Proactive Threat Intelligence from the team that finds the vulnerabilities. We publish what is being exploited right now, who is doing it, and whether it reaches you. No vendor summaries written a week late.

Updated Oct 1, 2026

Frequently Asked Questions About the Fortinet FortiMail Path Traversal (CVE-2026-104286)

Fortinet disclosed a Path Traversal in FortiMail that lets an unauthenticated attacker write files onto the underlying system through crafted web requests. This FAQ explains what is affected, what to do, and is updated as new details emerge.

Status

CVE

CVE-2026-104286

CVSS

9.8 (v3.1)

Exploitation

In The Wild

CISA KEV

Listed

Vendor patch

Mitigation only

Questions

Updates

Key takeaways

What is CVE-2026-104286?

A Path Traversal vulnerability in Fortinet FortiMail is a weakness in how the product’s web management interface handles file paths and null bytes inside incoming HTTP or HTTPS requests. An attacker who does not need to log in can send a crafted request that tricks FortiMail into writing a file outside its intended folder.

By placing a file onto the underlying system, the attacker gains a way to run commands on the device itself. This can lead to full control of the mail gateway, exposing stored mail, credentials, and other systems it connects to.

CVEDescriptionCVSSExploited in the wild
CVE-2026-104286Path Traversal in Fortinet FortiMail9.8 Critical (CVSS 3.1)Yes

Is CVE-2026-104286 being exploited in the wild?

CVE-2026-104286 is being exploited in the wild, as reported by CISA, which added it to its Known Exploited Vulnerabilities catalog on October 1, 2026.

How did CVE-2026-104286 come to light?

Fortinet’s own Product Security team identified the vulnerability internally, crediting Gwendal Guegniaud with the finding, and published advisory FG-IR-26-175 on October 1, 2026.

How is watchTowr helping Fortinet FortiMail customers?

  • Adversary Sight engine identified Fortinet FortiMail instances across client environments and assessed exposure.
  • Rapid Reaction identified exposure to this vulnerability across the watchTowr client base, giving teams the time they need to act.

What is Fortinet FortiMail?

Fortinet FortiMail is a secure email gateway appliance that filters inbound and outbound mail for spam, malware, and data loss, often sitting at the edge of an organization’s network to protect its mail flow.

Which Fortinet FortiMail versions are affected?

ProductAffected VersionsFixed Version
FortiMail 8.08.0.0 through 8.0.1Not yet available
FortiMail 7.67.6.0 through 7.6.6Not yet available
FortiMail 7.47.4.0 through 7.4.8Not yet available
FortiMail 7.27.2.0 through 7.2.9Not yet available
  • The vulnerability affects FortiMail’s web-based management interface, which an attacker can reach without any account.
  • Fortinet’s workaround targets the Identity-Based Encryption feature, suggesting the vulnerable code path runs through it.
  • Deployments that expose the FortiMail management interface to the internet are directly reachable by remote attackers.

Deployments where the FortiMail management interface is reachable from the internet, especially with Identity-Based Encryption enabled, should be addressed first, since Fortinet’s advisory treats this as the most likely attack path.

How do I fix CVE-2026-104286?

No fixed version was available when Fortinet published its advisory, so administrators should apply the workaround right away: disable the Identity-Based Encryption feature or block internet access to the management interface. Install the fixed build for each branch once Fortinet releases it.

  1. Preserve logs, configuration backups, and forensic images from every FortiMail appliance before making changes.
  2. Compare each appliance against Fortinet’s published indicators of compromise, including listed files, hashes, and attacker IP addresses.
  3. Disable the Identity-Based Encryption feature using Fortinet’s CLI command, or restrict the management interface to trusted networks only.
  4. Monitor Fortinet’s advisory for the fixed release of each branch and install it once available.
  5. Rotate administrative credentials and review accounts for unauthorized changes after remediation.

How do I check Fortinet FortiMail for compromise?

Fortinet’s advisory lists specific indicators of compromise, including suspicious files, unusual log entries, and attacker IP addresses that administrators can compare against their own FortiMail systems to check for signs of compromise.

What types of threat actors typically exploit this vulnerability?

No attribution has been made public.

If you are a watchTowr client

Adversary Sight engine identified Fortinet FortiMail instances across client environments and assessed exposure. Rapid Reaction identified exposure to this vulnerability across the watchTowr client base, giving teams the time they need to act. Contact your watchTowr team with any questions.

Want to know if this reaches you, before the next one?

watchTowr validates exposure and mitigates at the edge in under an hour.

Attackers Don't Give Up. Neither Should Your Security Testing.

Zero install. No infrastructure changes. Uplift your security posture within hours of onboarding the watchTowr Platform.

Find Out What an Attacker Can Reach Before They Do.

Point us at a domain. We reconstruct your real external estate and come back with validated exposure, not a theoretical CVE list.

Disclosure to Exploitation Is Four Hours. Patching Is Not.

The watchTowr Platform validates your exposure to an emerging threat and mitigates it at the edge while the vendor patch is still in testing.

We Find the Vulnerabilities. You Hear It From Us First.

watchTowr Labs publishes what is being exploited right now and whether it touches your estate, not vendor summaries written a week late.

Your Exposure Changes Weekly. Annual Testing Cannot Describe It.

Continuous, fully external validation of what an attacker can actually exploit against your estate, at a 0.01% false-positive rate.

See the Estate You Own, Including What No Asset List Holds.

Subsidiaries, forgotten infrastructure, shadow IT. We rebuild your external surface from a single domain, then validate what is exposed.