Fortinet has disclosed CVE-2026-104286 (PSIRT FG-IR-26-099), a critical (CVSS 9.8) path traversal flaw in FortiMail that is being exploited as a zero-day. CISA added it to the Known Exploited Vulnerabilities catalog on October 1 and gave federal agencies until October 4 to perform forensic triage and mitigate. Fixed builds have not shipped yet for the main release branches.

What happened

The bug is an improper limitation of a pathname to a restricted directory (CWE-22) in the FortiMail web interface. An unauthenticated remote attacker can send crafted HTTP or HTTPS requests that write arbitrary files to the underlying system. Fortinet describes the outcome as execution of unauthorized code or commands, which is the usual consequence of an arbitrary file write on an appliance: dropping a webshell or overwriting a file that a privileged service later loads.

Fortinet says it is coordinating with government agencies, including CISA. At the time of writing, no public detail on the threat actor or campaign scale has been released.

Affected versions

  • FortiMail 8.0.0 through 8.0.1
  • FortiMail 7.6.0 through 7.6.6
  • FortiMail 7.4.0 through 7.4.8
  • FortiMail 7.2.0 through 7.2.9

Fortinet lists 7.4.9, 7.6.7 and 8.0.2 as upcoming fixed releases. There is no fix for the 7.2 branch; customers on 7.2 must migrate to 7.4 or later.

Impact

FortiMail sits in the mail path of many organizations as a secure email gateway, so a compromised appliance exposes inbound and outbound mail flow, quarantined messages, directory (LDAP) bind credentials, and any relay or SMTP authentication secrets stored on it. Because it is a network appliance without EDR coverage, post-exploitation activity is easy to miss. Fortinet products have been a repeated target for zero-day exploitation, and a bug that is both unauthenticated and pre-patch is attractive to ransomware and espionage operators alike.

Mitigation

Until patches land, Fortinet’s guidance is:

  1. Disable the IBE (identity-based encryption) feature if you do not need it.
  2. Remove the management interface from internet exposure. Restrict admin access to a dedicated management network or VPN, and apply allow-lists on the HTTP/HTTPS admin ports.
  3. Upgrade to 7.4.9, 7.6.7 or 8.0.2 as soon as they are released; move 7.2 deployments to a supported branch.

Because exploitation precedes disclosure, treat any internet-exposed FortiMail as potentially compromised and hunt accordingly:

  • Review web server and admin access logs for unexpected requests containing traversal sequences (../, encoded variants) from unauthenticated sources.
  • Look for newly created or modified files outside normal application paths, especially scripts in web-accessible directories.
  • Rotate LDAP/AD service-account credentials, relay credentials and admin passwords stored on or reachable from the appliance.
  • Check for unexpected outbound connections from the appliance.

References