Fortinet confirms FortiMail zero-day: patching does not remove the backdoor
CVE-2026-104286 (CVSS 9.8) in the FortiMail web management interface lets unauthenticated attackers write arbitrary files and plant a Linux backdoor via ld.so.preload. CISA added it to the KEV catalog on October 1 with an October 4 deadline for federal agencies; fixed branches are 8.0.2+, 7.6.7+ and 7.4.9+, with no fix for 7.2.
- CVE-2026-104286: path traversal plus NULL byte, CVSS 9.8, no auth needed
- Attackers write /data/etc/ld.so.preload and rootkit /data/lib/liblog.so
- CISA KEV: US federal agencies must remediate by October 4
- Fixed in 8.0.2+, 7.6.7+, 7.4.9+; no patch for the 7.2 branch
Read next
Security