CVE-2026-104286: Fortinet Disclosed This FortiMail Zero-Day With No Patch Ready for Any Branch

Fortinet disclosed CVE-2026-104286, a CVSS 9.8 path traversal flaw in FortiMail, with active exploitation already underway and no fixed release available for any affected branch. Here's the mechanism, the IOCs to check, and the workaround Fortinet is recommending until patches ship.

CVE-2026-104286: Fortinet Disclosed This FortiMail Zero-Day With No Patch Ready for Any Branch

Fortinet disclosed CVE-2026-104286 on October 1, 2026. It is a CVSS 9.8 path traversal flaw in FortiMail that lets a remote, unauthenticated attacker write arbitrary files to the underlying system and gain full control of the appliance. Fortinet's own Product Security team found the bug internally, credited to Gwendal Guegniaud, and confirmed it is being exploited in zero-day attacks. CISA added it to the Known Exploited Vulnerabilities catalog the same day. At the time of the advisory, no fixed release existed for any affected branch, only a workaround.

How the Path Traversal Works

The flaw is tracked under two CWEs: CWE-22, improper limitation of a pathname to a restricted directory, and CWE-158, improper neutralization of NULL byte or NULL character. It sits in FortiMail's web management interface. A crafted HTTP or HTTPS request can escape its intended directory and, by embedding a NULL byte in the path, truncate how the underlying file handling interprets the string, letting an unauthenticated attacker write files anywhere on the filesystem the web process can reach. Writing files outside the web root is enough on its own to plant a working backdoor, which is what turns a file-write bug into full system compromise.

Who's Affected

FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9 are all vulnerable. Fortinet lists 8.0.2, 7.6.7, and 7.4.9 as upcoming fixed releases for their respective branches, and recommends 7.2 users move to 7.4 or later once a fix ships. None of those fixed versions were available when the advisory went out. CVSS 3.1 rates the bug 9.8 critical, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H: network-reachable, low complexity, no privileges or user interaction needed, full compromise of confidentiality, integrity, and availability. Fortinet and its own PSIRT entry agree on that score, which is not always the case across vendor and NVD scoring.

A Zero-Day Advisory With No Patch Attached

CVE-2026-104286 joins a run of edge-device zero-days actively exploited through 2026, following Check Point's management server flaws, Arista's VeloCloud Orchestrator bug, F5's BIG-IP Access Policy Manager issue, Cisco's Catalyst SD-WAN Manager bypass, and the pair of Citrix NetScaler flaws. What sets this one apart is that Fortinet shipped the advisory before it had a fix ready for any branch. Every affected release line, 7.2 through 8.0, was still waiting on an upcoming version at disclosure. Administrators could not patch their way out on day one. The only options were disabling the IBE feature or cutting management-interface access from the internet, both of which cost functionality rather than close the hole. That gap between disclosure and an actual fix is exactly the window attackers use, and Fortinet's own exploitation confirmation means it was already closing fast before this advisory ever went out.

Reading It on VulnTracker

The CVE-2026-104286 page on VulnTracker shows the 9.8 critical score from two independent sources, Fortinet and Fortinet PSIRT, both agreeing on the same vector. The CVSS breakdown confirms no privileges and no user interaction are needed. The Newsroom tab pulls in coverage from The Hacker News, Cyber Security News, and BleepingComputer as it is published, so you can track how the story develops without leaving the page. CWE-22 is tagged under Quick Info, and the status starts at Awaiting Analysis until NVD finishes its own review. Track the CVE to get notified the moment Fortinet ships a real fix.

What to Do Now

There is no patch to install yet for any branch, so start with the workaround Fortinet is recommending: disable IBE feature support by running config system encryption ibe, then set status disable, then end from the CLI. If that is not viable, restrict access to the FortiMail management interface to trusted private networks and remove it from the internet entirely. Check your logs against Fortinet's published indicators: added files at /data/lib/liblog.so, /data/bin/webconsole, and /data/bin/mailservice, and modifications to /bin/smit, /data/etc/httpd.conf, /data/etc/ld.so.preload, and /data/migadmin.tar.gz. Fortinet's advisory includes MD5 and SHA256 hashes for each, use them rather than file names alone. Watch for outbound traffic to 79.141.169.187 and 45.129.0.192, an archive account named archive234 configured to export data to those addresses, cron jobs referencing /migadmin, and IBE decryption errors reporting invalid Base64 data. Any of those is a sign of compromise, not just exposure. CISA's remediation deadline for federal agencies is October 4, 2026, and that is a reasonable target for anyone running FortiMail regardless of sector. Watch for Fortinet's fixed releases, 8.0.2, 7.6.7, and 7.4.9, and apply them as soon as they ship.

Fortinet found this one before outside researchers did, and still had to publish the advisory without a fix in hand. If FortiMail sits in your mail path, apply the workaround today and treat the IOCs as a compromise check, not a formality. Track CVE-2026-104286 on VulnTracker to catch the patched releases the moment they land.

References

Fortinet Security Advisory FG-IR-26-175 · CISA KEV and remediation timeline (BleepingComputer) · technical analysis (watchTowr)