Fortinet FortiMail — Critical Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes (CVE-2026-104286)
Publication date: October 2, 2026
Category: Vulnerability / Enterprise Security
Introduction
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical security vulnerability impacting Fortinet FortiMail to its Known Exploited Vulnerabilities (KEV) catalog. The flaw, tracked as CVE-2026-104286, is actively being exploited in targeted real-world attacks. The initial discovery and reporting were credited to Gwendal Guégniaud of the Fortinet Product Security team. This development unfolds amid heightened threat activity across global corporate infrastructure, running parallel to active exploitation campaigns targeting critical zero-day flaws across enterprise gateways, load balancers, and orchestrators from vendors such as Check Point, Arista, F5, Cisco, and Citrix.
What is FortiMail and Vulnerability CVE-2026-104286? (General Analysis)
FortiMail is Fortinet’s enterprise email security gateway platform designed to protect messaging environments against advanced threats such as phishing, malware, spam, and data leakage. Because it typically sits directly on the perimeter of corporate networks to inspect all inbound and outbound mail traffic, any security breach in this component poses an unacceptable systemic risk to the enterprise.
The CVE-2026-104286 vulnerability stems from an improper limitation of a pathname to a restricted directory (path traversal) combined with improper neutralization of null bytes or null characters in crafted HTTP or HTTPS requests. This flaw empowers an unauthenticated remote attacker to write arbitrary files onto the underlying operating system.
- Official CVSS Score (Confirmed Fact): 9.8 (CRITICAL) —
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - Official CWE Classification (Confirmed Fact): CWE-22 (Improper Limitation of a Pathname to a Restricted Directory / Path Traversal) and CWE-158 (Improper Neutralization of Null Byte or Null Character).
- CISA KEV Status (Confirmed Fact): Listed in the catalog of actively exploited vulnerabilities.
How Does It Work? (Technical Analysis)
The exploitation mechanism of this vulnerability relies on deficient input parameter validation within the web interfaces exposed by FortiMail for administration or HTTP/HTTPS request processing.
- Initial Infection Flow / Exploit Entry: The attacker transmits specially crafted HTTP or HTTPS requests incorporating directory escape sequences (such as
../) and null characters (%00). Due to inadequate input sanitization, the application processes the manipulated path, allowing the execution flow to break out of the secure web root directory. - Persistence and Privilege Escalation: Leveraging the capability to write arbitrary files onto the underlying file system, threat operators deploy malicious components directly into critical operating system paths. Attackers have been observed modifying existing binaries and creating shared libraries or pre-load configuration files (
ld.so.preload) to ensure high-privilege code execution and reboot persistence. - Evasion and Payload Delivery: The injected malicious artifacts aim to alter the behavior of web daemons, mail services, and legitimate administrative routines of the appliance, unlocking backdoors for total device control without requiring prior credentials.
Affected Systems / Environments
The vulnerability directly impacts multiple software version branches of FortiMail. Furthermore, the current threat landscape is exacerbated by concurrent critical vulnerabilities actively exploited across other core infrastructure components.
Affected FortiMail Versions
- FortiMail 8.0.0 through 8.0.1 (Upgrade to upcoming 8.0.2 or above).
- FortiMail 7.6.0 through 7.6.6 (Upgrade to upcoming 7.6.7 or above).
- FortiMail 7.4.0 through 7.4.8 (Upgrade to upcoming 7.4.9 or above).
- FortiMail 7.2.0 through 7.2.9 (Upgrade to branch 7.4 or above).
