The Exploit Bulletin

Archives
Log in
Subscribe
October 3, 2026

The Exploit Bulletin — Saturday, October 3, 2026: 2 issues require action

Saturday, October 3, 2026 — 2 issues require action. If you run none of the software below, you are done.

Affects: FortiMail · Internxt Desktop app


1. Unauthenticated path traversal in FortiMail IBE webmail allows arbitrary file write and code execution (CVE-2026-104286)

CISA KEV (due 2026-10-04) · REMOTE CODE EXECUTION · CRITICAL · CVSS 9.8

Fortinet confirmed in-the-wild exploitation and CISA added the flaw to KEV on 2026-10-01 while fixed builds are still listed as upcoming, so any FortiMail with IBE and internet-facing webmail left in its current configuration is exposed to a known, unauthenticated code-execution path.

A path traversal combined with NULL-byte handling in FortiMail's IBE (Identity-Based Encryption) web endpoint lets an unauthenticated attacker write arbitrary files on the appliance via crafted HTTP/HTTPS POST requests to /ibe, which Fortinet rates as leading to execution of unauthorized code or commands. Fortinet's advisory supplies attacker IPs and log artefacts showing cron-based command execution and creation of a rogue remote archive account for exfiltration.

Affected: FortiMail 8.0.0 through 8.0.1; FortiMail 7.6.0 through 7.6.6; FortiMail 7.4.0 through 7.4.8; FortiMail 7.2.0 through 7.2.9

How to Test: Check the FortiMail firmware version against the affected ranges (8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8, all 7.2.x) and whether the IBE service is enabled (Encryption -> IBE). Review System Event Logs for the cron entry type=event subtype=system pri=debug user=system ui=cron msg="(root) CMD (/bin/sh -c 'O=/migadmin ..., for user=admin ui=(null) ... msg="User admin logged out from (null).", and for a config log adding an archive account such as Added 'archive234' to 'archive account' ... remote-ip[79.141.169.187] ... remote-directory[/uploads]. Check web/WAF logs for POST requests to /ibe containing ../, and firewall/netflow for traffic to 79.141.169.187 or 45.129.0.192. Treat any match as a compromise and rotate admin credentials.

How to Mitigate: Fixed releases are FortiMail 8.0.2, 7.6.7 and 7.4.9, which Fortinet lists as upcoming; 7.2 users must migrate to the 7.4 branch or later. Until the fixed build is installed, apply Fortinet's workaround: disable IBE in the GUI (Encryption -> IBE -> IBE Service 'off') or via CLI config system encryption ibe / set status disable / end. Alternatively, block internet access to the FortiMail webmail interface (allow only trusted private networks), or if a WAF fronts FortiMail, block POST requests to /ibe that contain '../'.

Evidence: CISA KEV · VulnCheck KEV · Vendor confirmed · Vendor confirmed · CISA SSVC: active · CISA adds CVE-2026-104286 to KEV based on evidence of active exploitation

Full entry with sources →


2. Protocol-handler RCE from a single malicious link in the Internxt Desktop app (Internxt Desktop)

UNVERIFIED PUBLIC REPORT · NO CVE · REMOTE CODE EXECUTION · HIGH

The write-up was published 2026-10-02 with a working PoC, the fix has been merged for three months but no fixed release has shipped, and all installed copies (<=2.6.12) are exploitable by a single link click.

The Internxt desktop app registers the internxt:// protocol handler and its notification handler passes URLs to shell.openExternal without validation. A victim clicking a crafted link such as internxt://notification/file:///C:/Windows/System32/calc.exe causes the app to launch an attacker-chosen target, giving remote code execution on Windows, macOS and Linux. The researcher also documents structural crypto weaknesses (unauthenticated public keys, mnemonic key leakage via URL path, MD5-based password protection) that could leak long-term encryption keys. No CVE and no public vendor advisory; the vendor privately told the author a v2.7 fix is forthcoming.

Affected: Internxt Desktop app version 2.6.12 and earlier; v2.7 said by the vendor to be forthcoming but not yet shipped

How to Test: Check your installed Internxt desktop app version (Help/About); 2.6.12 and earlier are affected. To test exposure, confirm the app registered the internxt:// protocol handler and whether clicking an internxt://notification/... link launches an external target. Watch for unexpected child processes spawned by the Internxt app after link clicks.

How to Mitigate: There is no shipped fix as of this writing, so remove or stop using the app, or deregister/block the internxt:// protocol handler and avoid clicking internxt:// links; install v2.7 immediately once the vendor releases it.

Evidence: researcher write-up with PoC

Full entry with sources →


Read on the web · Every past edition

The Exploit Bulletin is free and daily. It publishes only what security teams must act on today — nothing else. Forward it freely.

Spot an error, or an exploit we missed? Reply here or email [email protected].

Don't miss what's next. Subscribe to The Exploit Bulletin:
← Newer The Exploit Bulletin — Sunday, October 4, 2026: all clear Older → The Exploit Bulletin — Friday, October 2, 2026: 1 issue requires action
www.exploitbulletin.com
jbac.co
LinkedIn
Powered by Buttondown, the easiest way to start and grow your newsletter.