No Patch, Active Exploitation: Why FortiMail Admins Can't Wait
Fortinet and the U.S. Cybersecurity and Infrastructure Security Agency (CISA) are jointly pressing organizations to act immediately on CVE-2026-104286, a critical-severity path traversal vulnerability in FortiMail that attackers are already exploiting in live attacks. Fortinet's advisory, FG-IR-26-175, published October 1, 2026, confirms the flaw lets an unauthenticated attacker send a crafted HTTP or HTTPS request to the FortiMail management interface and write arbitrary files to the underlying system — a capability that can be escalated into full code or command execution.
What makes this disclosure unusual is the order of events: exploitation came first, the advisory second, and a patch has not shipped for any affected branch as of publication. CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog the same day Fortinet's advisory went live, and federal civilian agencies have been given a compressed window to remediate under Binding Operational Directive 26-04. For every other organization running FortiMail, the practical message from both Fortinet and CISA is the same: treat this as an active incident, not a routine patch cycle.
Vulnerability Details
| Attribute | Value |
|---|---|
| CVE ID | CVE-2026-104286 |
| CVSS v3.1 Score | 9.8 (Critical) |
| Vulnerability Class | Path traversal (CWE-22) combined with improper neutralization of a NULL byte/character (CWE-158) |
| Affected Product | Fortinet FortiMail secure email gateway |
| Vulnerable Component | FortiMail's Identity-Based Encryption (IBE) web GUI |
| Authentication Required | None — unauthenticated, remotely exploitable |
| Primary Impact | Arbitrary file write; chainable to arbitrary code/command execution |
| Fortinet Advisory | FG-IR-26-175, published October 1, 2026 |
| Exploitation Status | Confirmed exploited in the wild |
| CISA KEV | Added October 1, 2026 |
| Patch Status | Not yet released for any branch at time of publication |
How the Exploit Chain Works
Escaping the sandboxed directory
The flaw lives in the web interface that backs FortiMail's Identity-Based Encryption feature, which is reachable through the appliance's management GUI without a login. The IBE component is supposed to confine any file operations it performs to a safe, designated directory. CVE-2026-104286 breaks that confinement: an attacker appends repeated ../ directory traversal sequences to a request, walking the file-write operation back out of the sandboxed folder and into arbitrary locations on the underlying filesystem.
Defeating the filename check with a NULL byte
Directory traversal alone is often caught by filename validation logic that rejects suspicious paths. Here, the second half of the bug — improper neutralization of a NULL character — lets the attacker smuggle a NULL byte into the crafted filename. Many filename-validation routines treat a NULL byte as a string terminator, so the validator inspects only the portion of the string before the NULL and approves it, while the underlying file-write operation processes the full, unterminated string. The combination lets a specially crafted HTTP or HTTPS request land a file anywhere the FortiMail process has write access — with no credentials, VPN foothold, or prior compromise required.
From file write to system compromise
An arbitrary file write on its own is dangerous; chained against a mail security appliance sitting in the inbound and outbound mail path, it is severe. Writing to the right location — a library loaded by a system process, a preload configuration, or a binary in a trusted system directory — converts the primitive into persistent code execution.
Exploitation in the Wild
Fortinet and third-party researchers have published indicators of compromise consistent with hands-on-keyboard post-exploitation activity rather than opportunistic scanning:
| Indicator Type | Details |
|---|---|
| Outbound C2 IP addresses | 79.141.169.187 and 45.129.0.192 |
| Library preload hijack | Modified /data/lib/liblog.so, used to hijack process library loading |
| Persistence artifact | Attacker-modified /data/etc/ld.so.preload |
| Dropped binaries | Files named smit, webconsole, and mailservice planted in standard system directories |
| Data exfiltration | Archived mail data transferred off compromised appliances via FTP or SFTP to attacker infrastructure |
| Attack surface | POST requests to the IBE endpoint carrying ../ traversal sequences |
The pattern — library hijacking plus renamed system-looking binaries plus outbound exfiltration — indicates attackers are using the file-write primitive not just to probe FortiMail, but to establish durable footholds and pull mail contents and credentials off the appliance before defenders notice.
