CVE-2026-104286 is a critical path traversal in Fortinet FortiMail. An unauthenticated attacker can write arbitrary files on the underlying system with crafted HTTP or HTTPS requests. Fortinet scores it 9.8.
Fortinet advisory FG-IR-26-175 says the bug has been exploited in the wild. CISA added it to the KEV catalog on 1 October 2026 and set a federal due date of 4 October. That date has passed. The KEV entry also calls for forensic triage, not a patch-and-forget response.
What happened
The weakness is improper limitation of a path to a restricted directory. A remote attacker who can reach the FortiMail web interface does not need an account. Version ranges in the CVE record include 7.0.0 through 7.0.9, 7.2.0 through 7.2.9, 7.4.0 through 7.4.6, 7.6.0 through 7.6.5, and 8.0.0. Later description text also lists builds through 7.4.8, 7.6.6, and 8.0.1. Use the Fortinet advisory as the version source of truth.
Fixed releases were still listed as upcoming in early October reporting. Do not describe a version as patched unless FG-IR-26-175 says it is.
Who is affected
Any organisation with FortiMail in those ranges, especially if the HTTP or HTTPS management or web interface is reachable from untrusted networks. Email gateways sit on the path of every inbound message, so a file-write bug here is an edge compromise, not a workstation issue.
What to do now
- Apply the workaround in Fortinet FG-IR-26-175 today, and remove public access to the FortiMail web interface.
- If the workaround cannot be applied, restrict the interface to management networks or take it offline.
- Treat exposed appliances as potentially compromised. Hunt for unexpected files and config changes, then rebuild if you cannot prove integrity.
- Re-check the advisory for a fixed build before the next maintenance window and install it as soon as Fortinet ships it.
Source: Fortinet CVE record and the CISA KEV catalog entry for CVE-2026-104286. Read the KEV entry.
Also on the blog
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.