Fortinet warns that attackers are actively exploiting a critical vulnerability in the FortiMail management interface. Tracked as CVE-2026-104286, the flaw has a CVSS score of 9.8 and could let an unauthenticated attacker write arbitrary files on an affected system through crafted HTTP or HTTPS requests.
Fortinet describes the issue as involving path traversal and improper handling of a NULL byte or character. The company says it can allow attackers to execute unauthorized code or commands. Gwendal Guégniaud of Fortinet’s Product Security team discovered the vulnerability internally.
Affected versions are FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9. Fortinet says fixes are planned for versions 7.4.9, 7.6.7, and 8.0.2, but those updates are not yet available. It says users of 7.2 can address the flaw by upgrading to the 7.4 branch or later.
Until updates are available, Fortinet advises disabling IBE feature support or limiting access to the management interface to trusted private networks. Its advisory lists 79[.]141.169.187 and 45[.]129.0.192 as addresses associated with the attacks, along with files and log entries that may help identify compromised appliances. One example describes an archive account, archive234, configured to send data to 79.141.169.187.
Fortinet has not said when exploitation began, how many systems were compromised, or who is responsible. The company told BleepingComputer it is coordinating with government organizations, including CISA. CISA added the flaw to its Known Exploited Vulnerability catalog and set an October 4 deadline for federal agencies to conduct forensic triage and mitigate it.
Comments
0No comments yet. Be the first to comment.