2026-10-02CRITICALexploitedFortinet confirms exploitation of an unauthenticated FortiMail file-write flaw; no branch has a fixed build yet
Fortinet FortiMail
product · product:fortinet-fortimail single-source
Coverage
1
first 2026-10-02 → last 2026-10-02
Latest activity
2026-10-02
Fortinet confirms exploitation of an unauthenticated FortiMail file-write flaw; no branch has a fixed build…
Peak priority
critical
1 critical
Targets
public-sector
sectors: public-sector, technology
Sources cited
3
3 hosts
Action items (3)
Do-now tasks recorded on the entries about Fortinet FortiMail, newest first. Check the date before acting on an older one.
- Immediate action: Fortinet reports in-the-wild exploitation of an unauthenticated file-write flaw in FortiMail and has not yet shipped a fixed build for 7.4, 7.6 or 8.0. Disable IBE support with the vendor's CLI command or take the management interface off the internet today, and check every appliance that was reachable against the compromise artifacts in advisory FG-IR-26-175.2026-10-02CVE-2026-104286
- On every FortiMail on 7.2, 7.4, 7.6 or 8.0, disable IBE support (config system encryption ibe, set status disable) or remove internet access to the management interface now; no fixed build exists for 7.4, 7.6 or 8.0, and 7.2 must move to 7.4 or above once a fixed 7.4 build ships.2026-10-02CVE-2026-104286
- Check every FortiMail that was internet-reachable before the workaround against the file, cron and CLI-audit artifacts published in FG-IR-26-175, including a mail archive account that sends to a remote host.2026-10-02CVE-2026-104286
Defender insights
What each entry about Fortinet FortiMail tells a defender to do, newest first.
Detection
Story timeline
Hunting pivots
CVEs (exploited first)
Releases covered
Fortinet FortiMail
ATT&CK techniques (5 across 6 tactics)
5 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
- ExecutionScheduled Task/Job: Cron · Hijack Execution Flow: Dynamic Linker Hijacking
- PersistenceScheduled Task/Job: Cron · Compromise Host Software Binary
- Privilege EscalationScheduled Task/Job: Cron
- StealthHijack Execution Flow: Dynamic Linker Hijacking
- CollectionEmail Collection
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-10-02/cve-2026-104286-fortimail-path-traversal-zero-day-kev · ATT&CK page ↗
Execution TA0002
T1053.003Scheduled Task/Job: Cron×1
Adversaries may abuse the <code>cron</code> utility to perform task scheduling for initial or recurring execution of malicious code. The <code>cron</code> utility is a time-based job scheduler for Unix-like operating systems. The <code> crontab</code> file contains the schedule of cron entries to be run and the specified times for execution. Any <code>crontab</code> files are stored in operating system-specific file paths.
Evidence: 2026-10-02/cve-2026-104286-fortimail-path-traversal-zero-day-kev · ATT&CK page ↗
T1574.006Hijack Execution Flow: Dynamic Linker Hijacking×1
Adversaries may execute their own malicious payloads by hijacking environment variables the dynamic linker uses to load shared libraries. During the execution preparation phase of a program, the dynamic linker loads specified absolute paths of shared libraries from various environment variables and files, such as <code>LD_PRELOAD</code> on Linux or <code>DYLD_INSERT_LIBRARIES</code> on macOS. Libraries specified in environment variables are loaded first, taking precedence over system libraries with the same function name. Each platform's linker uses an extensive list of environment variables at different points in execution. These variables are often used by developers to debug binaries without needing to recompile, deconflict mapped symbols, and implement custom functions in the original library.
Evidence: 2026-10-02/cve-2026-104286-fortimail-path-traversal-zero-day-kev · ATT&CK page ↗
Persistence TA0003
T1053.003Scheduled Task/Job: Cron×1
Adversaries may abuse the <code>cron</code> utility to perform task scheduling for initial or recurring execution of malicious code. The <code>cron</code> utility is a time-based job scheduler for Unix-like operating systems. The <code> crontab</code> file contains the schedule of cron entries to be run and the specified times for execution. Any <code>crontab</code> files are stored in operating system-specific file paths.
Evidence: 2026-10-02/cve-2026-104286-fortimail-path-traversal-zero-day-kev · ATT&CK page ↗
T1554Compromise Host Software Binary×1
Adversaries may modify host software binaries to establish persistent access to systems. Software binaries/executables provide a wide range of system commands or services, programs, and libraries. Common software binaries are SSH clients, FTP clients, email clients, web browsers, and many other user or server applications.
Evidence: 2026-10-02/cve-2026-104286-fortimail-path-traversal-zero-day-kev · ATT&CK page ↗
Privilege Escalation TA0004
T1053.003Scheduled Task/Job: Cron×1
Adversaries may abuse the <code>cron</code> utility to perform task scheduling for initial or recurring execution of malicious code. The <code>cron</code> utility is a time-based job scheduler for Unix-like operating systems. The <code> crontab</code> file contains the schedule of cron entries to be run and the specified times for execution. Any <code>crontab</code> files are stored in operating system-specific file paths.
Evidence: 2026-10-02/cve-2026-104286-fortimail-path-traversal-zero-day-kev · ATT&CK page ↗
Stealth TA0005
T1574.006Hijack Execution Flow: Dynamic Linker Hijacking×1
Adversaries may execute their own malicious payloads by hijacking environment variables the dynamic linker uses to load shared libraries. During the execution preparation phase of a program, the dynamic linker loads specified absolute paths of shared libraries from various environment variables and files, such as <code>LD_PRELOAD</code> on Linux or <code>DYLD_INSERT_LIBRARIES</code> on macOS. Libraries specified in environment variables are loaded first, taking precedence over system libraries with the same function name. Each platform's linker uses an extensive list of environment variables at different points in execution. These variables are often used by developers to debug binaries without needing to recompile, deconflict mapped symbols, and implement custom functions in the original library.
Evidence: 2026-10-02/cve-2026-104286-fortimail-path-traversal-zero-day-kev · ATT&CK page ↗
Collection TA0009
T1114Email Collection×1
Adversaries may target user email to collect sensitive information. Emails may contain sensitive data, including trade secrets or personal information, that can prove valuable to adversaries. Emails may also contain details of ongoing incident response operations, which may allow adversaries to adjust their techniques in order to maintain persistence or evade defenses. Adversaries can collect or forward email from mail servers or clients.
Evidence: 2026-10-02/cve-2026-104286-fortimail-path-traversal-zero-day-kev · ATT&CK page ↗
Entries about Fortinet FortiMail (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- bleepingcomputer.com1 (33%)
- cisa.gov1 (33%)
- fortiguard.com1 (33%)
All cited sources (3)
- bleepingcomputer.comBleepingComputerhttps://www.bleepingcomputer.com/news/security/fortinet-warns-of-critical-fortimail-flaw-exploited-in-zero-day-attacks/
- cisa.govCISA Known Exploited Vulnerabilities cataloghttps://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
- fortiguard.comFortinet PSIRT (FG-IR-26-175)https://www.fortiguard.com/psirt/FG-IR-26-175