Fortinet disclosed CVE-2026-104286 on October 1, 2026, and CISA added it to the Known Exploited Vulnerabilities (KEV) catalog the same day. The flaw is critical, rated CVSS 9.8. An unauthenticated attacker can write arbitrary files to a FortiMail email security appliance with crafted HTTP or HTTPS requests. Fortinet’s advisory says it has already been exploited in the wild. PSIRT | FortiGuard Labs +3
The timing is what makes this FortiMail vulnerability awkward. Fortinet lists the fixed releases, 8.0.2, 7.6.7 and 7.4.9, as upcoming. That means containment and compromise checks come before patching. This guide covers who is affected, what the KEV listing means for your organization, and how to tell whether an appliance has already been hit. fortinet
Quick Answer: CVE-2026-104286 is a critical (CVSS 9.8) unauthenticated path traversal flaw in the FortiMail management GUI that allows arbitrary file writes and is exploited in the wild. It affects FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8 and 7.2.0 through 7.2.9. Until fixed builds ship, disable IBE or restrict management access, then hunt for compromise.
In this article: What it is · Affected versions · Why CISA KEV matters · Exposure checklist · Detection and IOCs · Remediation · FAQ · Final thoughts

What Is CVE-2026-104286?
FortiMail is Fortinet’s email security gateway. It sits in the mail path and inspects messages for spam, malware and phishing. This flaw is in its graphical management interface. According to the Fortinet security advisory FG-IR-26-175, it combines path traversal (CWE-22) with improper handling of NULL bytes (CWE-158), which allows arbitrary file writes without authentication. fortinet
This FortiMail path traversal bug can be reached over the network with low complexity, no privileges and no user interaction. That comes from the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N) recorded in Rapid7’s vulnerability database, and the score is 9.8 out of 10. Fortinet’s own Product Security team found the issue. The advisory also states that no virtual patch exists. rapid7fortinet
Fortinet lists the impact as execution of unauthorized code or commands. CyberInfos assesses that as plausible. The published indicators include added binaries and a modified system binary, which is more than a single dropped file. What the sources we reviewed do not say: when attacks began, how many appliances were hit, or who is behind them. PSIRT | FortiGuard Labs +2

Affected FortiMail Versions and Fix Status
Treat the advisory as the authoritative scope. Fortinet marked the fixed builds as upcoming when it published on October 1, so confirm they exist in the live advisory before you book a maintenance window. fortinet
| Branch | Affected versions | Fortinet fix guidance |
|---|---|---|
| 8.0 | 8.0.0 through 8.0.1 | Upgrade to upcoming 8.0.2 or later |
| 7.6 | 7.6.0 through 7.6.6 | Upgrade to upcoming 7.6.7 or later |
| 7.4 | 7.4.0 through 7.4.8 | Upgrade to upcoming 7.4.9 or later |
| 7.2 | 7.2.0 through 7.2.9 | Upgrade to the 7.4 branch or later |
Two traps are worth avoiding. First, do not move a 7.2 appliance to a 7.4 build below the fixed release. Versions 7.4.0 through 7.4.8 are still vulnerable.
Second, third-party feeds do not agree with the advisory. Suped noted conflicting machine-readable metadata, and some aggregator pages list different ranges, including 7.0 builds. Check your firmware against Fortinet’s table. If you still run 7.0, which the table does not cover, ask Fortinet support. CISA flags active exploitation of FortiMail CVE-2026-104286 – Suped +2

Why the CISA KEV Listing Matters
The KEV catalog is CISA’s list of vulnerabilities with confirmed exploitation in the wild, so a listing carries more weight than a CVSS score alone. Suped’s review of the CISA KEV FortiMail entry shows it dated October 1, 2026, with an October 4 due date for U.S. federal civilian agencies.
The same record marks forensic triage as required under Binding Operational Directive (BOD) 26-04. In practice, agencies have to check for earlier compromise, not only mitigate. Mallory reported that no ransomware use is known. supedmallory
The October 4 date is a federal requirement, not a universal deadline. Private-sector organizations should treat the KEV listing and Fortinet’s guidance as risk signals and set their own remediation window. For this FortiMail vulnerability, CyberInfos recommends treating any internet-reachable management interface as urgent. Exploitation is confirmed, and no patch is available yet. suped

