{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/fortimail-7.4.0-7.4.8/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:fortinet:fortimail:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-104286"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["FortiMail (8.0.0-8.0.1)","FortiMail (7.6.0-7.6.6)","FortiMail (7.4.0-7.4.8)","FortiMail (7.2.0-7.2.9)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","remote-code-execution","persistence","network-security"],"_cs_type":"threat","_cs_vendors":["Fortinet"],"content_html":"\u003cp\u003eFortinet has confirmed active, in-the-wild exploitation of a critical vulnerability (CVE-2026-104286, CVSS 9.8) impacting multiple versions of FortiMail. The flaw arises from an improper limitation of a pathname to a restricted directory combined with improper neutralization of NULL bytes, enabling unauthenticated remote attackers to perform arbitrary file writes via crafted HTTP or HTTPS requests. Threat actors are leveraging this capability to modify existing system files and inject new binaries to establish persistent unauthorized access. CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, mandating that FCEB agencies apply patches or workarounds by October 4, 2026. Defenders must prioritize patching vulnerable versions or implementing the recommended CLI-based workarounds.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker sends a crafted HTTP/HTTPS request targeting the FortiMail appliance.\u003c/li\u003e\n\u003cli\u003eThe request utilizes path traversal sequences combined with NULL byte injection to bypass file system restrictions.\u003c/li\u003e\n\u003cli\u003eThe FortiMail application incorrectly processes the request, allowing the attacker to write files outside of intended directories.\u003c/li\u003e\n\u003cli\u003eAttacker overwrites or modifies critical system binaries, such as /bin/smit or /data/bin/webconsole.\u003c/li\u003e\n\u003cli\u003eAttacker deploys malicious shared objects, such as /data/lib/liblog.so or /data/etc/ld.so.preload, to achieve arbitrary code execution.\u003c/li\u003e\n\u003cli\u003eAttacker modifies configuration files, including /data/etc/httpd.conf, to maintain persistent access or redirect management traffic.\u003c/li\u003e\n\u003cli\u003eFinal objective achieved: establishment of a backdoor or persistence mechanism on the compromised appliance.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated remote attackers to gain unauthorized access to the underlying operating system of the FortiMail appliance. This can lead to full system compromise, exfiltration of sensitive email data, and the use of the appliance as a pivot point into the internal network. Active exploitation has been reported, necessitating immediate attention across all enterprise environments utilizing the affected FortiMail versions.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade FortiMail appliances to the vendor-specified fixed versions immediately (8.0.2, 7.6.7, 7.4.9, or branch 7.4+).\u003c/li\u003e\n\u003cli\u003eImplement the temporary CLI workaround: disable the IBE feature using 'config system encryption ibe' -\u0026gt; 'set status disable' -\u0026gt; 'end'.\u003c/li\u003e\n\u003cli\u003eRestrict access to the FortiMail management interface to trusted private networks only, blocking internet-facing management access.\u003c/li\u003e\n\u003cli\u003eHunt for indicators of compromise, specifically looking for unauthorized modifications to /data/bin/webconsole, /data/etc/ld.so.preload, and /bin/smit.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-02T06:25:40Z","date_published":"2026-10-02T06:25:40Z","id":"https://feed.craftedsignal.io/briefs/2026-10-fortimail-zero-day/","summary":"Unauthenticated attackers are actively exploiting a path traversal and NULL byte injection vulnerability (CVE-2026-104286) in FortiMail to write arbitrary files and establish persistence.","title":"Critical FortiMail Zero-Day Exploited for Arbitrary File Write","url":"https://feed.craftedsignal.io/briefs/2026-10-fortimail-zero-day/"}],"language":"en","title":"CraftedSignal Threat Feed - FortiMail (7.4.0-7.4.8)","version":"https://jsonfeed.org/version/1.1"}