CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →
← Back to the live brief
CRITICALCVE-2026-104286exploitedNATOA2vulnerability

CVE-2026-104286, Fortinet FortiMail: unauthenticated path traversal file write exploited as a zero-day, no fixed build yet (CVSS 9.8)

Fortinet confirms exploitation of an unauthenticated FortiMail file-write flaw; no branch has a fixed build yet

Defender actions

  • On every FortiMail on 7.2, 7.4, 7.6 or 8.0, disable IBE support (config system encryption ibe, set status disable) or remove internet access to the management interface now; no fixed build exists for 7.4, 7.6 or 8.0, and 7.2 must move to 7.4 or above once a fixed 7.4 build ships.
  • Check every FortiMail that was internet-reachable before the workaround against the file, cron and CLI-audit artifacts published in FG-IR-26-175, including a mail archive account that sends to a remote host.

Analysis

Fortinet published advisory FG-IR-26-175 on 2026-10-01 for CVE-2026-104286, a path traversal combined with improper neutralization of a NULL byte in FortiMail that may let an unauthenticated attacker write arbitrary files on the underlying system through crafted HTTP or HTTPS requests (Fortinet PSIRT, 2026-10-01). Fortinet says the flaw "has been reported to be exploited in the wild" (Fortinet PSIRT, 2026-10-01), its own product-security team found it, and BleepingComputer reports a CVSS score of 9.8 and a flaw in the management interface (BleepingComputer, 2026-10-01). CISA added the CVE to its KEV catalog on 2026-10-01 (CISA KEV, 2026-10-01). No source names an actor, a victim count or when exploitation began.

Affected are FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8 and 7.2.0 through 7.2.9; the advisory lists 8.0.2, 7.6.7 and 7.4.9 as upcoming fixes and tells 7.2 users to move to branch 7.4 or above, and no fix is listed as of 2026-10-02 (Fortinet PSIRT, 2026-10-01); BleepingComputer reads the 7.2 row as a patch by upgrading to the 7.4 branch or later, but 7.4.0 through 7.4.8 are themselves affected, so Fortinet's table is followed here (BleepingComputer, 2026-10-01). The workarounds are to disable IBE feature support with a CLI command, or to disable internet access to the management interface or limit it to trusted private networks (Fortinet PSIRT, 2026-10-01).

Fortinet's compromise section shows what exploitation left behind: a shared library added under the appliance's data partition with an ld.so.preload entry, a modified system binary, added service binaries, a modified web server configuration and a modified admin-migration archive; a cron job launched from the migration directory; an admin CLI session that added a mail archive account sending to a remote host; and IBE decrypter exceptions for invalid Base64 input plus failed internal-user logins (Fortinet PSIRT, 2026-10-01). BleepingComputer reads the archive account as a possible path to send archived data to a remote server (BleepingComputer, 2026-10-01).

Exposure: every FortiMail on the four listed branches; the vendor's two workarounds point to the IBE feature and the management interface as the reachable surface, so whether either is exposed to the internet is the first check (Fortinet PSIRT, 2026-10-01).

Cited evidence

This has been reported to be exploited in the wild, customers are urged to apply the workaround below.

Disable the IBE feature support using the following CLI command:

Fortinet PSIRT (FG-IR-26-175) 2026-10-01

For affected FortiMail 7.4, 7.6, and 8.0 installations, security updates are not yet available

BleepingComputer 2026-10-01

Sources3

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.