A FortiMail Bug Fortinet Rated 9.8 Is Already Being Used to Plant Web Shells
Cybersecurity

A FortiMail Bug Fortinet Rated 9.8 Is Already Being Used to Plant Web Shells

CVE-2026-104286 lets an unauthenticated attacker write files to a FortiMail server, and CISA added it to the exploited catalog within a day of disclosure.

PublishedOctober 3, 2026
Read time5 min read
Share

What the bug actually does

CVE-2026-104286 combines a path traversal flaw with improper handling of null bytes in FortiMail, Fortinet's email security gateway, to let an attacker who has not authenticated at all write arbitrary files onto the device. Fortinet rated it 9.8 out of 10 on the CVSS scale, the kind of score reserved for flaws that require no special access and no user interaction to exploit. The vulnerability spans a wide range of still-supported FortiMail branches, from 7.2 through the newly released 8.0 line, which means almost any organization running the product on a recent version is in scope.

The mechanism matters because it is not a crash or a denial of service. Writing an arbitrary file to an email gateway is a direct path to persistence: an attacker can drop a web shell, modify configuration files, or alter logging behavior to cover their tracks, all without ever presenting credentials. Fortinet's advisory specifically calls out modifications to liblog.so and httpd.conf on compromised systems, which suggests attackers are going after both the logging pipeline and the web server configuration in the same pass.

Already in the known-exploited catalog

CISA added CVE-2026-104286 to its Known Exploited Vulnerabilities catalog on October 1, the day after Fortinet's disclosure, which is a fast confirmation that this is live exploitation rather than a responsibly disclosed bug sitting unused. Fortinet's own product security researcher, Gwendal Guegniaud, is credited with the discovery, which is the better version of this story: the vendor found it before an attacker's use became public knowledge, even if exploitation was apparently already underway in the wild by the time of disclosure.

Investigators have published two indicators of compromise, the IP addresses 79.141.169.187 and 45.129.0.192, along with the specific files attackers modify or add once inside a compromised device, including liblog.so, a modified webconsole binary, and an altered httpd.conf. That level of specificity gives security teams something concrete to hunt for immediately rather than waiting on a signature update from an endpoint vendor. Any team running FortiMail should be checking logs and outbound connections against those indicators today, not after the next scheduled patch window, because the gap between disclosure and a team actually looking is where most of the damage in campaigns like this one gets done.

The mitigation gap enterprises are living in

Fortinet's interim guidance is to disable the IBE feature and restrict management interface access to trusted networks until version-specific patches land. That is a sensible stopgap, but it also describes a familiar and uncomfortable period: the window between a known, actively exploited critical vulnerability and a vendor patch an enterprise can actually install without breaking a production mail flow. Many organizations run FortiMail precisely because it is deeply integrated into existing mail routing and compliance archiving, which makes a quick rip-and-replace mitigation impractical.

That integration depth is exactly why gateway appliances like this one are such attractive targets for serious attackers. They sit between the public internet and an organization's internal mail infrastructure with broad permissions by design, and a compromise there can expose far more than the device itself. An attacker who controls a mail gateway can intercept, read, or redirect message traffic for further social engineering, harvest credentials in transit, and use the device's trusted position on the network to pivot toward systems that would normally be shielded from direct internet exposure.

Why email gateways keep showing up in this list

This is not an isolated FortiMail problem, and treating it as one would be a mistake. Perimeter security appliances, including email gateways, VPN concentrators, and firewalls, have become the preferred initial access point for serious attackers precisely because they are internet-facing by design and historically under-monitored compared to the endpoints and servers that run standard detection and response agents. A compromised laptop gets flagged by behavioral detection within minutes in a mature environment; a compromised email gateway often does not have an agent watching it at all, and its logs may not even flow into the same security information platform.

Security teams that have spent the last several years hardening endpoints and cloud workloads should treat this disclosure as a prompt to revisit the appliance layer with the same scrutiny they already apply elsewhere. That means building asset inventories that actually include every email gateway, firewall, and VPN concentrator on the network, not just the servers and laptops that show up automatically in an endpoint console, and then asking whether any of those appliances can forward logs into the same detection pipeline the rest of the environment already relies on.

What security leaders should do this week

Any organization running FortiMail 7.2 through 8.0.1 should treat this as an active incident response exercise rather than a routine patch cycle line item. That means checking logs and network connections against the published indicators of compromise immediately, applying Fortinet's interim mitigations, which include disabling the IBE feature and restricting management interface access to trusted networks, even before a permanent patch is available for a given branch, and assuming compromise rather than assuming safety if the device has been internet-facing without those access restrictions already in place for some time.

Beyond the immediate fix, this is a good trigger to raise a harder question in the next security steering committee meeting: which perimeter appliances in the environment lack the same monitoring coverage as the endpoint fleet, and what would it realistically take to close that gap before the next critical, actively exploited bug in this exact category gets disclosed. Fortinet will not be the last vendor to publish a 9.8 on an internet-facing appliance this year, and the organizations that fare best will be the ones that already know every box on that perimeter list.

Tagged#news#security#cybersecurity#breach#cisa#ransomware#zero-day#supply-chain#ai-security#fortinet#fortimail#cve-2026-104286#email-security#cisa-kev#web-shell#perimeter-security