decrypted · 3 october 2026 · vulnerabilities and patching · uk policy and law · surveillance and privacy

FortiMail's encryption portal let attackers write files without logging in

A mail security gateway is supposed to be the thing that checks the post before it reaches your staff. This week, Fortinet confirmed that attackers are using a flaw in its FortiMail product to write their own files onto that gateway without logging in. Fortinet published its advisory on 1 October, and CISA added the flaw, CVE-2026-104286, to its Known Exploited Vulnerabilities catalogue the same day, with a deadline of 4 October for US federal agencies.

What the flaw does

The bug scores 9.8 out of 10. It sits in the web component for Identity-Based Encryption, or IBE, the feature that lets FortiMail send encrypted messages to outside recipients who collect them through a web portal. Fortinet describes a path traversal combined with improper handling of NULL characters, two classic input-handling mistakes.

Think of a hotel porter told to deliver parcels only to the post room. The flaw lets a stranger hand over a note reading "post room, then up three floors and along the corridor", and the porter simply follows it, never asking who the stranger is. In technical terms, an unauthenticated attacker can write arbitrary files to the underlying system using crafted HTTP or HTTPS requests.

What defenders will see

Fortinet's indicators of compromise include newly added files named liblog.so, webconsole and mailservice, a ld.so.preload file, and modified configuration files such as httpd.conf. A preload file is a Linux mechanism for loading a chosen library into every program that starts, which is exactly what you would want if you planned to stay hidden. Two IP addresses are listed: 79.141.169[.]187 and 45.129.0[.]192. Reporting says the actor behind the attacks has not been identified.

One caution: sources disagree on patch status. Fortinet's advisory lists 8.0.2, 7.6.7 and 7.4.9 as fixed releases and tells 7.2 users to move to the 7.4 branch, but some write-ups describe the fixes as forthcoming. Check the advisory against your own appliance rather than trusting a summary, including this one.

The Secure by Design lesson

An email gateway sees the contents of an organisation's correspondence, so it should present the smallest surface possible. Here, an optional feature exposed a web interface, and one weak check turned it into a foothold. Secure by Design asks the vendor for three things: optional features off until chosen, input that contains path characters rejected rather than tidied up, and portals and management interfaces that are not reachable from the open internet by default. Fortinet's own workarounds point the same way: disable IBE, restrict access to trusted networks, or use a web application firewall to block POST requests to /ibe containing "../".

What UK organisations should do

That last question costs an afternoon. It is far cheaper than explaining to a regulator, or your board, why your mail gateway was open.

Also this week

MI5 says China's spies have been paying UK academics, sometimes unknowingly. In an alert dated 30 September, MI5 said more than 100 UK-linked academics have worked on projects funded by the China General Technology Research Institute. MI5 says the institute's primary purpose is to fund research that directly improves the Ministry of State Security's technical capability for espionage, across AI, cybersecurity, covert communications and steganography. It added that some academics may not know who is paying. Continuing could risk prosecution under the National Security Act 2023, and Security Minister Dan Jarvis has written to vice-chancellors. The Chinese embassy called the claims "imaginary and purely fabricated". The design point is provenance: who funds a piece of work is a control, and it should be traceable like any other dependency.

A Danish university's identity system was raided with stolen profiles. The Technical University of Denmark (DTU) says attackers compromised DTU profiles and used them to reach DTUBasen, its identity and access management system, retrieving data going back to 2003. Up to 200,000 current and former staff, students and partners may be affected, with exposed data including CPR numbers, home addresses and emergency contacts. DTU says it cannot yet determine exactly what was taken, so the 200,000 is an estimate, and it has reported the incident to the Danish data protection authority. The lesson travels to UK universities: a directory of people is a crown jewel, and keeping two decades of former users is a choice. Retention limits are a security control.

Sources

If you want a second pair of eyes on your own exposure, get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.

Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.

Play here Loads Apple's player when you press it.