Skip to content

CVE-2026-104286

FortiMail path traversal lets unauthenticated attackers write files (CVE-2026-104286)

Critical 9.8 KEV Vendor: Fortinet Published

FortiMail 7.0.0 through 7.0.9, 7.2.0 through 7.2.9, 7.4.0 through 7.4.6, 7.6.0 through 7.6.5, and 8.0.0 are vulnerable to unauthenticated path traversal (CVE-2026-104286) allowing arbitrary file writes via crafted HTTP or HTTPS requests. Fortinet reports exploitation in the wild; no fix is listed.

What happened

CVE-2026-104286 is an unauthenticated path traversal vulnerability in FortiMail. An attacker can send crafted HTTP or HTTPS requests to write arbitrary files on the underlying system. The CVSS v3.1 score is 9.8 (critical), with a network attack vector, low attack complexity, no privileges and no user interaction.

Fortinet's PSIRT says the vulnerability has been reported to be exploited in the wild and urges customers to apply the workaround in its advisory. CISA has added the CVE to the Known Exploited Vulnerabilities catalog with a due date of 4 October 2026. No fixed release is listed in the advisory or the KEV entry.

Who is affected

FortiMail is affected in these versions: 8.0.0; 7.6.0 through 7.6.5; 7.4.0 through 7.4.6; 7.2.0 through 7.2.9; and 7.0.0 through 7.0.9. The vulnerability is reachable over HTTP or HTTPS, so internet-facing FortiMail deployments are the priority. Fortinet has not listed fixed releases.

What to do now

  1. Apply the workaround in Fortinet's FG-IR-26-175 advisory. Fortinet says the vulnerability has been exploited in the wild, and no fixed release is listed.
  2. If you cannot apply the workaround, restrict network access to the FortiMail HTTP/HTTPS interface. CISA's KEV required action says to discontinue use of the product if mitigations are unavailable.
  3. Monitor Fortinet's FG-IR-26-175 advisory and CISA's KEV entry for updates. CISA's due date is 4 October 2026.

How to detect it

Fortinet and CISA have not listed specific indicators of compromise. Audit internet exposure of FortiMail HTTP/HTTPS interfaces, and review access logs for unusual or crafted requests, because exploitation relies on crafted HTTP or HTTPS requests.

Beyond the patch

This is an unauthenticated, network-reachable vulnerability that Fortinet and CISA say is already exploited. If you run internet-facing FortiMail, confirming exposure and detecting follow-on activity matters as much as applying the workaround. Our Managed Detection & Response (MDR) supports detection and response when a vulnerability is exploited, and Virtual CISO Services (vCISO) can help you close exposed services before the next critical advisory.

Affected and fixed versions

ProductAffectedFixed in
FortiMail8.0.0
7.6.0 – ≤ 7.6.5
7.4.0 – ≤ 7.4.6
7.2.0 – ≤ 7.2.9
7.0.0 – ≤ 7.0.9
No fixed version listed yet

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.