CVE-2026-104286: FortiMail path traversal, no patch yet
Unauthenticated arbitrary file write on FortiMail with IBE enabled

CVE-2026-104286: FortiMail path traversal, no patch yet

Fortinet and CISA warned on 1 October 2026 that CVE-2026-104286 is being exploited. It is a critical path-traversal flaw, CVSS 9.8, that lets an unauthenticated attacker write arbitrary files on a FortiMail system with crafted HTTP or HTTPS requests. Fixed releases were not available when the advisory went out.

What happened

Fortinet PSIRT advisory FG-IR-26-175 describes a path traversal plus improper NULL-byte handling. The company says the bug can lead to unauthorized code or command execution, marks it as exploited, and published indicators of compromise. CISA put it on the KEV catalog the same day, with a federal due date of 4 October and forensic triage required.

Public reporting places the vulnerable path in the Identity-Based Encryption feature, not in ordinary SMTP. The management interface has to be reachable for the request to land.

Who is affected

  • FortiMail 8.0.0 through 8.0.1. Fix is upcoming 8.0.2 or above.
  • FortiMail 7.6.0 through 7.6.6. Fix is upcoming 7.6.7 or above.
  • FortiMail 7.4.0 through 7.4.8. Fix is upcoming 7.4.9 or above.
  • FortiMail 7.2.0 through 7.2.9. Fortinet points this branch to 7.4 or above.

What to do now

Disable IBE or take the management interface off the internet, then hunt the Fortinet IoCs before you trust the box. The CLI workaround is config system encryption ibe, then set status disable. Disabling IBE stops the secure-message portal until you turn it back on. Neither workaround removes an attacker who is already on the appliance. Watch for unexpected files under data and bin paths, a malicious ld.so.preload, and a changed httpd.conf, as described in the vendor write-up.

Source: SecurityWeek, Exploited Fortinet FortiMail zero-day calls for urgent action. Vendor advisory: FG-IR-26-175.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

ShinyHunters suspect Rey detained in Jordan, sources say
Reuters: Saif al-Din Khader held 29 September, reportedly aiding FBI