Active Exploitation Alert: Critical Fortinet FortiMail Zero-Day (CVE-2026-104286) Enables Unauthenticated Arbitrary File Writes

Active Exploitation Alert: Critical Fortinet FortiMail Zero-Day (CVE-2026-104286) Enables Unauthenticated Arbitrary File Writes

Executive Summary

A critical zero-day vulnerability, tracked as CVE-2026-104286, has been discovered in Fortinet FortiMail appliances, enabling unauthenticated attackers to perform arbitrary file writes on the underlying system. This flaw, which carries a CVSS score of 9.8, is being actively exploited in the wild and poses a severe risk of remote code execution, privilege escalation, and full system compromise. The vulnerability is rooted in improper input validation, specifically a path traversal combined with improper neutralization of null bytes, allowing attackers to bypass directory restrictions and write files anywhere on the system. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, highlighting the urgent need for immediate mitigation. Organizations running vulnerable versions of FortiMail are strongly advised to patch or apply workarounds without delay.

Threat Actor Profile

While no specific advanced persistent threat (APT) group has been publicly attributed to the exploitation of CVE-2026-104286 as of this report, the tactics, techniques, and procedures (TTPs) observed align with both financially motivated cybercriminals and state-sponsored actors. The exploitation pattern—targeting internet-exposed management interfaces, leveraging unauthenticated access, and establishing persistence through file writes—mirrors those used in previous campaigns by groups such as FIN7, APT41, and other actors known for targeting enterprise infrastructure. The rapid weaponization of this vulnerability and the sophistication of post-exploitation activities suggest that both opportunistic and targeted attacks are underway. Threat actors are leveraging automated scanning tools to identify vulnerable FortiMail instances and are deploying custom malware and webshells to maintain long-term access.

Technical Analysis of Malware/TTPs

The core of CVE-2026-104286 lies in a path traversal vulnerability (CWE-22) combined with improper neutralization of null bytes (CWE-158) in the FortiMail web interface. Attackers exploit this flaw by crafting HTTP or HTTPS requests that manipulate file paths, allowing them to escape the intended directory structure and write arbitrary files to sensitive locations on the appliance. This is achieved by injecting sequences such as ../ (dot-dot-slash) and null bytes into request parameters, which the backend fails to properly sanitize.

Once arbitrary file write is achieved, attackers typically upload malicious binaries, webshells, or modify configuration files to escalate privileges and establish persistence. Observed malware includes custom shared objects (e.g., liblog.so), backdoored binaries (e.g., webconsole, mailservice), and modifications to critical system files such as ld.so.preload and httpd.conf. These modifications allow attackers to hijack legitimate processes, intercept credentials, and execute arbitrary commands with elevated privileges.

The exploitation chain often involves the following MITRE ATT&CK techniques: T1190 (Exploit Public-Facing Application) for initial access, T1105 (Ingress Tool Transfer) for uploading malicious payloads, T1059 (Command and Scripting Interpreter) for executing arbitrary code, and T1546 (Event Triggered Execution) for persistence via modified system files.

Exploitation in the Wild

Active exploitation of CVE-2026-104286 has been confirmed by multiple security vendors and government agencies. Attackers are scanning the internet for exposed FortiMail management interfaces and delivering crafted HTTP/HTTPS requests to vulnerable endpoints. Successful exploitation results in the creation or modification of files such as /data/lib/liblog.so, /data/bin/webconsole, /data/bin/mailservice, /data/etc/ld.so.preload, /bin/smit, /data/etc/httpd.conf, and /data/migadmin.tar.gz.

Malicious activity includes the deployment of webshells for remote command execution, installation of backdoors for persistent access, and alteration of system binaries to evade detection. Forensic analysis has identified connections from suspicious IP addresses, notably 79.141.169[.]187 and 45.129.0[.]192, which have been associated with scanning and exploitation attempts.

Organizations have reported incidents where attackers leveraged the vulnerability to gain root-level access, exfiltrate sensitive data, and pivot to other internal systems. The lack of authentication required for exploitation significantly increases the attack surface, making any internet-exposed FortiMail instance a high-value target.

Victimology and Targeting

Victims of CVE-2026-104286 exploitation span a wide range of sectors, including government agencies, financial institutions, healthcare providers, and large enterprises. The common denominator among victims is the exposure of FortiMail management interfaces to the public internet, either intentionally for remote administration or inadvertently due to misconfiguration.

Attackers are indiscriminate in their initial scanning, but post-exploitation activities suggest a focus on organizations with high-value data or critical infrastructure. The rapid inclusion of this vulnerability in ransomware operators' toolkits and the observed lateral movement within compromised networks indicate that both data theft and disruptive attacks are possible outcomes.

Geographically, incidents have been reported in North America, Europe, and Asia-Pacific, with a concentration in regions where FortiMail appliances are widely deployed. The exploitation does not require prior knowledge of the target environment, making it attractive for both targeted and opportunistic campaigns.

Mitigation and Countermeasures

Immediate mitigation is essential to prevent compromise. Organizations should upgrade FortiMail appliances to the latest fixed versions as specified by Fortinet: 8.0.2 or above for the 8.0 branch, 7.6.7 or above for the 7.6 branch, 7.4.9 or above for the 7.4 branch, and migration to the 7.4 branch for 7.2.x deployments.

If immediate patching is not feasible, a critical workaround is to disable the IBE (Identity-Based Encryption) feature using the following commands in the system configuration:

config system encryption ibe
set status disable
end

Additionally, restrict access to the FortiMail management interface by implementing network segmentation and firewall rules to allow only trusted internal networks. Exposing management interfaces to the internet should be avoided under all circumstances.

Detection strategies include monitoring for connections from known malicious IP addresses, auditing for the presence or modification of suspicious files listed above, and reviewing HTTP/HTTPS logs for anomalous requests targeting the management interface. Organizations should also conduct a thorough forensic review of potentially compromised systems, focusing on unauthorized file changes and new or modified binaries.

Incident response plans should be updated to include procedures for isolating affected appliances, eradicating malicious artifacts, and restoring systems from known-good backups. Regular vulnerability scanning and penetration testing are recommended to identify and remediate similar exposures proactively.

References

About Rescana

Rescana is a leader in third-party risk management (TPRM), providing organizations with a comprehensive platform to continuously monitor, assess, and mitigate cyber risks across their supply chain and digital ecosystem. Our advanced threat intelligence and automation capabilities empower security teams to proactively identify vulnerabilities, prioritize remediation, and ensure compliance with industry standards. For more information about how Rescana can help strengthen your organization's cyber resilience, please contact us at info@rescana.com.

Contact us / Book a demo

Talk to Rescana about this advisory, or book a demo of the platform.