FortiMail CVE-2026-104286: Critical Flaw Exploited, Patch Now

CISA confirms active exploitation of a critical, unauthenticated FortiMail path traversal flaw and gives federal agencies until October 4 to patch or mitigate.

Fortinet email and workspace security product graphic representing FortiMail
Fortinet's email and workspace security graphic. Image: Fortinet.

CISA added CVE-2026-104286 — a critical path traversal flaw in Fortinet's FortiMail secure email gateway — to its Known Exploited Vulnerabilities (KEV) catalog on October 1, 2026, citing confirmed real-world attacks. Fortinet's own advisory, FG-IR-26-175, rates the bug 9.8 (Critical) and confirms it lets an unauthenticated attacker write arbitrary files to a vulnerable FortiMail appliance over a crafted HTTP or HTTPS request. If you run FortiMail, the short version is: patch to 8.0.2, 7.6.7, 7.4.9 or later (7.2.x has no fix and must move to 7.4 or newer), or, if you cannot patch immediately, disable the IBE feature via the CLI and lock the management interface down to a trusted network today. Federal civilian agencies have until October 4, 2026 to remediate under CISA's Binding Operational Directive 26-04.

FortiMail sits at the edge of an organization's email flow, inspecting, relaying and archiving messages for the business behind it — which is exactly why an unauthenticated file-write bug on the appliance is so dangerous. Fortinet says it discovered the issue internally, has evidence of active exploitation, and has already published indicators of compromise for defenders to hunt with.

Quick facts

  • CVE: CVE-2026-104286 (CWE-22 path traversal + CWE-158 improper NULL byte handling)
  • CVSS: 9.8 Critical, unauthenticated, GUI component
  • Affected product: Fortinet FortiMail secure email gateway, branches 8.0, 7.6, 7.4 and 7.2
  • Fixed in: 8.0.2+, 7.6.7+, 7.4.9+ (7.2.x: upgrade to 7.4 branch or later — no 7.2 patch)
  • Added to CISA KEV: October 1, 2026
  • Federal patch deadline: October 4, 2026 (CISA Binding Operational Directive 26-04)
  • Workaround if you can't patch yet: disable IBE via CLI, or restrict management-interface access to trusted networks

What happened

Fortinet's Product Security Incident Response Team published advisory FG-IR-26-175 on October 1, 2026, describing an "Improper Limitation of a Pathname to a Restricted Directory" vulnerability — classic path traversal — combined with improper handling of NULL byte characters in FortiMail. The advisory states plainly that the bug "has been reported to be exploited in the wild," and urges customers to apply the workaround immediately while patched builds roll out. The same day, CISA added CVE-2026-104286 to its Known Exploited Vulnerabilities catalog, the agency's running list of flaws it has direct evidence are being abused in active attacks, not just theoretically exploitable ones.

That KEV listing matters beyond the federal government it technically binds. It's the clearest public signal from the U.S. government's own threat-intel apparatus that a specific, named vulnerability is not hypothetical — someone, somewhere, is already using it to break into real systems. For FortiMail administrators, that's the difference between "patch in the next maintenance window" and "patch this weekend." It's also the second Fortinet-adjacent edge-security incident security teams have had to deal with in short order; Pandromeda previously covered a related wave of attacks in the ongoing campaign against internet-exposed MikroTik routers, a reminder that unauthenticated bugs in perimeter appliances remain one of the most reliably exploited categories of vulnerability in 2026.

Why a bug in an email gateway is such a high-value target

FortiMail is Fortinet's dedicated secure email gateway (SEG) — appliances and virtual machines that sit in front of an organization's mail flow to filter spam, phishing, malware and business email compromise attempts before messages reach inboxes, and to apply outbound data-loss-prevention and encryption policy on the way out. That position in the network is valuable to attackers for two reasons. First, FortiMail appliances are almost always internet-facing by design, since they have to receive mail from the outside world, which puts their management and processing surfaces within reach of anyone scanning the internet. Second, a gateway that already touches every email flowing through an organization is an extremely effective place to sit if your goal is surveillance, credential theft, or planting a foothold that looks like normal mail infrastructure rather than an obvious intrusion.

That combination — unauthenticated, internet-facing, and sitting on a sensitive data path — is the same pattern behind nearly every vulnerability that lands on CISA's KEV list within days of disclosure. It's also why FortiMail's own job description, blocking the exact kind of social-engineering attacks covered in Pandromeda's guide to spotting phishing emails, makes a compromise of the gateway itself especially ironic and especially damaging: an attacker who gains a foothold on the device that is supposed to be stopping malicious mail can potentially manipulate what it lets through, or use its trusted position to send convincing messages that evade filtering elsewhere.

