FortiMail CVE-2026-104286 (CVSS 9.8): unauth path-traversal/NULL-byte write — exploited; FG-IR-26-175; CISA KEV due 4 Oct
Fortinet PSIRT FG-IR-26-175 (published / revised 1 October 2026; FortiGuard IR RSS + advisory) discloses CVE-2026-104286, a Critical CVSSv3 9.8 path-traversal (CWE-22) plus improper NULL-byte neutralization (CWE-158) flaw in the FortiMail management interface that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. Impact: execute unauthorised code or commands. Attack type: unauthenticated. Known exploited: Yes (Fortinet). Affected: FortiMail 8.0.0–8.0.1 (upgrade to upcoming 8.0.2+), 7.6.0–7.6.6 (upcoming 7.6.7+), 7.4.0–7.4.8 (upcoming 7.4.9+), 7.2.0–7.2.9 (upgrade to 7.4 branch or later). Discovered internally by Fortinet Product Security. Workarounds until patches land: disable IBE (`config system encryption ibe` / `set status disable`) and/or remove internet exposure of the FortiMail management interface (trusted networks only). BleepingComputer (1 Oct) amplifies Fortinet IoCs (added/modified files under /data and /bin, SHA-256 hashes, attacker IPs 79.141.169.187 and 45.129.0.192, archive234 remote-archive config, cron/migadmin and IBE Base64 decode failure log patterns) and notes Fortinet is coordinating with government agencies including CISA. CISA added CVE-2026-104286 to KEV on 1 Oct 2026 (FCEB due 4 Oct 2026 per BleepingComputer). Primary: FortiGuard FG-IR-26-175; wire: BleepingComputer 1 Oct.
- Product
- Fortinet FortiMail (management interface / GUI)
- Versions
- 8.0.0–8.0.1 (fix upcoming 8.0.2+); 7.6.0–7.6.6 (fix upcoming 7.6.7+); 7.4.0–7.4.8 (fix upcoming 7.4.9+); 7.2.0–7.2.9 (upgrade to 7.4 branch or later)
- CVSS
- (CVSSv3 Critical; Fortinet)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- Apply Fortinet fixed builds when released (8.0.2+ / 7.6.7+ / 7.4.9+; 7.2 → 7.4+). Until then: disable IBE encryption feature and/or block internet access to the FortiMail management interface. Hunt Fortinet-published IoCs (liblog.so, smit, webconsole, mailservice, httpd.conf, ld.so.preload, migadmin.tar.gz hashes; IPs 79.141.169.187 / 45.129.0.192; archive234 remote archive; cron/migadmin and IBE decode-failure logs). FCEB: CISA KEV due 4 Oct 2026.
Primary: Fortinet PSIRT FG-IR-26-175 — FortiMail CVE-2026-104286 (1 Oct 2026) · Vendor: FortiGuard Labs PSIRT — FG-IR-26-175 · CVE: CVE-2026-104286 · BleepingComputer — FortiMail critical flaw exploited; IoCs + workarounds (1 Oct 2026)
