FortiMail CVE-2026-104286: Zero-Day Path Traversal Response Guide
CVE-2026-104286 combines a path traversal flaw (CWE-22) with improper neutralization of NULL bytes (CWE-158) in the Identity-Based Encryption (IBE) GUI component of Fortinet FortiMail. Chained together, the two weaknesses let a remote, unauthenticated attacker send a crafted HTTP or HTTPS request to the management interface that bypasses file-path restrictions and writes arbitrary files to the underlying system — enough to disable mail scanning, exfiltrate archived mail, or plant a backdoor. Fortinet rates it CVSS 9.8 and has confirmed active exploitation. CISA added it to the Known Exploited Vulnerabilities catalog on October 1, 2026, with a federal remediation deadline of October 4, 2026. Unlike the Fortinet flaws already covered on this site (the 26035/24858/22153/35616/84393/71407/71408 cluster), this is a distinct vulnerability and component — and as of this writing, Fortinet has not yet shipped a fixed build.
No Patch Yet — This Changes the Response Priority
Affected branches are FortiMail 7.2.0–7.2.9, 7.4.0–7.4.8, 7.6.0–7.6.6, and 8.0.0–8.0.1. Fortinet has stated fixed builds (8.0.2, 7.6.7, 7.4.9) are pending but not yet released. That means the response here cannot start with 'upgrade to the fixed version' the way most entries in this series do — interim mitigation is the only lever available until a patch ships, and that mitigation needs to go in immediately given confirmed active exploitation and a three-day federal KEV deadline.
A compromised FortiMail appliance is a mail gateway with write access to the underlying filesystem — the same privileged-position risk this site has flagged before for mail-gateway CVEs (see the Cisco Secure Email Gateway CVE-2026-76461 guide): an attacker in that position can disable scanning, read archived mail, or establish persistence before anyone notices.
Determine Exposure
Exposure turns on whether a vulnerable build is running and whether its management/IBE interface is reachable — treat both internet-facing and internal-only deployments as in scope, since the attacker only needs network access to the interface, not a user account.
- •Inventory every FortiMail appliance and confirm the running build against the affected list: 7.2.0–7.2.9, 7.4.0–7.4.8, 7.6.0–7.6.6, 8.0.0–8.0.1
- •Confirm whether the IBE (Identity-Based Encryption) GUI component is enabled on each appliance — this is the specific vulnerable surface, not FortiMail as a whole
- •Check which appliances expose the management interface beyond the trusted admin network, including any reachable from the internet
- •This is a separate CVE and component from the previously tracked Fortinet cluster — do not assume mitigations already applied for those flaws cover this one
Immediate Response Steps — Interim Mitigation First
With no fixed build available, the priority order is: disable the vulnerable component, restrict access to the management interface, then apply the vendor patch as soon as it ships.
- •Disable the IBE (Identity-Based Encryption) GUI component on every affected FortiMail appliance where it is not actively required — this closes the vulnerable surface directly
- •Where IBE cannot be disabled, restrict network reachability to the management interface to a minimal set of trusted admin IPs as a compensating control
- •Review FortiMail logs and the filesystem for unexpected files written outside normal application paths, particularly around the IBE component, since exploitation is already confirmed active
- •Monitor Fortinet's PSIRT advisory for the fixed build (8.0.2 / 7.6.7 / 7.4.9) and apply it as soon as released — interim mitigation is not a substitute for patching once available
- •Treat any appliance showing signs of unauthorized file writes as a full incident under your IR plan — see our ransomware IR playbook for the same NIST SP 800-61 containment-and-recovery structure
Why the Three-Day Deadline Matters Beyond Federal Agencies
CISA's October 4, 2026 deadline binds federal civilian agencies under BOD 22-01, but the underlying signal — confirmed active exploitation of an unauthenticated, no-patch-available flaw — is the reason every operator should move on the same timeline. Organizations in regulated sectors (BFSI, healthcare) should expect CERT-In and sector regulators to treat a known, actively exploited, publicly disclosed vulnerability left unmitigated as a 'known and preventable' gap in any subsequent incident review, independent of KEV status or whether a patch existed yet.
References
Primary sources for the material above. Standards are cited by identifier so they stay findable as publishers reorganise their sites.
- CISA — Known Exploited Vulnerabilities Catalog, entry added 2026-10-01 (CVE-2026-104286)
- Fortinet PSIRT Advisory — FortiMail IBE GUI Path Traversal and Arbitrary File Write (CVE-2026-104286)