What the vulnerability actually is

According to Fortinet's advisory, CVE-2026-104286 combines two weaknesses: CWE-22 (Improper Limitation of a Pathname to a Restricted Directory, i.e. path traversal) and CWE-158 (Improper Neutralization of NULL Byte or NULL Character). In plain terms, a component of FortiMail's GUI fails to properly sanitize file paths supplied in a request, and also mishandles NULL byte characters that are sometimes used to prematurely terminate a string during that sanitization check. Chained together, those two flaws let an attacker who sends a specially crafted HTTP or HTTPS request walk outside the directory the application intended to restrict them to, and write a file somewhere on the underlying filesystem — all without supplying any credentials.

Fortinet classifies the resulting impact as the ability to "execute unauthorized code or commands," which is the practical ceiling of an unauthenticated arbitrary file write on an appliance like this: dropping or modifying an executable, a configuration file, or a library that the system will later load or run gives an attacker a path to full code execution, not just file-system access. Fortinet credits its own Product Security team, specifically Gwendal Guégniaud, with discovering the issue internally — it was not reported by an outside researcher — and the advisory notes that no official "virtual patch" (an IPS signature that can block exploitation attempts without an upgrade) is currently available, which is part of why Fortinet is pushing the CLI workaround as the stopgap of choice.

Affected and fixed FortiMail versions

FortiMail's advisory lists four affected branches, each with its own fixed release. Every version in the vulnerable ranges below should be treated as exploitable; there is no partial-fix or configuration-dependent carve-out described in the advisory.

FortiMail branchAffected versionsFixed version
8.08.0.0 through 8.0.1Upgrade to 8.0.2 or above
7.67.6.0 through 7.6.6Upgrade to 7.6.7 or above
7.47.4.0 through 7.4.8Upgrade to 7.4.9 or above
7.27.2.0 through 7.2.9No 7.2.x fix — upgrade to branch 7.4 or above

The 7.2 branch is worth flagging separately: Fortinet is not issuing a patched 7.2.x build at all, so any FortiMail deployment still on that branch needs a full version upgrade to 7.4.9 or later (or 7.6.7+/8.0.2+) rather than a routine point-release update. Check your running version under the FortiMail GUI's System Information, or via the CLI with get system status, before deciding which remediation path applies to your deployment.

Why CISA added it to the KEV catalog

CISA's KEV entry for CVE-2026-104286 describes the vulnerability as one that "may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests," and lists the vulnerability name simply as "Fortinet FortiMail Path Traversal Vulnerability." The catalog entry sets a due date of October 4, 2026 — just three days after the addition date — which is on the short end of CISA's usual remediation windows and signals the agency sees this as an urgent, already-active threat rather than a routine disclosure. CISA's required action directs agencies to apply Fortinet's mitigations in line with Binding Operational Directive 26-04, Prioritizing Security Updates Based on Risk, and to follow the directive's forensic-triage requirements — meaning affected systems should be checked for signs of prior compromise, not just patched and left alone.

CISA's own data marks the vulnerability's "known ransomware campaign use" as unknown, meaning there is no confirmed link to a specific ransomware operation at the time of listing — but an unknown link is not the same as a cleared one, and KEV additions have a track record of ransomware groups following not long after.

What Fortinet's indicators of compromise show

Unusually, Fortinet's advisory ships with a concrete set of indicators of compromise (IoCs) rather than a generic "contact support" note, which is itself a sign of how far along the in-the-wild investigation already is. The published IoCs include newly added or modified files on compromised FortiMail systems — among them a new shared library at /data/lib/liblog.so, a modified system binary at /bin/smit, new executables at /data/bin/webconsole and /data/bin/mailservice, a modified /data/etc/httpd.conf, and a newly created /data/etc/ld.so.preload — a file commonly abused to load malicious code into legitimate running processes. Fortinet also published two attacker-associated IP addresses and example log entries, including a suspicious cron job invocation and an admin-level configuration change that added a remote log-archiving account pointed at one of those external IPs.

Defenders with FortiMail in their environment should check for exactly these artifacts as a first step, independent of whether the appliance has been patched yet: their presence indicates likely compromise that a patch alone will not remediate, and would justify the forensic triage CISA's directive calls for rather than a routine update-and-move-on response.

Patch now, or use Fortinet's interim workaround

Fortinet's advisory is explicit that upgrading is the real fix, but it also documents a CLI-based workaround for environments that cannot patch immediately. Disabling the IBE (Identity-Based Encryption) feature closes off the vulnerable code path:

config system encryption
    set ibe status disable
end

As a second, independent layer of mitigation, Fortinet also recommends disabling access to the FortiMail management interface from the internet entirely, or restricting it to a trusted private network only — standard advice for any management-plane service, but doubly important here since the flaw requires no authentication at all. Neither workaround is a substitute for the actual patch; both are stopgaps meant to reduce exposure while an upgrade is scheduled, and Fortinet has not indicated either one fully eliminates risk from other GUI-facing issues that may surface later.

