Fortinet FortiMail Path-Traversal Flaw Exploited Before Fixes Ship
Security / news
Fortinet FortiMail Path-Traversal Flaw Exploited Before Fixes Ship
CVE-2026-104286 lets an unauthenticated attacker write files to a FortiMail appliance, and one analyst reading of Fortinet's advisory says the patched builds may not be downloadable yet.
A path-traversal flaw in Fortinet's FortiMail email gateway, CVE-2026-104286, is being exploited in the wild, and an unauthenticated attacker can use it to write arbitrary files to the appliance over HTTP or HTTPS. Fortinet rates it 9.8 out of 10 on the CVSS severity scale.
Fortinet published advisory FG-IR-26-175 on Oct. 1, 2026, and CISA added the flaw to its Known Exploited Vulnerabilities catalog the same day, citing evidence of active exploitation.
What the advisory says
The advisory classifies the bug as path traversal (CWE-22) combined with improper neutralization of a NULL byte (CWE-158). Rapid7's database entry gives the vector as CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H: reachable over the network, low complexity, no privileges, no user interaction. The advisory lists the discovery as internal to Fortinet, so no outside researcher is credited.
An arbitrary file write is not itself code execution. Fortinet rates the flaw critical because an attacker who can overwrite binaries and configuration on the box can get there.
| Branch | Affected | Fixed in |
|---|---|---|
| 8.0 | 8.0.0 to 8.0.1 | 8.0.2 |
| 7.6 | 7.6.0 to 7.6.6 | 7.6.7 |
| 7.4 | 7.4.0 to 7.4.8 | 7.4.9 |
| 7.2 | 7.2.0 to 7.2.9 | No 7.2 fix; migrate |
The 7.2 branch has no patch of its own. Because 7.4.0 through 7.4.8 are also affected, moving a 7.2 appliance to an older 7.4 build does not close the hole; it has to reach 7.4.9 or later.
The fixed builds may not be out
The advisory names the fixed versions, but the analyst write-up from Suped cautions that "operators should not plan a maintenance window on the assumption that these builds are already downloadable." That is Suped's reading, not a quote from Fortinet, and The Terminal could not check Fortinet's download portal. Confirm the build exists before scheduling downtime.
Until then Fortinet's workarounds are to disable Identity-Based Encryption (IBE) support from the command line, and to restrict the management interface to trusted private networks. GBHackers reports that no virtual patch is available. The exact CLI syntax differs between the advisory and the secondary write-ups, so copy it from the advisory itself.
Indicators of compromise
The advisory lists files that attackers modified or planted:
- /data/lib/liblog.so
- /data/bin/webconsole and /data/bin/mailservice
- /data/etc/ld.so.preload and /data/etc/httpd.conf
- /bin/smit and /data/migadmin.tar.gz
It also lists two source addresses, 79.141.169.187 and 45.129.0.192. A modified ld.so.preload is a persistence trick, because it loads a library into every process that starts. Nobody has named the actor, and the sources do not say how many appliances were compromised.
Dates differ by one day between sources. Fortinet's advisory and Rapid7 give Oct. 1 for publication; GBHackers says Oct. 2. Suped puts the CISA due date for federal agencies at Oct. 4, three days after the listing.
The sequence for an administrator is short: check for the files and addresses above, disable IBE, take the management interface off the internet, and install 8.0.2, 7.6.7 or 7.4.9 once the build is confirmed. Related reading on CISA-listed flaws: Johnson Controls EasyIO Neo and the Armadin Series B, a security startup that raised $255.5 million.
Sources
More in Security
- 01Citrix Confirms Two NetScaler Zero-Days Exploited Since Early SeptemberPalo Alto Networks' Unit 42 traces exploitation of CVE-2026-88771 and CVE-2026-88772 to Sept. 4, 23 days before Citrix published its bulletin, and says patching will not evict an attacker who is already inside.
- 02Cisco SD-WAN Manager Auth Bypass Exploited, With No WorkaroundCVE-2026-76504 gives an unauthenticated attacker admin access to the Catalyst SD-WAN Manager API, and Cisco's only advice besides patching is to keep the interface off untrusted networks.
- 03Three Exploited Edge Flaws Test CISA's Three-Day Patch DeadlineCitrix, Cisco and Fortinet appliances landed in the Known Exploited Vulnerabilities catalog within five days, and BOD 26-04 asks agencies to collect evidence before they patch any of them.
- 04Monta's EV Charging Platform Has No Patch for a 9.4 Authentication GapCISA lists four flaws in monta.app, all versions. The vendor points operators to an optional OCPP security profile and has shipped no fix.