Summary Table of Related Vulnerabilities in Recent Campaigns
| CVE | Category (CWE) | Impact | CVSS | Vector (summary) |
|---|---|---|---|---|
| CVE-2026-104286 (Fortinet FortiMail) | CWE-22 / CWE-158 | Arbitrary file write / RCE | 9.8 | Remote / Unauthenticated / No UI |
| CVE-2026-85102 (Check Point Quantum) | CWE-295 | Remote Code Execution | 9.8 | Remote / Unauthenticated / VPN cert validation |
| CVE-2026-93616 (Check Point Management) | CWE-22 | Script upload & execution | 9.8 | Remote / Unauthenticated / Path traversal |
| CVE-2026-93952 (Arista VeloCloud) | CWE-20 | Full Orchestrator compromise | 9.5 (v4.0) | Remote / High complexity / Unauthenticated |
| CVE-2026-94127 (F5 BIG-IP APM) | CWE-122 | Remote Code Execution (RCE) | 9.3 (v4.0) | Remote / Unauthenticated / OAuth Authorization Server |
| CVE-2026-76504 (Cisco SD-WAN Manager) | CWE-177 | Admin Authentication Bypass | 9.8 | Remote / Unauthenticated / URI manipulation |
| CVE-2026-88771 (Citrix NetScaler ADC/GW) | CWE-20 | Arbitrary command execution | 9.5 (v4.0) | Remote / Unauthenticated / Input validation |
| CVE-2026-88772 (Citrix NetScaler ADC/GW) | CWE-119 | RCE or Denial of Service (DoS) | 9.5 (v4.0) | Remote / Unauthenticated / Memory safety |
Intelligence Advisory: The simultaneous active exploitation across multiple edge technologies (Fortinet, Check Point, F5, Cisco, Citrix, Arista) indicates coordinated campaigns by advanced persistent threat (APT) actors or ransomware syndicates seeking mass initial access vectors into corporate and government networks.
Mitigation and Detection
Remediation
- Priority Patching: Apply official patches provided by Fortinet as soon as they become available for your specific FortiMail branch. For U.S. Federal Civilian Executive Branch (FCEB) agencies, CISA mandated a compliance deadline of October 4, 2026, to apply patches or workarounds.
- Temporary Workarounds: If immediate patching is not feasible, disable IBE feature support using the following CLI command:
text
config system encryption ibe set status disable end - Perimeter Access Restriction: Disable access to the FortiMail management interface from the internet or strictly restrict access to trusted private networks via access control lists (ACLs) or corporate VPNs.
Detection
Incident response teams (Blue Teams) should audit their environments for the following Indicators of Compromise (IoCs) observed during active intrusions:
- Source IP Addresses Associated with Attacks:
79.141.169[.]18745.129.0[.]192
- Files Created or Modified on the System:
/data/lib/liblog.so(Added)/data/bin/webconsole(Added)/data/bin/mailservice(Added)/data/etc/ld.so.preload(Added)/bin/smit(Modified)/data/etc/httpd.conf(Modified)/data/migadmin.tar.gz(Modified)
Wrapping Up
The emergence of the critical CVE-2026-104286 vulnerability in Fortinet FortiMail highlights the speed with which adversaries operationalize zero-day flaws into mass initial access weapons. The ability to write arbitrary files without authentication fundamentally compromises the integrity of perimeter email gateways. Combined with concurrent vulnerabilities across network appliances from Check Point, Cisco, Citrix, F5, and Arista, organizations face an environment where rapid patch management and strict exposure isolation of management interfaces are indispensable defenses against operational breaches.
References
- Fortinet. (2026). FortiMail Path Traversal Vulnerability Advisory (FG-IR-26-175). https://fortiguard.fortinet.com/psirt/FG-IR-26-175
- Cybersecurity and Infrastructure Security Agency (CISA). (2026). CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-104286). https://www.cisa.gov/news-events/alerts/2026/10/01/cisa-adds-one-known-exploited-vulnerability-catalog
- Cybersecurity and Infrastructure Security Agency (CISA). (2026). Known Exploited Vulnerabilities Catalog (CVE-2026-104286, CVE-2026-85102, CVE-2026-93616, CVE-2026-93952, CVE-2026-94127, CVE-2026-76504, CVE-2026-88771, CVE-2026-88772). https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- Check Point Software Technologies. (2026). Security Advisory: Action Required - Active Exploitation of CVE-2026-85102 and Management Pre-Authentication Vulnerability. https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616/
- F5 Networks. (2026). BIG-IP APM vulnerability CVE-2026-94127. https://my.f5.com/manage/s/article/K000162605
- Cisco Systems. (2026). Cisco Catalyst SD-WAN Manager Web Authentication Bypass Vulnerability (cisco-sa-sdwan-webauth-xr8beuuU). https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU
- Citrix Systems. (2026). Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin (CTX697096). https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096
- Arista Networks. (2026). Security Advisory 0183: VeloCloud Orchestrator (24765-security-advisory-0183). https://www.arista.com/en/support/advisories-notices/security-advisory/24765-security-advisory-0183