What FortiMail admins should do right now

With active exploitation confirmed and a federal deadline just days away, the practical checklist for anyone running FortiMail looks like this: first, identify your running version against the table above and schedule the upgrade to the fixed release for your branch — 7.2.x administrators should plan for a full branch move to 7.4.9 or later rather than waiting for a same-branch patch that isn't coming. Second, if the upgrade can't happen immediately, apply the IBE-disable CLI workaround and lock down management-interface exposure today, not after the next change window. Third, regardless of patch status, check for Fortinet's published IoCs — the added or modified files and the two listed IP addresses — since a vulnerability already confirmed as actively exploited means some deployments may already be compromised. Fourth, treat this the way CISA's directive frames it: as a forensic-triage event, not a routine patch cycle, if you find any sign of the IoCs or have internet-exposed FortiMail that was running an affected version before today.

Enterprises juggling multiple urgent patches this week aren't alone — Pandromeda's recent coverage of another critical, actively exploited bug added to CISA's KEV catalog in the same stretch is a reminder that KEV-listed vulnerabilities in edge and management infrastructure have been landing in clusters this year, and prioritization matters: patch internet-facing, unauthenticated, KEV-listed bugs first, every time.

What's next

Expect Fortinet to keep updating FG-IR-26-175 as its investigation continues — advisories like this one are frequently revised with additional affected-version detail, new IoCs, or confirmation of the specific threat activity once more is known, so administrators should bookmark the advisory page rather than treat today's version as final. CISA's KEV catalog entry and its October 4 due date apply directly only to U.S. federal civilian agencies, but the KEV catalog functions as a de facto urgency signal for every organization running the affected product, and enterprise security teams commonly adopt the same deadlines internally. Pandromeda will update this story if Fortinet publishes a formal CVSS vector string, additional IoCs, or evidence tying the exploitation to a specific threat actor or campaign; none of that attribution has been confirmed publicly as of this writing, and any claims along those lines should be treated with caution until Fortinet or CISA confirm them directly.

Frequently asked questions

What is CVE-2026-104286?

CVE-2026-104286 is a critical vulnerability in Fortinet's FortiMail secure email gateway combining a path traversal flaw (CWE-22) with improper NULL byte handling (CWE-158). It lets an unauthenticated remote attacker send a crafted HTTP or HTTPS request that writes arbitrary files to the underlying system, which Fortinet says can lead to unauthorized code execution. Fortinet rates it 9.8 (Critical).

Is FortiMail actually being exploited right now?

Yes. Fortinet's own advisory, FG-IR-26-175, states the vulnerability has been reported to be exploited in the wild, and CISA added CVE-2026-104286 to its Known Exploited Vulnerabilities catalog on October 1, 2026 on that basis. Fortinet has also published indicators of compromise, including specific file artifacts and attacker IP addresses, from real incidents it has investigated.

Which FortiMail versions are affected, and what should I upgrade to?

FortiMail 8.0.0 through 8.0.1 should upgrade to 8.0.2 or above; 7.6.0 through 7.6.6 should upgrade to 7.6.7 or above; 7.4.0 through 7.4.8 should upgrade to 7.4.9 or above. FortiMail 7.2.0 through 7.2.9 has no dedicated patch and must be upgraded to the 7.4 branch or newer.

What is CISA's deadline for patching this vulnerability?

CISA set a due date of October 4, 2026 for U.S. federal civilian agencies to remediate CVE-2026-104286, just three days after it was added to the KEV catalog on October 1, 2026, under Binding Operational Directive 26-04.

Is there a workaround if I can't patch FortiMail immediately?

Yes. Fortinet's advisory describes disabling the IBE (Identity-Based Encryption) feature via the CLI command 'config system encryption', 'set ibe status disable', 'end' as a workaround, along with restricting access to the FortiMail management interface to trusted private networks rather than exposing it to the internet. Neither workaround replaces the eventual patch.

How can I check if my FortiMail appliance has already been compromised?

Fortinet's advisory lists indicators of compromise including new or modified files such as /data/lib/liblog.so, /bin/smit, /data/bin/webconsole, /data/bin/mailservice, /data/etc/httpd.conf and /data/etc/ld.so.preload, plus two attacker-associated IP addresses. Administrators should check for these artifacts regardless of patch status and treat any match as a sign of possible compromise requiring forensic triage.

Sources

More on Fortinet FortiMail →FortinetFortiMailCVE-2026-104286CISA KEVEmail Security
Sana Qureshi
Written bySana Qureshi

Sana Qureshi runs the security and privacy desk. She reports on actively exploited vulnerabilities, vendor patches and data breaches, and covers the password managers, VPNs and authentication tools readers use to protect themselves. Her alerts cite vendor advisories, CISA and the CVE record directly.

More from Security & Privacy

See all