Fortinet warns of critical FortiMail flaw exploited in zero-day attacks
AI Summary
Fortinet has disclosed a critical zero-day vulnerability, CVE-2026-104286, in its FortiMail product that is actively being exploited to achieve unauthorized code execution via path traversal and null byte injection. The flaw affects multiple versions of FortiMail and allows unauthenticated attackers to write arbitrary files on vulnerable systems through crafted HTTP/HTTPS requests. Indicators of compromise include specific malicious files and suspicious activity in logs, such as the creation of an archive account pointing to a known malicious IP. Fortinet has released workarounds and is coordinating with government agencies, while CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog with a mitigation deadline for federal agencies.
AI-extracted · verify before operational use
Indicators of Compromise 16 extracted
| Type | Value | Detail |
|---|---|---|
| IP | 79[.]141[.]169[.]187 | Details → |
| IP | 45[.]129[.]0[.]192 | Details → |
| Filename | /data/lib/liblog.so | Details → |
| Filename | /bin/smit | Details → |
| Filename | /data/bin/webconsole | Details → |
| Filename | /data/bin/mailservice | Details → |
| Filename | /data/etc/httpd.conf | Details → |
| Filename | /data/etc/ld.so.preload | Details → |
| Filename | /data/migadmin.tar.gz | Details → |
| SHA-256 | 8015f34dc84922b03688399d7f9fe7a00361789f7e420c7e2a2cdb23e75cef84 | Details → |
| SHA-256 | 77324ac428bde86d351fc5fc06f6d64a6bfe737dfb2743df1d4c5ac2418a5b6a | Details → |
| SHA-256 | 7a6cea9f5c9e2e9994d4e3c4da73f86cf5acd05ea5d312c066c9d1dafd69ee38 | Details → |
| SHA-256 | 4000276a150a165d3c2537d1e19fb393c4de8333076a16655e28059cae82157b | Details → |
| SHA-256 | 703e97c64e61e41dc3aaba580d82bb2aa7b6a11b54ee6fb467ed5d5a3bffdef5 | Details → |
| SHA-256 | 8953ec7960b09f544a880b072ad4e6cfda7a8303f486251d3478dcfdfbac23b6 | Details → |
| SHA-256 | d6fe51c22b91776f4c961ea58bcac5917f15d560a619d7ce726d3d51795609d3 | Details → |