Particle.news

Critical FortiMail Zero-Day Lets Attackers Write Files and Run Code

CISA has ordered federal agencies to mitigate the flaw by October 4 to force rapid triage of affected systems.

Overview

  • Fortinet confirmed on Oct. 1–2 that CVE-2026-104286 is being actively exploited in the wild and urged customers to follow its advisory.
  • The flaw is a path‑traversal plus NULL‑byte handling bug in the FortiMail management interface that can let an unauthenticated attacker write arbitrary files and enable command or code execution.
  • Fortinet published indicators of compromise including file hashes, added or modified system files, two attacker IP addresses, and example log entries to help detection and hunting.
  • Full security updates are listed but not yet released for several FortiMail branches, so Fortinet recommends disabling IBE and blocking internet access to management interfaces as temporary workarounds.
  • CISA added the CVE to its Known Exploited Vulnerabilities catalog and ordered federal mitigation and forensic triage by October 4, and organizations are advised to inventory FortiMail instances, rotate credentials, and perform forensic checks because patches alone may not remove active backdoors.