FortiMail path traversal exploited in the wild (CVE-2026-104286)
CVE-2026-104286
CVE-2026-104286: unauthenticated attackers write arbitrary files on FortiMail 7.2 to 8.0.1 via crafted HTTP requests. Patch to 8.0.2 or later now.
Actively exploited in the wild - CVE-2026-104286 is a critical path traversal flaw in Fortinet FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9 that lets unauthenticated attackers write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. No credentials or user interaction are required, and the vulnerability carries a CVSS score of 9.8.
Overview
FortiMail is Fortinet’s secure email gateway, typically deployed at the network edge where it receives mail from the public internet. CVE-2026-104286 is a path traversal vulnerability, which means the software fails to properly restrict a file path to its intended directory. An attacker can supply a crafted path in an HTTP or HTTPS request and cause the appliance to write a file outside the directory that should have contained it.
The request needs no authentication. An attacker with network reachability to the FortiMail web interface can trigger file writes without valid credentials. Because the vulnerable component handles HTTP requests rather than mail traffic, any FortiMail management or web interface exposed to the internet is directly at risk.
Impact
Successful exploitation allows arbitrary file writes on the underlying system. In practice, this kind of access is a stepping stone: attackers can overwrite configuration files, plant web shells in web-accessible directories, or modify scripts that the appliance later executes. That can lead to full compromise of the appliance, persistent access, and lateral movement into the internal network. Since FortiMail sits in the mail path, a compromised gateway also puts email content and credentials flowing through it at risk.
CISA has added CVE-2026-104286 to its Known Exploited Vulnerabilities catalog, confirming that attackers are using this flaw in real campaigns. Fortinet products have been a repeated target for edge-device exploitation, and this pattern fits a broader trend of attackers favoring internet-facing appliances as initial access points. Our coverage of a critical FortiClient EMS flaw used to deploy a credential stealer shows the same playbook against the same vendor.
Remediation and Mitigation
- Upgrade FortiMail to a fixed release. Check Fortinet’s advisory (FG-IR-26-104286) for the exact patched build for your branch, and move 8.0.x deployments to the corrected version.
- Until you can patch, remove internet exposure from the FortiMail web and management interfaces. Restrict access to trusted management networks or a VPN.
- Review the appliance for signs of compromise: unexpected files in web directories, modified scripts, new admin accounts, and outbound connections to unknown hosts.
- Enable logging and monitoring for abnormal HTTP requests that contain path traversal sequences such as
../, and forward FortiMail logs to your SIEM.
Security Insight
CVE-2026-104286 is another data point in a long pattern: Fortinet edge appliances are repeatedly compromised because they are internet-facing, credential-free to attack, and trusted once breached. The path traversal mechanism itself is mundane, but pairing it with a CVSS 9.8 unauthenticated attack surface and confirmed exploitation makes it a high-value target for initial access brokers. Organizations should treat secure email gateways as Tier-0 infrastructure and audit their internet exposure the same way they audit VPN concentrators, as highlighted in our weekly threat roundup. Attackers continue to industrialize edge exploitation, and AI-assisted tooling is likely to shorten the window between disclosure and mass scanning.
Further Reading
Never miss a critical vulnerability
Get real-time security alerts delivered to your preferred platform.
Related Advisories
A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server....
VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code....
ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execut...
excel-mcp-server is a Model Context Protocol server for Excel file manipulation. A path traversal vulnerability exists in excel-mcp-server versions up to and including 0.1.7. When running in SSE or St...