Fortinet — FortiMail Critical Path Traversal Flaw Exploited in Zero-Day Attacks (CVE-2026-104286)

Publication date: October 1, 2026
Category: News

Introduction

Fortinet has issued an urgent security warning after discovering active exploitation in zero-day attacks targeting a critical vulnerability in its email security platform, FortiMail. Tracked as CVE-2026-104286, the flaw enables unauthenticated remote attackers to write arbitrary files on the underlying operating system. The vulnerability was discovered internally by Gwendal Guégniaud of Fortinet’s Product Security team, prompting coordinated responses with government agencies such as CISA due to severe risks facing enterprise and critical infrastructures.

What is CVE-2026-104286? (General Analysis)

Technically, the vulnerability stems from an improper limitation of a pathname to a restricted directory (Path Traversal, classified under CWE-22) combined with improper neutralisation of null bytes or null characters (CWE-158).

In enterprise architectures, FortiMail functions as a Secure Email Gateway (SEG) responsible for inspecting inbound and outbound mail traffic, blocking advanced threats, and handling Identity-Based Encryption (IBE) policies. When exposed on management interfaces or web services, path traversal vulnerabilities bypass filesystem isolation barriers, allowing specially crafted HTTP or HTTPS requests to manipulate files outside of intended directories.

According to official National Vulnerability Database (NVD) records, this vulnerability carries a CVSS v3.1 base score of 9.8 (CRITICAL) with the exact vector:

  • Official CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    • AV:N (Network): Exploitable remotely across the internet.
    • AC:L (Low Attack Complexity): No specialized conditions or complex setups required.
    • PR:N (No Privileges Required): Unauthenticated attackers can trigger the flaw.
    • UI:N (No User Interaction): No legitimate operator interaction is needed.
    • S:U (Unchanged Scope): Impact remains within the vulnerable component’s security context.
    • C:H / I:H / A:H (High Confidentiality, Integrity, and Availability): Full system compromise.

Due to its severity and confirmation of in-the-wild exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the CVE to its Known Exploited Vulnerabilities (KEV) catalog.

How Does It Work? (Technical Analysis)

The exploitation mechanism relies on manipulating file paths via HTTP/HTTPS requests that fail to properly sanitize special characters and null bytes (NULL bytes).

  • Initial Entry Vector: Attackers dispatch malicious web requests designed to traverse outside permitted web roots, exploiting path handling flaws within FortiMail services. This facilitates the overwriting of core binaries, shared libraries, or web configuration files (httpd.conf).
  • Persistence and Code Execution: Published Indicators of Compromise (IoCs) demonstrate that malicious actors added or modified critical operating system files. Observed modifications include altering dynamic linker preloads (/data/etc/ld.so.preload), injecting shared logging libraries (/data/lib/liblog.so), tampering with administrative utilities (/bin/smit), and deploying modified web and mail service binaries (/data/bin/webconsole, /data/bin/mailservice).
  • Exfiltration and Remote Setup: Audit logs show that attackers configured unauthorized archive accounts (e.g., archive234) directed to external command-and-control IP addresses (such as 79.141.169.187), leveraging cron jobs executing commands tied to migration directories (/migadmin) to enable silent data exfiltration.

Affected Systems / Environments

The vulnerability impacts multiple software branches of FortiMail. The affected versions are outlined below:

CVE Category (CWE) Affected Versions CVSS Vector
CVE-2026-104286 CWE-22 (Path Traversal) FortiMail 8.0.0 through 8.0.1
FortiMail 7.6.0 through 7.6.6
FortiMail 7.4.0 through 7.4.8
FortiMail 7.2.0 through 7.2.9
9.8 (Critical) AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Mitigation and Detection

Remediation

FortiMail 7.2 users can mitigate the flaw by upgrading to branch 7.4 or later. For affected installations on branches 7.4, 7.6, and 8.0, FortiMail has announced that upcoming fixed versions will be 7.4.9, 7.6.7, and 8.0.2, respectively.

As an interim mitigation while patches are pending, administrators should apply the following hardening steps:

  1. Disable Identity-Based Encryption (IBE) feature support by running the following CLI commands:
    text
    config system encryption ibe
    set status disable
    end
  2. Restrict access to the FortiMail management interface by removing public internet exposure and limiting connectivity strictly to trusted private networks.

Detection

Blue Team analysts should perform rigorous threat hunting for Indicators of Compromise (IoCs) and review system logs for anomalies:

  • SHA-256 Hashes of Modified/Added Critical Files:
    • /data/lib/liblog.so (8015f34dc84922b03688399d7f9fe7a00361789f7e420c7e2a2cdb23e75cef84)
    • /bin/smit (77324ac428bde86d351fc5fc06f6d64a6bfe737dfb2743df1d4c5ac2418a5b6a)
    • /data/bin/webconsole (7a6cea9f5c9e2e9994d4e3c4da73f86cf5acd05ea5d312c066c9d1dafd69ee38)
    • /data/bin/mailservice (4000276a150a165d3c2537d1e19fb393c4de8333076a16655e28059cae82157b)
    • /data/etc/httpd.conf (703e97c64e61e41dc3aaba580d82bb2aa7b6a11b54ee6fb467ed5d5a3bffdef5)
    • /data/etc/ld.so.preload (8953ec7960b09f544a880b072ad4e6cfda7a8303f486251d3478dcfdfbac23b6)
    • /data/migadmin.tar.gz (d6fe51c22b91776f4c961ea58bcac5917f15d560a619d7ce726d3d51795609d3)
  • Associated Malicious IP Addresses: 79.141.169.187, 45.129.0.192.
  • Suspicious Log Patterns: Monitor for unauthorized archive account creations (e.g., archive234) or cron executions referencing /migadmin.

“The active exploitation of zero-day path traversal flaws in perimeter email gateways highlights the urgent need to decouple administrative interfaces from public networks and maintain strict integrity monitoring over system binaries.”

Wrapping Up

The incident surrounding CVE-2026-104286 demonstrates the persistence of threat actors in leveraging path control flaws against perimeter appliances. Its swift integration into the CISA KEV catalog underscores the severity of the operational risk. Organizations utilizing FortiMail must immediately apply CLI workarounds and restrict administrative access while official security patches are deployed.

References