Cyber Threat Brief — October 2 2026
1. FortiMail unauth path-traversal file write — CVE-2026-104286
TL;DR: CISA added CVE-2026-104286 to KEV after Fortinet confirmed ITW exploitation of an unauthenticated path-traversal plus NULL-byte flaw that writes arbitrary files via crafted HTTP/HTTPS to the management GUI. Preserve forensics, hunt the implant paths below, disable IBE or lock down management access, then upgrade when fixed builds ship — KEV due 2026-10-04.
What’s New:
- Fortinet advisory FG-IR-26-175 (2026-10-01) and CISA KEV catalog 2026.10.01 (count 1731) list CVSS 9.8 unauth arbitrary file write; forensic triage Yes; due 2026-10-04.
- Fixed builds are still upcoming (8.0.2 / 7.6.7 / 7.4.9); FortiMail 7.2.x has no in-branch fix — migrate to 7.4.9+.
- Workaround now: disable IBE (
config system encryption ibe→set status disable) or block internet to the management interface. - ITW implant adds
/data/etc/ld.so.preload+/data/lib/liblog.so, dropswebconsole/mailservice, and stages exfil via archive account archive234 to 79.141.169.187.
Actionable Intel
| Artifact | Type | ATT&CK | Log Source | Action |
|---|---|---|---|---|
| CVE-2026-104286 on FortiMail 8.0.0–8.0.1 / 7.6.0–7.6.6 / 7.4.0–7.4.8 / 7.2.0–7.2.9. KEV due 2026-10-04 (forensic triage Yes). Fixed: upcoming 8.0.2+ / 7.6.7+ / 7.4.9+ (7.2: migrate to 7.4). | Vulnerable edge / KEV | T1190 | Inventory / get system status | Inventory FortiMail versions. Capture config/logs before change. Apply IBE-disable or management-ACL workaround until the fixed build for your train is installed. Rebuild from clean image if any implant IoC hits. |
Path /data/etc/ld.so.preload (added; SHA256 8953ec7960b09f544a880b072ad4e6cfda7a8303f486251d3478dcfdfbac23b6) | Persistence / dynamic linker | T1574.006 | Appliance filesystem / FIM | Check for /data/etc/ld.so.preload. Treat presence as compromise; do not just delete — rebuild from a fixed image. |
Path /data/lib/liblog.so (added; SHA256 8015f34dc84922b03688399d7f9fe7a00361789f7e420c7e2a2cdb23e75cef84) | Rootkit / shared object | T1014 / T1574.006 | Appliance filesystem / malware scanner | Hash-scan for this liblog.so. Correlate with ld.so.preload entries that load it. |
Path /data/bin/webconsole (added; SHA256 7a6cea9f5c9e2e9994d4e3c4da73f86cf5acd05ea5d312c066c9d1dafd69ee38) | Backdoor binary | T1505.003 | Appliance filesystem / process list | List /data/bin/webconsole and hash-match. Kill unexpected processes and rebuild if present. |
Path /data/bin/mailservice (added; SHA256 4000276a150a165d3c2537d1e19fb393c4de8333076a16655e28059cae82157b) | Backdoor binary | T1505.003 | Appliance filesystem / process list | List /data/bin/mailservice and hash-match. Kill unexpected processes and rebuild if present. |
Modified /bin/smit (SHA256 77324ac428bde86d351fc5fc06f6d64a6bfe737dfb2743df1d4c5ac2418a5b6a) | Tampered system binary | T1036 | Appliance filesystem | Compare /bin/smit hash to vendor baseline. Treat mismatch with other IoCs as confirmed compromise. |
Modified /data/etc/httpd.conf (SHA256 703e97c64e61e41dc3aaba580d82bb2aa7b6a11b54ee6fb467ed5d5a3bffdef5) | Tampered httpd config | T1505 | Appliance filesystem | Compare /data/etc/httpd.conf hash to vendor baseline. Treat mismatch with other IoCs as confirmed compromise. |
