<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>FortiMail (8.0.0-8.0.1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/fortimail-8.0.0-8.0.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 02 Oct 2026 06:25:40 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/fortimail-8.0.0-8.0.1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Critical FortiMail Zero-Day Exploited for Arbitrary File Write</title><link>https://feed.craftedsignal.io/briefs/2026-10-fortimail-zero-day/</link><pubDate>Fri, 02 Oct 2026 06:25:40 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-fortimail-zero-day/</guid><description>Unauthenticated attackers are actively exploiting a path traversal and NULL byte injection vulnerability (CVE-2026-104286) in FortiMail to write arbitrary files and establish persistence.</description><content:encoded><![CDATA[<p>Fortinet has confirmed active, in-the-wild exploitation of a critical vulnerability (CVE-2026-104286, CVSS 9.8) impacting multiple versions of FortiMail. The flaw arises from an improper limitation of a pathname to a restricted directory combined with improper neutralization of NULL bytes, enabling unauthenticated remote attackers to perform arbitrary file writes via crafted HTTP or HTTPS requests. Threat actors are leveraging this capability to modify existing system files and inject new binaries to establish persistent unauthorized access. CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, mandating that FCEB agencies apply patches or workarounds by October 4, 2026. Defenders must prioritize patching vulnerable versions or implementing the recommended CLI-based workarounds.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker sends a crafted HTTP/HTTPS request targeting the FortiMail appliance.</li>
<li>The request utilizes path traversal sequences combined with NULL byte injection to bypass file system restrictions.</li>
<li>The FortiMail application incorrectly processes the request, allowing the attacker to write files outside of intended directories.</li>
<li>Attacker overwrites or modifies critical system binaries, such as /bin/smit or /data/bin/webconsole.</li>
<li>Attacker deploys malicious shared objects, such as /data/lib/liblog.so or /data/etc/ld.so.preload, to achieve arbitrary code execution.</li>
<li>Attacker modifies configuration files, including /data/etc/httpd.conf, to maintain persistent access or redirect management traffic.</li>
<li>Final objective achieved: establishment of a backdoor or persistence mechanism on the compromised appliance.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated remote attackers to gain unauthorized access to the underlying operating system of the FortiMail appliance. This can lead to full system compromise, exfiltration of sensitive email data, and the use of the appliance as a pivot point into the internal network. Active exploitation has been reported, necessitating immediate attention across all enterprise environments utilizing the affected FortiMail versions.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade FortiMail appliances to the vendor-specified fixed versions immediately (8.0.2, 7.6.7, 7.4.9, or branch 7.4+).</li>
<li>Implement the temporary CLI workaround: disable the IBE feature using 'config system encryption ibe' -&gt; 'set status disable' -&gt; 'end'.</li>
<li>Restrict access to the FortiMail management interface to trusted private networks only, blocking internet-facing management access.</li>
<li>Hunt for indicators of compromise, specifically looking for unauthorized modifications to /data/bin/webconsole, /data/etc/ld.so.preload, and /bin/smit.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">threat</category><category>vulnerability</category><category>remote-code-execution</category><category>persistence</category><category>network-security</category></item></channel></rss>