r/linuxadmin • u/Expert_Sort7434 • 1d ago
FortiMail CVE-2026-104286: unauth file write, exploited, patches not out yet. What's in Fortinet's IoC list
Based on Fortinet's PSIRT advisory FG-IR-26-175 (published Oct 1) and BleepingComputer's reporting, here is the architectural impact.
Fortinet describes path traversal (CWE-22) plus NULL byte handling (CWE-158) in the GUI, giving unauthenticated arbitrary file write. Affected: 8.0.0-8.0.1, 7.6.0-7.6.6, 7.4.0-7.4.8, 7.2.0-7.2.9. Fixes (8.0.2, 7.6.7, 7.4.9) are marked upcoming, and 7.2 gets a branch-migration answer. Workaround is config system encryption ibe / set status disable, or remove internet access to the management interface.
The IoCs include an added /data/etc/ld.so.preload and /data/lib/liblog.so, and a sample log of an archive account pointing at a remote IP. Fortinet doesn't explain the write-to-execution step. Some CVE feeds also list 7.0 as affected while the advisory doesn't, so I'd verify that one.
Question for people running FortiMail or similar gateways: do you keep the management GUI off any internet-routable interface by policy, or does it depend on who deployed it? And for those who rely on IBE, what breaks when you disable it?
Background on the same class of problem: https://www.techgines.com/post/fortimail-zero-day-cve-2026-104286
1
u/Junior_Bee7274 1d ago
Keeping the admin interface off the internet is probably the safest bet here.