字号 ·· | 护眼
theregister

Fortinet就正被积极利用的FortiMail零日漏洞发出警报Fortinet sounds the alarm over actively exploited FortiMail zero-day

点「原文对照」整页切到原文,或双击某段只看那段的原文。

Fortinet提醒用户务必立即加固FortiMail系统,因为攻击者已开始利用一个高危漏洞,该漏洞可令攻击者在无需登录的情况下向易受攻击的系统写入文件。该漏洞编号为CVE-2026-104286,CVSS评分高达9.8分,影响Fortinet多款电子邮件安全平台版本。据Fortinet说明,该漏洞源于FortiMail网页界面存在路径遍历漏洞以及对空字符处理不当的问题。

Fortinet is warning customers to lock down FortiMail after attackers started exploiting a critical bug that lets them write files to vulnerable systems without logging in. The flaw, tracked as CVE-2026-104286, carries a CVSS score of 9.8 and affects multiple versions of Fortinet's email security platform. Fortinet describes the vulnerability as a combination of path traversal and improper handling of null characters in FortiMail's web interface.

未经身份验证的攻击者可通过发送特制的HTTP或HTTPS请求,向系统底层写入任意文件。若文件被写入特定位置,攻击者便有可能在设备上执行代码或命令。

An unauthenticated attacker can exploit it using specially crafted HTTP or HTTPS requests to write arbitrary files to the underlying system. Writing files to certain locations could allow an attacker to execute code or commands on the appliance.

受此漏洞影响的FortiMail版本包括:8.0.0至8.0.1、7.6.0至7.6.6、7.4.0至7.4.8以及7.2.0至7.2.9。Fortinet在安全公告中指出,CVE-2026-104286“目前正遭到攻击者利用”,但并未说明攻击开始的时间、幕后黑手身份以及有多少用户已遭侵害。不过,厂商已公布了管理员可在系统中排查的异常迹象,包括可疑文件、配置变更情况以及与攻击相关的IP地址。

Fortinet says the flaw affects FortiMail versions 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9. The vendor's advisory says CVE-2026-104286 "is being exploited in the wild," although it doesn't say when the attacks began, who is behind them, or how many customers may have been compromised. It has, however, published indicators administrators can hunt for on their systems. These include suspicious files and configuration changes, along with IP addresses associated with the attacks.

美国网络安全和基础设施安全局(CISA)已将CVE-2026-104286列入“已知被利用漏洞”清单,并要求美国联邦文职机构于10月4日前完成系统排查并采取相应防护措施。目前Fortinet表示多个受影响版本的修复补丁仍在开发中,因此使用这些版本的用户在更新发布前只能采取临时应对措施。在此期间,Fortinet建议用户若无需使用基于身份的加密功能,应将其予以禁用;若无法禁用,则需确保FortiMail管理界面无法从互联网访问,且仅允许受信任的私有网络进行访问。

CISA has added CVE-2026-104286 to its Known Exploited Vulnerabilities catalog, directing US federal civilian agencies to carry out forensic triage and apply mitigations by October 4. Fortinet lists fixes for several affected branches as "upcoming," leaving customers on those versions reliant on workarounds until updates arrive. In the meantime, Fortinet recommends disabling Identity Based Encryption if it isn't required. Where that's not possible, customers should prevent the FortiMail management interface from being reachable from the internet and restrict access to trusted private networks.

此外,管理员还应检查系统是否存在被入侵的迹象——因为采取临时措施无法清除攻击者早已植入的文件或持久化机制。

Administrators should also check for signs of compromise: applying a workaround will not remove any files or persistence mechanisms attackers may already have planted.

这并非Fortinet今年首次遭遇攻击者侵入其网络设备的情况。今年6月,约75,000台FortiGate防火墙的相关登录凭证被犯罪分子获取,不过Fortinet方面表示,这些数据源自此前的安全事件及暴力破解攻击,并非由新的数据泄露事件导致。®

It's not Fortinet's first encounter with attackers making themselves at home on its network appliances this year. In June, credentials linked to around 75,000 FortiGate firewalls turned up in criminal hands, though Fortinet said the data came from previous incidents and brute-force attacks rather than a fresh breach. ®