What is CVE-2026-104286?
A Path Traversal vulnerability in Fortinet FortiMail is a weakness in how the product’s web management interface handles file paths and null bytes inside incoming HTTP or HTTPS requests. An attacker who does not need to log in can send a crafted request that tricks FortiMail into writing a file outside its intended folder.
By placing a file onto the underlying system, the attacker gains a way to run commands on the device itself. This can lead to full control of the mail gateway, exposing stored mail, credentials, and other systems it connects to.
| CVE | Description | CVSS | Exploited in the wild |
|---|---|---|---|
| CVE-2026-104286 | Path Traversal in Fortinet FortiMail | 9.8 Critical (CVSS 3.1) | Yes |
Is CVE-2026-104286 being exploited in the wild?
CVE-2026-104286 is being exploited in the wild, as reported by CISA, which added it to its Known Exploited Vulnerabilities catalog on October 1, 2026.
How did CVE-2026-104286 come to light?
Fortinet’s own Product Security team identified the vulnerability internally, crediting Gwendal Guegniaud with the finding, and published advisory FG-IR-26-175 on October 1, 2026.
How is watchTowr helping Fortinet FortiMail customers?
- Adversary Sight engine identified Fortinet FortiMail instances across client environments and assessed exposure.
- Rapid Reaction identified exposure to this vulnerability across the watchTowr client base, giving teams the time they need to act.
What is Fortinet FortiMail?
Fortinet FortiMail is a secure email gateway appliance that filters inbound and outbound mail for spam, malware, and data loss, often sitting at the edge of an organization’s network to protect its mail flow.
Which Fortinet FortiMail versions are affected?
| Product | Affected Versions | Fixed Version |
|---|---|---|
| FortiMail 8.0 | 8.0.0 through 8.0.1 | Not yet available |
| FortiMail 7.6 | 7.6.0 through 7.6.6 | Not yet available |
| FortiMail 7.4 | 7.4.0 through 7.4.8 | Not yet available |
| FortiMail 7.2 | 7.2.0 through 7.2.9 | Not yet available |
- The vulnerability affects FortiMail’s web-based management interface, which an attacker can reach without any account.
- Fortinet’s workaround targets the Identity-Based Encryption feature, suggesting the vulnerable code path runs through it.
- Deployments that expose the FortiMail management interface to the internet are directly reachable by remote attackers.
Deployments where the FortiMail management interface is reachable from the internet, especially with Identity-Based Encryption enabled, should be addressed first, since Fortinet’s advisory treats this as the most likely attack path.
How do I fix CVE-2026-104286?
No fixed version was available when Fortinet published its advisory, so administrators should apply the workaround right away: disable the Identity-Based Encryption feature or block internet access to the management interface. Install the fixed build for each branch once Fortinet releases it.
- Preserve logs, configuration backups, and forensic images from every FortiMail appliance before making changes.
- Compare each appliance against Fortinet’s published indicators of compromise, including listed files, hashes, and attacker IP addresses.
- Disable the Identity-Based Encryption feature using Fortinet’s CLI command, or restrict the management interface to trusted networks only.
- Monitor Fortinet’s advisory for the fixed release of each branch and install it once available.
- Rotate administrative credentials and review accounts for unauthorized changes after remediation.
How do I check Fortinet FortiMail for compromise?
Fortinet’s advisory lists specific indicators of compromise, including suspicious files, unusual log entries, and attacker IP addresses that administrators can compare against their own FortiMail systems to check for signs of compromise.
What types of threat actors typically exploit this vulnerability?
No attribution has been made public.
