What happened
On October 1, 2026, Fortinet published advisory FG-IR-26-175 for CVE-2026-104286,
a path traversal (CWE-22) combined with improper handling of NULL bytes (CWE-158) in FortiMail, its
email security gateway. Fortinet's CVSS score is 9.8: network reachable, no
authentication, no user interaction. The flaw sits in FortiMail's Identity-Based Encryption (IBE)
feature, and Fortinet's own workaround targets requests to the /ibe endpoint.
It was a zero-day. Fortinet marked it as exploited in the wild when it disclosed it, and the same day CISA added it to the KEV catalog with a three-day federal deadline. Fortinet credits the discovery to its own product security team. It has not said when the attacks started, how many customers were hit or who is behind them, as Help Net Security noted. At disclosure the fixed releases were not yet available. Fortinet updated the advisory on October 5 and says it patched FortiMail Cloud that day by moving it to 7.6.7 or 8.0.2.
Why it matters if you run public infrastructure
Fortinet's advisory describes a file write. Researchers say that is enough for full control: watchTowr notes that placing a file on the system gives the attacker a way to run commands on the device itself, and a watchTowr researcher told Cybersecurity Dive the bug is "trivial to exploit." FortiMail sits in the mail path and is reachable from the internet by design, so a compromised gateway can read and redirect the organization's email. The indicators Fortinet published point at exactly that. One shows an attacker adding a remote "archive account" so that mail gets copied to a server they control.
What to check this week
- List every FortiMail reachable from the internet, including the webmail and admin interfaces and any appliance kept around after a migration.
- Check the firmware version in the dashboard's System Information widget or
with
get system statuson the CLI. Affected: 8.0.0 to 8.0.1, 7.6.0 to 7.6.6, 7.4.0 to 7.4.8 and 7.2.0 to 7.2.9. - Upgrade to 8.0.2, 7.6.7 or 7.4.9 or later. There is no 7.2 fix: move to a fixed release on a supported branch.
- If you cannot upgrade yet, use Fortinet's workaround. Turn off the IBE service
(Encryption, then IBE, then set IBE Service to off, or
config system encryption ibe,set status disable,end). Alternatively, restrict internet access to the webmail interface, or have a WAF block POST requests to/ibethat contain../. - Look for signs of compromise, especially if the appliance was exposed before
October 1. Fortinet lists connections from 79.141.169.187 and 45.129.0.192. Its log indicators
include cron entries that run
/bin/shagainst/migadmin, an archive account added with a remote destination at 79.141.169.187 and a/uploadsdirectory, and IBE decrypter errors about invalid Base64 encoding. The Hacker News reports these planted files:/data/lib/liblog.so,/data/bin/webconsole,/data/bin/mailserviceand/data/etc/ld.so.preload. Audit the archive accounts too, and if you find any of these, treat the mail on that gateway and the credentials stored on it as exposed. - Ask whether the admin interface needs to be public at all. An allowlist in front of it turns the next flaw like this from an emergency into a routine patch.
How Attack Surface Scan covers this
Attack Surface Scan does not identify FortiMail specifically and will not raise a CVE finding for this flaw. What it does show is the inventory: the hosts under your verified domains (including ones found through certificate transparency logs), their open ports and their TLS certificates. That is how you find a mail gateway with a web interface listening on the internet that is missing from your patch list. See Vulnerability matching for which products we match CVEs against.
Sources
- Fortinet PSIRT: FG-IR-26-175, Improper limitation of a pathname to a restricted directory (CVE-2026-104286)
- CISA: CISA Adds One Known Exploited Vulnerability to Catalog (October 1, 2026)
- watchTowr: Frequently Asked Questions About the Fortinet FortiMail Path Traversal (CVE-2026-104286)
- The Hacker News: Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes
- Help Net Security: Critical FortiMail zero-day exploited in the wild (CVE-2026-104286)
- Cybersecurity Dive: Fortinet warns that critical flaw in FortiMail is facing exploitation