Unauthenticated Path Traversal Flaw Lets Attackers Write Arbitrary Files to FortiMail Systems
Fortinet's FortiMail secure email gateway is affected by a critical zero-day vulnerability, tracked as CVE-2026-104286, that is being actively exploited in the wild. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities (KEV) catalog on October 1, 2026, giving Federal Civilian Executive Branch agencies until October 4, 2026 to remediate under Binding Operational Directive 26-04. Fortinet published its own advisory, FG-IR-26-175, the same day, crediting the find to Gwendal Guégniaud of Fortinet's Product Security team.
As of publication, Fortinet has not yet released a patched build for any affected branch — only interim workarounds are available, making this an active zero-day in the truest sense: exploitation predates a fix.
Vulnerability Details
| Attribute | Value |
|---|---|
| CVE ID | CVE-2026-104286 |
| CVSS v3.1 Score | 9.8 (Critical) |
| Weakness Class | CWE-22 (Path Traversal) combined with CWE-158 (improper neutralization of NULL byte/character) |
| Affected Product | Fortinet FortiMail |
| Primary Impact | Unauthenticated arbitrary file write; potential arbitrary code/command execution |
| Attack Vector | Crafted HTTP/HTTPS requests to the FortiMail interface |
| Authentication Required | None |
| Discovered By | Gwendal Guégniaud, Fortinet Product Security team (internal discovery) |
| Fortinet Advisory | FG-IR-26-175 (published October 1, 2026) |
| CISA KEV Listed | Yes — added October 1, 2026 |
| Federal Remediation Deadline | October 4, 2026 (BOD 26-04) |
| Patch Availability | None at time of publication — fixed builds still forthcoming |
Affected Versions
| FortiMail Branch | Affected Versions | Fix Status |
|---|---|---|
| 8.0 | 8.0.0 – 8.0.1 | Upcoming 8.0.2 (not yet released) |
| 7.6 | 7.6.0 – 7.6.6 | Upcoming 7.6.7 (not yet released) |
| 7.4 | 7.4.0 – 7.4.8 | Upcoming 7.4.9 (not yet released) |
| 7.2 | 7.2.0 – 7.2.9 | No fix planned for this branch — migration to 7.4+ required |
Fortinet's advisory is the authoritative source for current fix status, since machine-readable CVE affected-version metadata circulating in third-party feeds has been reported to conflict with the live advisory. Administrators should check FG-IR-26-175 directly rather than relying on a cached scanner feed.
How the Flaw Works
CVE-2026-104286 combines a path traversal weakness with improper neutralization of NULL bytes/characters, allowing a remote, unauthenticated attacker to send crafted HTTP or HTTPS requests to FortiMail that cause the system to write arbitrary files outside their intended directory. Depending on where a malicious file lands, this can be chained into arbitrary code or command execution on the underlying system — a textbook critical-severity outcome for a flaw with no authentication requirement, reachable over the network.
Fortinet's own incident data points to active, hands-on-keyboard exploitation: the company has identified indicators of compromise including two attacker-controlled IP addresses and seven suspicious files, among them modified system binaries and newly injected libraries — consistent with attackers using the file-write primitive to drop persistence mechanisms or backdoors on compromised appliances.
Mitigations (No Patch Available)
Because no fixed build currently exists for any affected branch, Fortinet's guidance is workaround-only:
- Disable Identity-Based Encryption (IBE) feature support on affected FortiMail systems, which Fortinet identifies as implicated in the vulnerable code path.
- Restrict access to the FortiMail management interface to trusted internal networks only — remove it from direct public internet exposure.
- Hunt for the published indicators of compromise: check for connections from the two IoC IP addresses, and audit system binaries and loaded libraries against known-good baselines for signs of the seven identified suspicious files or similar tampering.
- FortiMail 7.2.x administrators should plan migration to the 7.4 branch or later, since Fortinet has indicated no fix is planned for 7.2.x directly.
- Monitor Fortinet's FG-IR-26-175 advisory for the release of 7.4.9, 7.6.7, and 8.0.2, and apply them immediately once available.
Impact Assessment
| Impact Area | Description |
|---|---|
| Confidentiality / Integrity | Arbitrary file write can plant backdoors, web shells, or modified binaries, giving attackers a durable foothold on the mail gateway |
| Availability | A compromised FortiMail appliance sits in the inbound/outbound mail path — tampering can disrupt or redirect organizational email flow |
| Scope | FortiMail is a perimeter-facing secure email gateway by design, making this a direct bridge from the public internet into email infrastructure |
| Federal Exposure | CISA's KEV listing and three-day BOD 26-04 deadline reflect confirmed active exploitation against federal and likely broader targets |
| Patch Gap | With no fixed build yet released, every affected deployment remains exposed until Fortinet ships 7.4.9 / 7.6.7 / 8.0.2 — workarounds are the only current defense |
Key Takeaways
- CVE-2026-104286 is a CVSS 9.8 critical, unauthenticated path-traversal/file-write flaw in Fortinet FortiMail, actively exploited in the wild.
- CISA added it to the KEV catalog on October 1, 2026, giving federal agencies until October 4 to remediate.
- No patched version exists yet for any affected branch (7.2, 7.4, 7.6, 8.0) — Fortinet's advisory FG-IR-26-175 lists 7.4.9, 7.6.7, and 8.0.2 as forthcoming but unreleased.
- FortiMail 7.2.x has no planned fix; administrators on that branch must migrate to 7.4 or later.
- Fortinet has published indicators of compromise (two attacker IPs, seven suspicious files including modified binaries) from its own investigation of in-the-wild exploitation.
- Until a patch ships, organizations must rely on workarounds: disabling IBE support and restricting management-interface access to trusted networks.