---
schema: 1
kind: vulnerability
title: "CVE-2026-104286, Fortinet FortiMail: unauthenticated path traversal file write exploited as a zero-day, no fixed build yet (CVSS 9.8)"
headline: "Fortinet confirms exploitation of an unauthenticated FortiMail file-write flaw; no branch has a fixed build yet"
summary: >
  Fortinet's advisory FG-IR-26-175 of 2026-10-01 describes a path traversal in FortiMail that lets an unauthenticated
  attacker write arbitrary files through crafted HTTP or HTTPS requests, and says it has been reported exploited in
  the wild; CISA listed it in KEV the same day. FortiMail 7.4, 7.6 and 8.0 have no fixed build as of 2026-10-02 (8.0.2, 7.6.7 and 7.4.9 are listed as upcoming) and 7.2 users are told to move to 7.4 or above, so no branch has a fix yet and the vendor workarounds are the only control.
discovered_at: "2026-10-02T04:44:00Z"
updated_at: null
event_date: "2026-10-01"
run_id: 2026-10-02T0404Z-intel
priority: critical
immediate_action:
  title: "Apply Fortinet's workaround to every FortiMail now: no fixed build exists for 7.4, 7.6 or 8.0"
  action: >
    Fortinet reports in-the-wild exploitation of an unauthenticated file-write flaw in FortiMail and has not yet
    shipped a fixed build for 7.4, 7.6 or 8.0. Disable IBE support with the vendor's CLI command or take the
    management interface off the internet today, and check every appliance that was reachable against the compromise
    artifacts in advisory FG-IR-26-175.
tags: [vulnerabilities, path-traversal, pre-auth, actively-exploited, cisa-kev, no-patch]
regions: [global]
sectors: [public-sector, technology]
entities: ["product:fortinet-fortimail"]
techniques: [T1190, T1574.006, T1053.003, T1554, T1114]
affected_products: ["Fortinet FortiMail"]
cves:
  - id: CVE-2026-104286
    cvss: "9.8"
    epss: null
    type: path-traversal
    vector: zero-click
    auth: pre-auth
    status: [exploited, cisa-kev, no-patch, mitigation-only]
    affected: "FortiMail 8.0.0 through 8.0.1; 7.6.0 through 7.6.6; 7.4.0 through 7.4.8; 7.2.0 through 7.2.9"
    fixed: "No fixed build released as of 2026-10-02: 8.0.2, 7.6.7 and 7.4.9 are listed as upcoming; FortiMail 7.2 users are told to move to branch 7.4 or above"
sources:
  - url: "https://www.fortiguard.com/psirt/FG-IR-26-175"
    publisher: "Fortinet PSIRT (FG-IR-26-175)"
    date: "2026-10-01"
    role: primary
  - url: "https://www.bleepingcomputer.com/news/security/fortinet-warns-of-critical-fortimail-flaw-exploited-in-zero-day-attacks/"
    publisher: "BleepingComputer"
    date: "2026-10-01"
    role: corroborating
  - url: "https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json"
    publisher: "CISA Known Exploited Vulnerabilities catalog"
    date: "2026-10-01"
    role: corroborating
closed_sources: []
evidence:
  - quote: "This has been reported to be exploited in the wild, customers are urged to apply the workaround below."
    publisher: "Fortinet PSIRT (FG-IR-26-175)"
    source_url: "https://www.fortiguard.com/psirt/FG-IR-26-175"
  - quote: "Disable the IBE feature support using the following CLI command:"
    publisher: "Fortinet PSIRT (FG-IR-26-175)"
    source_url: "https://www.fortiguard.com/psirt/FG-IR-26-175"
  - quote: "For affected FortiMail 7.4, 7.6, and 8.0 installations, security updates are not yet available"
    publisher: "BleepingComputer"
    source_url: "https://www.bleepingcomputer.com/news/security/fortinet-warns-of-critical-fortimail-flaw-exploited-in-zero-day-attacks/"
verification: single-source
sourcing_note: >
  The exploitation statement is Fortinet's own; CISA's KEV listing relies on it and no second telemetry holder has
  published observations. Fortinet gives no actor, victim count or first-exploitation date; BleepingComputer states
  Fortinet declined to say more.
confidence: high
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: A
  credibility: 2
watchlist_hit: false
actions:
  - "On every FortiMail on 7.2, 7.4, 7.6 or 8.0, disable IBE support (config system encryption ibe, set status disable) or remove internet access to the management interface now; no fixed build exists for 7.4, 7.6 or 8.0, and 7.2 must move to 7.4 or above once a fixed 7.4 build ships."
  - "Check every FortiMail that was internet-reachable before the workaround against the file, cron and CLI-audit artifacts published in FG-IR-26-175, including a mail archive account that sends to a remote host."
updates: []
migrated_from: null
---

