CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

FortiMail, path traversal zero-day (CVSS 9.8), exploited, in CISA KEV, no patch, mitigation only

cve · CVE-2026-104286 single-source

Coverage
1
first 2026-10-02 → last 2026-10-02
Latest activity
2026-10-02
Fortinet confirms exploitation of an unauthenticated FortiMail file-write flaw; no branch has a fixed build…
Peak priority
critical
1 critical
Targets
public-sector
sectors: public-sector, technology
Sources cited
3
3 hosts

Action items (3)

Do-now tasks recorded on the entries about CVE-2026-104286, newest first. Check the date before acting on an older one.

  • Immediate action: Fortinet reports in-the-wild exploitation of an unauthenticated file-write flaw in FortiMail and has not yet shipped a fixed build for 7.4, 7.6 or 8.0. Disable IBE support with the vendor's CLI command or take the management interface off the internet today, and check every appliance that was reachable against the compromise artifacts in advisory FG-IR-26-175.
    2026-10-02CVE-2026-104286
  • On every FortiMail on 7.2, 7.4, 7.6 or 8.0, disable IBE support (config system encryption ibe, set status disable) or remove internet access to the management interface now; no fixed build exists for 7.4, 7.6 or 8.0, and 7.2 must move to 7.4 or above once a fixed 7.4 build ships.
    2026-10-02CVE-2026-104286
  • Check every FortiMail that was internet-reachable before the workaround against the file, cron and CLI-audit artifacts published in FG-IR-26-175, including a mail archive account that sends to a remote host.
    2026-10-02CVE-2026-104286

Defender insights

What each entry about CVE-2026-104286 tells a defender to do, newest first.

2026-10-02CRITICALexploitedFortinet confirms exploitation of an unauthenticated FortiMail file-write flaw; no branch has a fixed build yet

Detection

Story timeline

  1. 2026-10-02CVE-2026-104286, Fortinet FortiMail: unauthenticated path traversal file write exploited as a zero-day, no fixed build yet (CVSS 9.8)
    trending-vulnerabilitiesFortinet confirms exploitation of an unauthenticated FortiMail file-write flaw; no branch has a fixed build yet
ATT&CK techniques (5 across 6 tactics)

5 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessExploit Public-Facing Application
  • ExecutionScheduled Task/Job: Cron · Hijack Execution Flow: Dynamic Linker Hijacking
  • PersistenceScheduled Task/Job: Cron · Compromise Host Software Binary
  • Privilege EscalationScheduled Task/Job: Cron
  • StealthHijack Execution Flow: Dynamic Linker Hijacking
  • CollectionEmail Collection

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-10-02/cve-2026-104286-fortimail-path-traversal-zero-day-kev · ATT&CK page ↗

Execution TA0002

T1053.003Scheduled Task/Job: Cron×1

Adversaries may abuse the <code>cron</code> utility to perform task scheduling for initial or recurring execution of malicious code. The <code>cron</code> utility is a time-based job scheduler for Unix-like operating systems. The <code> crontab</code> file contains the schedule of cron entries to be run and the specified times for execution. Any <code>crontab</code> files are stored in operating system-specific file paths.

Evidence: 2026-10-02/cve-2026-104286-fortimail-path-traversal-zero-day-kev · ATT&CK page ↗

T1574.006Hijack Execution Flow: Dynamic Linker Hijacking×1

Adversaries may execute their own malicious payloads by hijacking environment variables the dynamic linker uses to load shared libraries. During the execution preparation phase of a program, the dynamic linker loads specified absolute paths of shared libraries from various environment variables and files, such as <code>LD_PRELOAD</code> on Linux or <code>DYLD_INSERT_LIBRARIES</code> on macOS. Libraries specified in environment variables are loaded first, taking precedence over system libraries with the same function name. Each platform's linker uses an extensive list of environment variables at different points in execution. These variables are often used by developers to debug binaries without needing to recompile, deconflict mapped symbols, and implement custom functions in the original library.

Evidence: 2026-10-02/cve-2026-104286-fortimail-path-traversal-zero-day-kev · ATT&CK page ↗

Persistence TA0003

T1053.003Scheduled Task/Job: Cron×1

Adversaries may abuse the <code>cron</code> utility to perform task scheduling for initial or recurring execution of malicious code. The <code>cron</code> utility is a time-based job scheduler for Unix-like operating systems. The <code> crontab</code> file contains the schedule of cron entries to be run and the specified times for execution. Any <code>crontab</code> files are stored in operating system-specific file paths.

Evidence: 2026-10-02/cve-2026-104286-fortimail-path-traversal-zero-day-kev · ATT&CK page ↗

T1554Compromise Host Software Binary×1

Adversaries may modify host software binaries to establish persistent access to systems. Software binaries/executables provide a wide range of system commands or services, programs, and libraries. Common software binaries are SSH clients, FTP clients, email clients, web browsers, and many other user or server applications.