Affected Versions and Fix Status
| FortiMail Branch | Affected Versions | Fixed Build |
|---|---|---|
| 8.0 | 8.0.0 – 8.0.1 | 8.0.2 (not yet released) |
| 7.6 | 7.6.0 – 7.6.6 | 7.6.7 (not yet released) |
| 7.4 | 7.4.0 – 7.4.8 | 7.4.9 (not yet released) |
| 7.2 | 7.2.0 – 7.2.9 | No fix planned — upgrade to 7.4 or later |
Every supported FortiMail branch at the time of disclosure is affected. Administrators should treat the 7.4.9, 7.6.7, and 8.0.2 build numbers as the ones to watch for and apply the moment Fortinet publishes them, since none were available as of this writing.
Impact Assessment
| Impact Area | Description |
|---|---|
| Confidentiality | Arbitrary file write enables credential theft and bulk exfiltration of stored and in-transit mail |
| Integrity | Attackers have modified system libraries and planted unauthorized binaries, undermining trust in the appliance's software state |
| Availability | A compromised FortiMail sits directly in the mail flow path; tampering can disrupt, delay, or silently redirect organizational email |
| Perimeter Exposure | FortiMail is typically internet-facing by design, making an unauthenticated bug a direct bridge from the public internet into internal mail infrastructure |
| Regulatory/Federal Urgency | CISA's same-day KEV addition and BOD 26-04 deadline reflect confirmed active exploitation, not theoretical risk |
Recommendations
For FortiMail administrators (immediate, today)
- Disable Identity-Based Encryption (IBE) support on every FortiMail instance until a patch is available — this directly removes the vulnerable code path.
- Restrict access to the FortiMail management interface so it is reachable only from trusted internal networks, not the open internet.
- Inventory every FortiMail deployment and version across the organization; do not assume a single appliance represents the whole footprint.
- Plan the upgrade path now for 7.4.9, 7.6.7, or 8.0.2, and for FortiMail 7.2.x specifically, budget for migration to the 7.4 branch or later since no fix is planned for 7.2.
For security teams
- Hunt for the published indicators of compromise: outbound connections to
79.141.169.187and45.129.0.192, unexpected modifications to/data/lib/liblog.soor/data/etc/ld.so.preload, and unfamiliar binaries namedsmit,webconsole, ormailservice. - Review outbound FTP/SFTP traffic from mail appliances for signs of mail archive exfiltration to unrecognized destinations.
- Treat any confirmed compromise as a credential-reset event — assume mail contents and any stored credentials on the appliance may have been exposed.
- Deploy a WAF or reverse-proxy rule blocking requests to the IBE endpoint that contain
../traversal sequences as an interim compensating control.
For end users and IT leadership
- Expect temporary friction if IBE is disabled — encrypted-mail workflows that depend on it will be unavailable until Fortinet ships a fix and the feature is safely re-enabled.
- Escalate patching this specific CVE above routine vulnerability-management cadence given confirmed in-the-wild exploitation and KEV status.
- Communicate to stakeholders that a perimeter mail security appliance, not just an internal workstation, may be the entry point in this incident class.
Key Takeaways
- CVE-2026-104286 is a CVSS 9.8 critical, unauthenticated path traversal and NULL-byte flaw in FortiMail's Identity-Based Encryption component, allowing arbitrary file writes.
- Exploitation in the wild was confirmed before a patch existed — Fortinet's FG-IR-26-175 advisory and CISA's KEV addition both landed on October 1, 2026, with no fixed build yet available for any branch.
- All four supported branches (7.2, 7.4, 7.6, 8.0) are affected; fixes are planned as 7.4.9, 7.6.7, and 8.0.2, while 7.2.x has no planned fix and requires migration.
- Published indicators of compromise include two attacker-controlled IPs, a hijacked library preload mechanism, and renamed system binaries used for persistence and mail exfiltration.
- Disabling IBE and restricting management-interface access are the only current defenses — there is no "just patch it" option yet.
- CISA's compressed federal remediation deadline under BOD 26-04 signals this is being treated as an active, urgent incident, not a routine advisory, and private-sector organizations should match that urgency.