Critical FortiMail Flaw Exploited in Zero-Day Attacks, Warning Issued for Affected Users
Cybersecurity firm Fortinet has issued a warning to its customers about a critical vulnerability affecting their popular email security solution, FortiMail. The flaw, tracked as CVE-2026-104286, is being actively exploited by attackers to execute unauthorized code or commands on vulnerable devices, making it an urgent matter for affected users.
The vulnerability, rated critical with a CVSS score of 9.8, resides in the FortiMail management interface and can be exploited through crafted HTTP or HTTPS requests. This allows unauthenticated attackers to write arbitrary files on the underlying system, potentially leading to data breaches or system compromise. The flaw affects multiple versions of FortiMail, including 7.2, 7.4, 7.6, and 8.0.
Fortinet’s Product Security team discovered the vulnerability internally, and it is currently being actively exploited by attackers. To mitigate this risk, Fortinet has published shared workarounds that can be applied until a security update becomes available. These workarounds include disabling IBE feature support using specific commands or restricting access to the FortiMail management interface.
Admins of affected FortiMail installations should take immediate action to protect their systems. The most straightforward solution is to upgrade to patched versions, with Fortinet listing 7.4.9, 7.6.7, and 8.0.2 as upcoming versions containing the fix. In the meantime, admins can disable IBE feature support using the following commands: `config system encryption ibe` followed by `set status disable` and `end`.
Fortinet has also published indicators of compromise (IOCs) associated with the attacks, including several files that were added or modified on compromised systems. These IOCs include IP addresses 79[.]141.169.187 and 45[.]129.0.192, as well as specific log entries that can be used to identify potentially compromised appliances.
To help admins detect potential compromise, Fortinet has shared example log events related to the attacks. These events include an archive account being configured with a remote server and directory, a cron job executing a command related to `/migadmin`, administrator logout events, IBE decryption errors due to invalid Base64 encoding, and failed login attempts.
FortiMail admins should closely review these IOCs and log entries to identify potential compromise. If you suspect your FortiMail appliance has been compromised, please follow Fortinet’s published guidance for mitigation and remediation.
In conclusion, the critical FortiMail vulnerability is a pressing concern that requires immediate attention from affected users. By taking swift action to apply workarounds or upgrade to patched versions, admins can protect their systems from potential data breaches or system compromise.
Source: Bleeping Computer — 2026-10-01