msg="Added 'archive234' to 'archive account' : rotation-size[50]rotation-time[1] rotation-hour[14]destination[remote]remote-ip[79.141.169.187]remote-username[archive234]remote-password[***]remote-directory[/uploads] (user: admin, from: cli)"
    - FortiMail::IBE::DecrypterMediaIn::DecrypterMediaIn(FortiMail::MediaIn&, const FortiMail::IBE::KeyFinder&, const FortiMail::EmailAddress&, const FortiMail::Buffer&, FortiMail::IBE::DecrypterMediaIn::Version): Caught BufferException(2), BufferImpl.cpp:973, 'Invalid Base64 Encoding at pos 0. Character=0x2a'
    - Internal user *@domain.tld failed to log in.

    Fortinet has not disclosed when the flaw was first exploited, how many systems were compromised, or who is behind the attacks.

    When BleepingComputer asked for more information about the exploitation activity, Fortinet referred customers to the advisory and said it is coordinating with government agencies, including CISA.

    “Fortinet published an advisory to provide guidance regarding CVE-2026-104286 (FG-IR-26-175), including workarounds to help customers mitigate risk,” Fortinet told BleepingComputer.

    “Consistent with Fortinet’s commitment to responsible PSIRT disclosure and public-private partnerships, we are communicating with relevant government organizations, including CISA, on the content of this advisory.”

    CISA has now added the CVE-2026-104286 flaw to the Known Exploited Vulnerability catalog and requires federal agencies to perform forensic triage and mitigate the flaw by October 4th.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    attacks critical Exploited Flaw FortiMail Fortinet warns ZeroDay
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Hacker Conversations: Rob Juncker, a Knock at the Door and a Moral Compass

    Coroner warns of risk of future deaths at mental health unit where patient was killed

    Alleged KillSec Ransomware Mastermind a 16-Year-Old

    China Warns Foreign Spies About Crypto, Singapore Dominates Asia: Asia Express

    ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories

    Putin warns West that Russia is ready to use every weapon to protect Kaliningrad

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    How Mike Morath’s Agency Linked Texas Schools to Alpha’s AI Tool — ProPublica

    October 2, 2026

    Disinformation is just one symptom of the authorities’ failure to regulate social media | Social media

    October 2, 2026

    Saudi-led coalition accuses Houthis of striking Medina power station

    October 2, 2026

    Burnham wants to change British elections. Voters think they’re fine as is. – POLITICO

    October 2, 2026
    Latest Posts

    Max Miller Continues to Resist Pressure to Drop Out as Deadline Looms

    August 7, 2026

    Houthi attacks kill at least 10 in Yemen as rebels target oil-rich Marib

    August 8, 2026

    Scientists find unexpected life on Ötzi the Iceman’s 5,300-year-old body

    August 8, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    How Mike Morath’s Agency Linked Texas Schools to Alpha’s AI Tool — ProPublica

    October 2, 2026

    Disinformation is just one symptom of the authorities’ failure to regulate social media | Social media

    October 2, 2026

    Saudi-led coalition accuses Houthis of striking Medina power station

    October 2, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.