Exposure Checklist: Are You Affected?
Any Fortinet FortiMail CVE this severe deserves a quick inventory pass. Start here:
- List every FortiMail appliance and virtual machine, with its exact firmware version.
- Compare each version with Fortinet’s affected ranges, not a scanner feed alone.
- Check whether the management interface is reachable from the internet, and test it from outside.
- Check whether IBE (identity-based encryption) is enabled in your configuration.
- Review the firewall, NAT and reverse-proxy rules that publish the FortiMail web interface.
- Note how long the interface was exposed and whether your logs cover that period.
- Optional: runZero published the asset query
hw:="Fortinet FortiMail"to locate appliances. runzero
If any affected appliance has a reachable management interface, go straight to containment.
Detection and IOC Checklist
The Fortinet security advisory publishes indicators of compromise (IOCs). Treat any match as an incident. Hashes for each file are listed in the advisory. fortinet
| Type | Indicator |
|---|---|
| Added files | /data/lib/liblog.so, /data/bin/webconsole, /data/bin/mailservice, /data/etc/ld.so.preload |
| Modified files | /bin/smit, /data/etc/httpd.conf, /data/migadmin.tar.gz |
| IP addresses | 79[.]141[.]169[.]187, 45[.]129[.]0[.]192 |
Log patterns to hunt for:
- A system cron event whose command references /migadmin.
- A configuration event adding an archive account named archive234 with a remote destination of 79[.]141[.]169[.]187 and directory /uploads.
- An admin logout recorded as reason=unknown from (null).
- An IBE decrypter exception citing invalid Base64 encoding at position 0.
- Failed login messages for internal users.
Search firewall, proxy and DNS logs for both IP addresses in both directions. Then run a file-integrity comparison against a known-good appliance.
CyberInfos maps the activity to MITRE ATT&CK T1190 (Exploit Public-Facing Application) for initial access and T1574.006 (Dynamic Linker Hijacking) for the ld.so.preload persistence. An archive account pointing at an external server is also a plausible route for exfiltrating mail, so confirm every archive destination is one you created.
A missing match does not prove an appliance is clean. Logs roll over, and Fortinet may update the list.
Remediation and Containment
Fortinet offers two workarounds because fixed builds are not yet released. CyberInfos recommends applying both where possible. fortinet
- Restrict management access. Take the interface off the internet and allow it only from a trusted private network. Then verify from outside that it is unreachable.
- Disable IBE using Fortinet’s CLI workaround:
config system encryption ibe
set status disable
end
Record the prior state first, because workflows that rely on IBE encryption will be affected. suped
3. Preserve evidence. Export logs and configuration, snapshot the appliance if you can, and involve incident response before any reboot or reimage.
4. Respond to matches. If any IOC matches, rebuild or restore under your incident response plan rather than assuming an upgrade removes every change. Rotate administrator credentials, API tokens, certificates, directory credentials and DKIM keys.
5. Plan the upgrade. Watch the Fortinet advisory for release status, confirm that 8.0.2, 7.6.7 or 7.4.9 is actually published, and keep management access private afterward.
CyberInfos Analyst Insight: Email gateways sit in the mail path and can hold archives and key material, so a compromised one is a data risk, not just an outage. Persistence and external archive destinations can outlast a patch, which is why a clean upgrade does not prove a clean appliance.
FAQ
What is CVE-2026-104286?
It is a critical, unauthenticated FortiMail path traversal flaw in the management interface that allows arbitrary file writes. Fortinet reports exploitation in the wild, and CISA added it to KEV on October 1, 2026. fortinetsuped
Is there a patch yet?
Not as of October 2, 2026. Fortinet lists 8.0.2, 7.6.7 and 7.4.9 as upcoming, so use the IBE or management-access workarounds and recheck the advisory for release status. fortinet
Does the October 4 deadline apply to my organization?
No, unless you are a covered U.S. federal civilian agency. The date comes from CISA’s KEV record. Other organizations should use it as a risk signal and set their own timeline.
Can I tell from logs whether I was compromised?
Sometimes. Match your logs and files against Fortinet’s published IOCs, but a clean result is not proof. Logs roll over and indicators can change.
Does disabling IBE fully fix the problem?
No. It is a workaround, not a patch, and it can affect encryption workflows. Restricting management access and upgrading once fixed builds ship are still advisable.
Final Thoughts
CVE-2026-104286 is not just another vulnerability to add to a patching list. Because the flaw is being actively exploited and has been added to CISA’s KEV catalog, organizations should treat it as both a vulnerability-management priority and a potential security incident.
Security teams should first identify which FortiMail systems are exposed and whether attackers could have reached them. From there, they should apply Fortinet’s recommended mitigation, check logs and other available evidence for signs of compromise, and move to a fixed release as soon as it is available and appropriate for their environment.
For SOC teams, marking the ticket as “patched” should not be the end of the investigation. The bigger questions are: Was the system exposed? Could it have been accessed? Are there any signs of malicious activity? And has the remediation actually been verified? Answering those questions gives the organization a much clearer picture of its real risk.
