Critical 9.8 Actively Exploited

FortiMail path traversal exploited in the wild (CVE-2026-104286)

CVE-2026-104286

By Yazoul AI · automated

CVE-2026-104286: unauthenticated attackers write arbitrary files on FortiMail 7.2 to 8.0.1 via crafted HTTP requests. Patch to 8.0.2 or later now.

Actively exploited in the wild - CVE-2026-104286 is a critical path traversal flaw in Fortinet FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9 that lets unauthenticated attackers write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. No credentials or user interaction are required, and the vulnerability carries a CVSS score of 9.8.

Overview

FortiMail is Fortinet’s secure email gateway, typically deployed at the network edge where it receives mail from the public internet. CVE-2026-104286 is a path traversal vulnerability, which means the software fails to properly restrict a file path to its intended directory. An attacker can supply a crafted path in an HTTP or HTTPS request and cause the appliance to write a file outside the directory that should have contained it.

The request needs no authentication. An attacker with network reachability to the FortiMail web interface can trigger file writes without valid credentials. Because the vulnerable component handles HTTP requests rather than mail traffic, any FortiMail management or web interface exposed to the internet is directly at risk.

Impact

Successful exploitation allows arbitrary file writes on the underlying system. In practice, this kind of access is a stepping stone: attackers can overwrite configuration files, plant web shells in web-accessible directories, or modify scripts that the appliance later executes. That can lead to full compromise of the appliance, persistent access, and lateral movement into the internal network. Since FortiMail sits in the mail path, a compromised gateway also puts email content and credentials flowing through it at risk.

CISA has added CVE-2026-104286 to its Known Exploited Vulnerabilities catalog, confirming that attackers are using this flaw in real campaigns. Fortinet products have been a repeated target for edge-device exploitation, and this pattern fits a broader trend of attackers favoring internet-facing appliances as initial access points. Our coverage of a critical FortiClient EMS flaw used to deploy a credential stealer shows the same playbook against the same vendor.

Remediation and Mitigation

  • Upgrade FortiMail to a fixed release. Check Fortinet’s advisory (FG-IR-26-104286) for the exact patched build for your branch, and move 8.0.x deployments to the corrected version.
  • Until you can patch, remove internet exposure from the FortiMail web and management interfaces. Restrict access to trusted management networks or a VPN.
  • Review the appliance for signs of compromise: unexpected files in web directories, modified scripts, new admin accounts, and outbound connections to unknown hosts.
  • Enable logging and monitoring for abnormal HTTP requests that contain path traversal sequences such as ../, and forward FortiMail logs to your SIEM.

Security Insight

CVE-2026-104286 is another data point in a long pattern: Fortinet edge appliances are repeatedly compromised because they are internet-facing, credential-free to attack, and trusted once breached. The path traversal mechanism itself is mundane, but pairing it with a CVSS 9.8 unauthenticated attack surface and confirmed exploitation makes it a high-value target for initial access brokers. Organizations should treat secure email gateways as Tier-0 infrastructure and audit their internet exposure the same way they audit VPN concentrators, as highlighted in our weekly threat roundup. Attackers continue to industrialize edge exploitation, and AI-assisted tooling is likely to shorten the window between disclosure and mass scanning.

Further Reading

Share:

Never miss a critical vulnerability

Get real-time security alerts delivered to your preferred platform.

Related Advisories

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.