Evidence: 2026-10-02/cve-2026-104286-fortimail-path-traversal-zero-day-kev · ATT&CK page ↗

Privilege Escalation TA0004

T1053.003Scheduled Task/Job: Cron×1

Adversaries may abuse the <code>cron</code> utility to perform task scheduling for initial or recurring execution of malicious code. The <code>cron</code> utility is a time-based job scheduler for Unix-like operating systems. The <code> crontab</code> file contains the schedule of cron entries to be run and the specified times for execution. Any <code>crontab</code> files are stored in operating system-specific file paths.

Evidence: 2026-10-02/cve-2026-104286-fortimail-path-traversal-zero-day-kev · ATT&CK page ↗

Stealth TA0005

T1574.006Hijack Execution Flow: Dynamic Linker Hijacking×1

Adversaries may execute their own malicious payloads by hijacking environment variables the dynamic linker uses to load shared libraries. During the execution preparation phase of a program, the dynamic linker loads specified absolute paths of shared libraries from various environment variables and files, such as <code>LD_PRELOAD</code> on Linux or <code>DYLD_INSERT_LIBRARIES</code> on macOS. Libraries specified in environment variables are loaded first, taking precedence over system libraries with the same function name. Each platform's linker uses an extensive list of environment variables at different points in execution. These variables are often used by developers to debug binaries without needing to recompile, deconflict mapped symbols, and implement custom functions in the original library.

Evidence: 2026-10-02/cve-2026-104286-fortimail-path-traversal-zero-day-kev · ATT&CK page ↗

Collection TA0009

T1114Email Collection×1

Adversaries may target user email to collect sensitive information. Emails may contain sensitive data, including trade secrets or personal information, that can prove valuable to adversaries. Emails may also contain details of ongoing incident response operations, which may allow adversaries to adjust their techniques in order to maintain persistence or evade defenses. Adversaries can collect or forward email from mail servers or clients.

Evidence: 2026-10-02/cve-2026-104286-fortimail-path-traversal-zero-day-kev · ATT&CK page ↗

Entries about FortiMail, path traversal zero-day (CVSS 9.8), exploited, in CISA KEV, no patch, mitigation only (1)

2026-10-02 · view entry permalink →

CRITICALCVE-2026-104286exploitedNATOA2

CVE-2026-104286, Fortinet FortiMail: unauthenticated path traversal file write exploited as a zero-day, no fixed build yet (CVSS 9.8)

Fortinet published advisory FG-IR-26-175 on 2026-10-01 for CVE-2026-104286, a path traversal combined with improper neutralization of a NULL byte in FortiMail that may let an unauthenticated attacker write arbitrary files on the underlying system through crafted HTTP or HTTPS requests (Fortinet PSIRT, 2026-10-01). Fortinet says the flaw "has been reported to be exploited in the wild" (Fortinet PSIRT, 2026-10-01), its own product-security team found it, and BleepingComputer reports a CVSS score of 9.8 and a flaw in the management interface (BleepingComputer, 2026-10-01). CISA added the CVE to its KEV catalog on 2026-10-01 (CISA KEV, 2026-10-01). No source names an actor, a victim count or when exploitation began.

Affected are FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8 and 7.2.0 through 7.2.9; the advisory lists 8.0.2, 7.6.7 and 7.4.9 as upcoming fixes and tells 7.2 users to move to branch 7.4 or above, and no fix is listed as of 2026-10-02 (Fortinet PSIRT, 2026-10-01); BleepingComputer reads the 7.2 row as a patch by upgrading to the 7.4 branch or later, but 7.4.0 through 7.4.8 are themselves affected, so Fortinet's table is followed here (BleepingComputer, 2026-10-01). The workarounds are to disable IBE feature support with a CLI command, or to disable internet access to the management interface or limit it to trusted private networks (Fortinet PSIRT, 2026-10-01).

Fortinet's compromise section shows what exploitation left behind: a shared library added under the appliance's data partition with an ld.so.preload entry, a modified system binary, added service binaries, a modified web server configuration and a modified admin-migration archive; a cron job launched from the migration directory; an admin CLI session that added a mail archive account sending to a remote host; and IBE decrypter exceptions for invalid Base64 input plus failed internal-user logins (Fortinet PSIRT, 2026-10-01). BleepingComputer reads the archive account as a possible path to send archived data to a remote server (BleepingComputer, 2026-10-01).

Exposure: every FortiMail on the four listed branches; the vendor's two workarounds point to the IBE feature and the management interface as the reachable surface, so whether either is exposed to the internet is the first check (Fortinet PSIRT, 2026-10-01).

This has been reported to be exploited in the wild, customers are urged to apply the workaround below.

Disable the IBE feature support using the following CLI command:

Fortinet PSIRT (FG-IR-26-175) 2026-10-01

For affected FortiMail 7.4, 7.6, and 8.0 installations, security updates are not yet available

BleepingComputer 2026-10-01
vulnerability02 Oct 04:44Zsingle-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Vulns1

Source distribution

  • bleepingcomputer.com1 (33%)
  • cisa.gov1 (33%)
  • fortiguard.com1 (33%)