Cyber Threat Brief — October 2 2026

⚠️ This report is AI-generated. Always validate findings.

1. FortiMail unauth path-traversal file write — CVE-2026-104286

TL;DR: CISA added CVE-2026-104286 to KEV after Fortinet confirmed ITW exploitation of an unauthenticated path-traversal plus NULL-byte flaw that writes arbitrary files via crafted HTTP/HTTPS to the management GUI. Preserve forensics, hunt the implant paths below, disable IBE or lock down management access, then upgrade when fixed builds ship — KEV due 2026-10-04.

What’s New:

  • Fortinet advisory FG-IR-26-175 (2026-10-01) and CISA KEV catalog 2026.10.01 (count 1731) list CVSS 9.8 unauth arbitrary file write; forensic triage Yes; due 2026-10-04.
  • Fixed builds are still upcoming (8.0.2 / 7.6.7 / 7.4.9); FortiMail 7.2.x has no in-branch fix — migrate to 7.4.9+.
  • Workaround now: disable IBE (config system encryption ibe → set status disable) or block internet to the management interface.
  • ITW implant adds /data/etc/ld.so.preload + /data/lib/liblog.so, drops webconsole/mailservice, and stages exfil via archive account archive234 to 79.141.169.187.

Actionable Intel

ArtifactTypeATT&CKLog SourceAction
CVE-2026-104286 on FortiMail 8.0.0–8.0.1 / 7.6.0–7.6.6 / 7.4.0–7.4.8 / 7.2.0–7.2.9. KEV due 2026-10-04 (forensic triage Yes). Fixed: upcoming 8.0.2+ / 7.6.7+ / 7.4.9+ (7.2: migrate to 7.4).Vulnerable edge / KEVT1190Inventory / get system statusInventory FortiMail versions. Capture config/logs before change. Apply IBE-disable or management-ACL workaround until the fixed build for your train is installed. Rebuild from clean image if any implant IoC hits.
Path /data/etc/ld.so.preload (added; SHA256 8953ec7960b09f544a880b072ad4e6cfda7a8303f486251d3478dcfdfbac23b6)Persistence / dynamic linkerT1574.006Appliance filesystem / FIMCheck for /data/etc/ld.so.preload. Treat presence as compromise; do not just delete — rebuild from a fixed image.
Path /data/lib/liblog.so (added; SHA256 8015f34dc84922b03688399d7f9fe7a00361789f7e420c7e2a2cdb23e75cef84)Rootkit / shared objectT1014 / T1574.006Appliance filesystem / malware scannerHash-scan for this liblog.so. Correlate with ld.so.preload entries that load it.
Path /data/bin/webconsole (added; SHA256 7a6cea9f5c9e2e9994d4e3c4da73f86cf5acd05ea5d312c066c9d1dafd69ee38)Backdoor binaryT1505.003Appliance filesystem / process listList /data/bin/webconsole and hash-match. Kill unexpected processes and rebuild if present.
Path /data/bin/mailservice (added; SHA256 4000276a150a165d3c2537d1e19fb393c4de8333076a16655e28059cae82157b)Backdoor binaryT1505.003Appliance filesystem / process listList /data/bin/mailservice and hash-match. Kill unexpected processes and rebuild if present.
Modified /bin/smit (SHA256 77324ac428bde86d351fc5fc06f6d64a6bfe737dfb2743df1d4c5ac2418a5b6a)Tampered system binaryT1036Appliance filesystemCompare /bin/smit hash to vendor baseline. Treat mismatch with other IoCs as confirmed compromise.
Modified /data/etc/httpd.conf (SHA256 703e97c64e61e41dc3aaba580d82bb2aa7b6a11b54ee6fb467ed5d5a3bffdef5)Tampered httpd configT1505Appliance filesystemCompare /data/etc/httpd.conf hash to vendor baseline. Treat mismatch with other IoCs as confirmed compromise.
Archive account archive234 with remote-directory /uploadsExfil / config IoCT1041 / T1074FortiMail kevent/config logsGrep config and kevent logs for account archive234. Remove the account only after forensic capture.
Actor IPv4 79.141.169.187 (also hunt 45.129.0.192)Network IoCT1071 / T1190Firewall / FortiMail audit / egressBlock or heighten logging for 79.141.169.187 (and 45.129.0.192). Alert on FortiMail hosts opening unexpected outbound sessions to them.
Internet-exposed FortiMail management / IBE GUI portsExposureT1190Firewall / external scanDisable IBE now. Restrict management HTTP/HTTPS to trusted admin networks or VPN jump hosts until patched.