Fortinet published advisory FG-IR-26-175 on 2026-10-01 for CVE-2026-104286, a path traversal combined with improper neutralization of a NULL byte in FortiMail that may let an unauthenticated attacker write arbitrary files on the underlying system through crafted HTTP or HTTPS requests ([Fortinet PSIRT, 2026-10-01](https://www.fortiguard.com/psirt/FG-IR-26-175)). Fortinet says the flaw "has been reported to be exploited in the wild" ([Fortinet PSIRT, 2026-10-01](https://www.fortiguard.com/psirt/FG-IR-26-175)), its own product-security team found it, and BleepingComputer reports a CVSS score of 9.8 and a flaw in the management interface ([BleepingComputer, 2026-10-01](https://www.bleepingcomputer.com/news/security/fortinet-warns-of-critical-fortimail-flaw-exploited-in-zero-day-attacks/)). CISA added the CVE to its KEV catalog on 2026-10-01 ([CISA KEV, 2026-10-01](https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json)). No source names an actor, a victim count or when exploitation began.

Affected are FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8 and 7.2.0 through 7.2.9; the advisory lists 8.0.2, 7.6.7 and 7.4.9 as upcoming fixes and tells 7.2 users to move to branch 7.4 or above, and no fix is listed as of 2026-10-02 ([Fortinet PSIRT, 2026-10-01](https://www.fortiguard.com/psirt/FG-IR-26-175)); BleepingComputer reads the 7.2 row as a patch by upgrading to the 7.4 branch or later, but 7.4.0 through 7.4.8 are themselves affected, so Fortinet's table is followed here ([BleepingComputer, 2026-10-01](https://www.bleepingcomputer.com/news/security/fortinet-warns-of-critical-fortimail-flaw-exploited-in-zero-day-attacks/)). The workarounds are to disable IBE feature support with a CLI command, or to disable internet access to the management interface or limit it to trusted private networks ([Fortinet PSIRT, 2026-10-01](https://www.fortiguard.com/psirt/FG-IR-26-175)).

Fortinet's compromise section shows what exploitation left behind: a shared library added under the appliance's data partition with an `ld.so.preload` entry, a modified system binary, added service binaries, a modified web server configuration and a modified admin-migration archive; a cron job launched from the migration directory; an admin CLI session that added a mail archive account sending to a remote host; and IBE decrypter exceptions for invalid Base64 input plus failed internal-user logins ([Fortinet PSIRT, 2026-10-01](https://www.fortiguard.com/psirt/FG-IR-26-175)). BleepingComputer reads the archive account as a possible path to send archived data to a remote server ([BleepingComputer, 2026-10-01](https://www.bleepingcomputer.com/news/security/fortinet-warns-of-critical-fortimail-flaw-exploited-in-zero-day-attacks/)).

**Exposure:** every FortiMail on the four listed branches; the vendor's two workarounds point to the IBE feature and the management interface as the reachable surface, so whether either is exposed to the internet is the first check ([Fortinet PSIRT, 2026-10-01](https://www.fortiguard.com/psirt/FG-IR-26-175)).

**Detection:** appliance admin and CLI audit events (a configuration change from the CLI adding an archive account whose destination is a remote host), system-event entries for a cron job launching from the migration directory, IBE decrypter exceptions for invalid Base64 input, and a file-integrity comparison of the data partition against a known-good image for the added library, the `ld.so.preload` entry and the modified binary and web server configuration; Fortinet's advisory lists the exact artifacts and log patterns ([Fortinet PSIRT, 2026-10-01](https://www.fortiguard.com/psirt/FG-IR-26-175)).

**Defender takeaway:** apply a workaround to every FortiMail today because no fixed build exists for 7.4, 7.6 or 8.0, then check each appliance that was reachable before the workaround for Fortinet's artifacts; plan the move to the fixed build as soon as Fortinet ships it.
