Fortinet FortiMail CVE-2026-104286 Actively Exploited: Critical Path Traversal and NULL Byte Vulnerability Alert

Fortinet FortiMail CVE-2026-104286 Actively Exploited: Critical Path Traversal and NULL Byte Vulnerability Alert

Executive Summary

A critical vulnerability, CVE-2026-104286 (also referenced as FG-IR-26-175), has been identified in Fortinet FortiMail appliances. This flaw enables unauthenticated remote attackers to write arbitrary files to the underlying system by sending specially crafted HTTP or HTTPS requests, leveraging both path traversal and improper neutralization of NULL byte vulnerabilities. The impact is severe: successful exploitation can result in remote code execution, full system compromise, data exfiltration, and lateral movement within the network. The vulnerability is being actively exploited in the wild, and the Cybersecurity and Infrastructure Security Agency (CISA) has confirmed its inclusion in the Known Exploited Vulnerabilities (KEV) catalog as of 2026-10-01. Immediate mitigation is required for all organizations operating affected FortiMail versions.

Technical Information

CVE-2026-104286 is a critical path traversal and NULL byte injection vulnerability in the FortiMail web interface, specifically within the Identity-Based Encryption (IBE) feature. The vulnerability is classified under CWE-22 (Improper Limitation of a Pathname to a Restricted Directory) and CWE-158 (Improper Neutralization of NULL Byte or NULL Character). With a CVSS v3 score of 9.8, this issue allows remote, unauthenticated attackers to bypass directory restrictions and input validation, enabling arbitrary file writes to sensitive locations on the appliance.

Attackers exploit this flaw by crafting HTTP or HTTPS requests containing path traversal sequences (such as ../) and NULL bytes, which are not properly sanitized by the application logic. This allows them to escape the intended directory structure and write files anywhere on the system, including locations that can be executed or loaded by the operating system. The result is the potential for remote code execution, installation of webshells or backdoors, modification of system binaries, and persistent compromise.

The vulnerability affects the following FortiMail versions: 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9. Exploitation has been observed in the wild, with attackers deploying malicious binaries, modifying configuration files, and establishing persistence mechanisms. The attack surface is exposed via the webmail interface, particularly if accessible from the internet.

The technical impact includes arbitrary file write, remote code execution, full system compromise, data exfiltration, and the ability for attackers to pivot to other internal systems. The vulnerability is being leveraged for both initial access and post-exploitation activities, including credential theft and lateral movement.

Exploitation in the Wild

Exploitation of CVE-2026-104286 is ongoing and confirmed by multiple security vendors and the vendor itself. Attackers are actively targeting exposed FortiMail appliances, dropping malicious binaries and webshells, modifying system files, and establishing persistence. The observed tactics include the use of crafted HTTP/HTTPS requests to exploit the IBE feature, followed by the deployment of custom payloads and modification of critical configuration files.

The potential impact of successful exploitation is severe. Attackers can gain full control over the FortiMail appliance, access and exfiltrate stored emails and credentials, and use the compromised system as a foothold for further attacks within the organization. Outbound connections to attacker-controlled infrastructure have been observed, as well as attempts to evade detection by modifying log files and system binaries.

CISA has confirmed active exploitation by adding CVE-2026-104286 to its Known Exploited Vulnerabilities catalog on 2026-10-01, underscoring the urgency of immediate mitigation.

APT Groups using this vulnerability

As of the time of writing, there is no public attribution of CVE-2026-104286 exploitation to specific Advanced Persistent Threat (APT) groups. However, the tactics, techniques, and infrastructure observed in attacks overlap with both financially motivated and espionage-focused threat actors that commonly target mail gateways and perimeter devices. The global exploitation pattern suggests that a range of threat actors, including those with advanced capabilities, are leveraging this vulnerability for initial access and persistent compromise.

Affected Product Versions

The following FortiMail versions are affected by CVE-2026-104286:

FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, and FortiMail 7.2.0 through 7.2.9. No other versions are listed as affected in the official advisory. Organizations running any of these versions are at immediate risk and must implement mitigations without delay.

Workaround and Mitigation

As of this writing, no official patch is available from Fortinet. Organizations are strongly advised to implement the following mitigations immediately:

Disable the IBE feature via the GUI by navigating to Encryption, then IBE, and setting IBE Service to 'off'. Alternatively, disable the IBE feature via the CLI using the following commands:

config system encryption ibe
set status disable
end

Restrict access to the FortiMail webmail interface from the internet, allowing only trusted private networks. If a web application firewall (WAF) is present, configure it to block POST requests to /ibe that contain path traversal sequences such as ../. Monitor for suspicious file additions or modifications, especially in /data/lib/, /data/bin/, /data/etc/, and /bin/. Monitor for outbound connections to known malicious IP addresses associated with exploitation activity.

CISA requires organizations to apply mitigations in accordance with vendor instructions and to comply with BOD 26-04 guidance for prioritizing security updates based on risk. If mitigations are unavailable, organizations should discontinue use of the affected product.

Indicators of Compromise

The following indicators of compromise (IOCs) are provided as a point-in-time reference and should be validated before enforcement in your environment. These IOCs have been extracted from public threat intelligence sources and vendor advisories.

Type

Indicator

Reported (date)

Source

 

IPv4

79[.]141[.]169[.]187

2026-10-01

https://fortiguard.fortinet.com/psirt/FG-IR-26-175

IPv4

45[.]129[.]0[.]192

2026-10-01

https://fortiguard.fortinet.com/psirt/FG-IR-26-175

File

/data/lib/liblog.so (MD5: 64c90a00c7fda4d5c7973ed64c25783a)

2026-10-01

https://fortiguard.fortinet.com/psirt/FG-IR-26-175

File

/bin/smit (MD5: 5241738a3e9988404239e12243f6d35b)

2026-10-01

https://fortiguard.fortinet.com/psirt/FG-IR-26-175

File

/data/bin/webconsole (MD5: ae0ea6502d3fa5f0664bceb73189eb54)

2026-10-01

https://fortiguard.fortinet.com/psirt/FG-IR-26-175

File

/data/bin/mailservice (MD5: f90fa81a5f521d785f2b2f765e3ab897)

2026-10-01

https://fortiguard.fortinet.com/psirt/FG-IR-26-175

File

/data/etc/httpd.conf (MD5: 61af1c4bce1c2eebc8ff689ca5337791)

2026-10-01

https://fortiguard.fortinet.com/psirt/FG-IR-26-175

File

/data/etc/ld.so.preload (MD5: 8eb64f25d2a8e18e05aae058629473cf)

2026-10-01

https://fortiguard.fortinet.com/psirt/FG-IR-26-175

File

/data/migadmin.tar.gz (MD5: 49a7156a7d043cc8f9f680579db22f86)

2026-10-01

https://fortiguard.fortinet.com/psirt/FG-IR-26-175

References

Fortinet PSIRT Advisory FG-IR-26-175, NVD Entry CVE-2026-104286, Truesec Threat Insight, HelpNetSecurity Coverage, CISA KEV Catalog

Rescana is here for you

Rescana empowers organizations to proactively manage third-party risk with our advanced TPRM platform, providing continuous monitoring, automated risk assessments, and actionable intelligence to strengthen your cybersecurity posture. For any questions or further assistance, we are happy to help at info@rescana.com.

Contact us / Book a demo

Talk to Rescana about this advisory, or book a demo of the platform.