Detection

SourceRuleGap
Splunk ESCUNone — verifiedAdjacent Linux Auditd Preload Hijack Via Preload File matches /etc/ld.so.preload only; ITW path is /data/etc/ld.so.preload. Fortinet appliance analytics target FortiGate/FortiNAC CVE-2022-40684 /api/v2/ — not FortiMail GUI write.
ElasticNone — verifiedModification of Dynamic Linker Preload Shared Object and Dynamic Linker Creation select /etc/ld.so.preload — miss FortiMail /data/etc/ld.so.preload. FortiGate rules do not cover FortiMail.
SigmaNone — verifiedModification of ld.so.preload / Code Injection by ld.so Preload hardcode /etc/ld.so.preload. No emerging-threat rule for CVE-2026-104286.

Hunt hint: Run get system status and compare to the affected ranges. Grep FortiMail system/kevent logs for archive234, O=/migadmin, admin logout from (null), and IBE Invalid Base64 Encoding. On the filesystem, check /data/etc/ld.so.preload, /data/lib/liblog.so, /data/bin/webconsole, /data/bin/mailservice, and hashes for /bin/smit and /data/etc/httpd.conf. Block 79.141.169.187 and 45.129.0.192. If any implant hits, rebuild from a clean fixed image and rotate admin/LDAP/SMTP/API credentials.

Sources: Fortinet FG-IR-26-175 · CISA KEV alert · BleepingComputer · The Hacker News · SecurityWeek · CISACyber on X


Status Updates

  • CVE-2026-86950 (Apple CoreGraphics): KEV due TODAY 2026-10-02; forensic triage Yes. Confirm iOS/iPadOS 26.7.1, Tahoe 26.7.1 (25G241), Sequoia 15.8.1 (24H32). Sep 29 brief.
  • CVE-2026-76504 (Cisco Catalyst SD-WAN Manager): KEV due TOMORROW 2026-10-03. Keep hunting URI-encoded j_security_check and viptela-reserved- in NMS logs; patch fixed builds. Oct 1 brief.
  • CVE-2026-88771 (Citrix NetScaler): KEV due was 2026-09-30. Keep LevelBlue sec_monitor / .local_journal and Mandiant WHIPSHOT/SLAPSHOT hunts. Oct 1 brief.
  • CVE-2026-88772 (Citrix NetScaler DTLS): KEV due was 2026-09-30. Confirm fixed builds; DTLS-off is temporary only for this CVE. Sep 28 brief.
  • GHSA-qx49-fqc8-xw99 (MCP Python SDK OAuth): No material change. Keep mcp ≥1.30.0 / ≥2.2.0 and issuer= on unattended providers. Sep 29 brief.
  • CVE-2026-65660 (SharePoint): KEV due was 2026-09-28. Confirm fixed builds / sphealth.aspx hunts. Sep 26 brief.
  • CVE-2026-67279 (MikroTik): KEV due was 2026-09-28. Confirm RouterOS ≥6.49.21 / ≥7.23.4 / ≥7.24.2. Sep 06 brief.
  • CVE-2026-87902 (WordPress): KEV due was 2026-09-28. Confirm WP ≥7.1.2. Sep 24 brief.
  • Carbonato / CVE-2026-62062 (Elementor): No material change. Keep TCP/2375, GH0ST/SOUL.md, and elementor/v1/events/ hunts; Elementor ≥4.3.2. Sep 28 brief.