Archive account archive234 with remote-directory /uploads | Exfil / config IoC | T1041 / T1074 | FortiMail kevent/config logs | Grep config and kevent logs for account archive234. Remove the account only after forensic capture. |
| Actor IPv4 79.141.169.187 (also hunt 45.129.0.192) | Network IoC | T1071 / T1190 | Firewall / FortiMail audit / egress | Block or heighten logging for 79.141.169.187 (and 45.129.0.192). Alert on FortiMail hosts opening unexpected outbound sessions to them. |
| Internet-exposed FortiMail management / IBE GUI ports | Exposure | T1190 | Firewall / external scan | Disable IBE now. Restrict management HTTP/HTTPS to trusted admin networks or VPN jump hosts until patched. |
Detection
| Source | Rule | Gap |
|---|---|---|
| Splunk ESCU | None — verified | Adjacent Linux Auditd Preload Hijack Via Preload File matches /etc/ld.so.preload only; ITW path is /data/etc/ld.so.preload. Fortinet appliance analytics target FortiGate/FortiNAC CVE-2022-40684 /api/v2/ — not FortiMail GUI write. |
| Elastic | None — verified | Modification of Dynamic Linker Preload Shared Object and Dynamic Linker Creation select /etc/ld.so.preload — miss FortiMail /data/etc/ld.so.preload. FortiGate rules do not cover FortiMail. |
| Sigma | None — verified | Modification of ld.so.preload / Code Injection by ld.so Preload hardcode /etc/ld.so.preload. No emerging-threat rule for CVE-2026-104286. |
Hunt hint: Run get system status and compare to the affected ranges. Grep FortiMail system/kevent logs for archive234, O=/migadmin, admin logout from (null), and IBE Invalid Base64 Encoding. On the filesystem, check /data/etc/ld.so.preload, /data/lib/liblog.so, /data/bin/webconsole, /data/bin/mailservice, and hashes for /bin/smit and /data/etc/httpd.conf. Block 79.141.169.187 and 45.129.0.192. If any implant hits, rebuild from a clean fixed image and rotate admin/LDAP/SMTP/API credentials.
Sources: Fortinet FG-IR-26-175 · CISA KEV alert · BleepingComputer · The Hacker News · SecurityWeek · CISACyber on X
Status Updates
- CVE-2026-86950 (Apple CoreGraphics): KEV due TODAY 2026-10-02; forensic triage Yes. Confirm iOS/iPadOS 26.7.1, Tahoe 26.7.1 (25G241), Sequoia 15.8.1 (24H32). Sep 29 brief.
- CVE-2026-76504 (Cisco Catalyst SD-WAN Manager): KEV due TOMORROW 2026-10-03. Keep hunting URI-encoded
j_security_checkandviptela-reserved-in NMS logs; patch fixed builds. Oct 1 brief. - CVE-2026-88771 (Citrix NetScaler): KEV due was 2026-09-30. Keep LevelBlue
sec_monitor/.local_journaland Mandiant WHIPSHOT/SLAPSHOT hunts. Oct 1 brief. - CVE-2026-88772 (Citrix NetScaler DTLS): KEV due was 2026-09-30. Confirm fixed builds; DTLS-off is temporary only for this CVE. Sep 28 brief.
- GHSA-qx49-fqc8-xw99 (MCP Python SDK OAuth): No material change. Keep
mcp≥1.30.0 / ≥2.2.0 andissuer=on unattended providers. Sep 29 brief. - CVE-2026-65660 (SharePoint): KEV due was 2026-09-28. Confirm fixed builds /
sphealth.aspxhunts. Sep 26 brief. - CVE-2026-67279 (MikroTik): KEV due was 2026-09-28. Confirm RouterOS ≥6.49.21 / ≥7.23.4 / ≥7.24.2. Sep 06 brief.
- CVE-2026-87902 (WordPress): KEV due was 2026-09-28. Confirm WP ≥7.1.2. Sep 24 brief.
- Carbonato / CVE-2026-62062 (Elementor): No material change. Keep TCP/2375,
GH0ST/SOUL.md, andelementor/v1/events/hunts; Elementor ≥4.3.2. Sep 28 brief.