
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-104286 is a critical path traversal vulnerability (CWE-22) in Fortinet FortiMail that allows unauthenticated remote attackers to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. The vulnerability also involves improper neutralization of NULL byte or NULL character (CWE-158). Affected versions include FortiMail 7.2.0–7.2.9, 7.4.0–7.4.8, 7.6.0–7.6.6, and 8.0.0–8.0.1. Disclosed on October 1, 2026, it was simultaneously added to CISA's Known Exploited Vulnerabilities (KEV) catalog, confirming active in-the-wild exploitation. It carries a CVSS v3.1 base score of 9.8 (Critical) (FortiGuard Advisory, CISA KEV, GitHub Advisory).
The vulnerability stems from insufficient validation of user-supplied path components in HTTP/HTTPS request handling within FortiMail's IBE (Identity-Based Encryption) feature, classified as CWE-22 (Path Traversal) and CWE-158 (Improper Neutralization of NULL Byte). An unauthenticated attacker can craft HTTP or HTTPS requests containing path traversal sequences (e.g., ../ or NULL byte-encoded variants) to escape the restricted web root and write arbitrary files to sensitive locations on the underlying operating system. No authentication or user interaction is required, and the attack is fully network-accessible with low complexity. The attack chain progresses from arbitrary file write to code execution, as evidenced by post-exploitation artifacts including a dropped shared library (/data/lib/liblog.so) and a modified ld.so.preload file (FortiGuard Advisory, GitHub Advisory).
Successful exploitation enables an unauthenticated attacker to write arbitrary files anywhere on the FortiMail system, which in observed attacks has led to full system compromise including deployment of backdoors, web shells, and malicious shared libraries. The confirmed impact includes unauthorized code execution, potential exfiltration of email data and credentials processed by the mail gateway, and service disruption. Given FortiMail's role as an email security gateway, compromise could also facilitate interception of sensitive communications and lateral movement into internal networks (FortiGuard Advisory, CISA KEV).
CVE-2026-104286 is actively exploited in the wild as a zero-day and was added to CISA's KEV catalog on October 1, 2026, with a remediation due date of October 4, 2026 — an unusually short window reflecting the severity of active exploitation (CISA KEV). Exploitation has been reported by watchTowr and BleepingComputer, with Fortinet confirming in-the-wild exploitation in its advisory (FortiGuard Advisory, BleepingComputer). The NVD SSVC assessment classifies exploitation as "active" and the vulnerability as "automatable," indicating it can be exploited at scale without manual intervention. No public proof-of-concept code has been confirmed, but the vulnerability is being weaponized by unknown threat actors. The EPSS score is currently 0.0 (newly published), though active exploitation makes this a high-priority remediation target (GitHub Advisory).
../../) or NULL byte characters to escape the restricted directory context./data/lib/liblog.so and modified /data/etc/ld.so.preload to force its loading.ld.so.preload, granting the attacker persistent code execution on the FortiMail appliance./data/bin/webconsole or /data/bin/mailservice, and modify httpd.conf to maintain access. Configure data exfiltration via archive accounts pointing to attacker-controlled infrastructure (e.g., 79.141.169.187) (FortiGuard Advisory).[ADDED] /data/lib/liblog.so — MD5: 64c90a00c7fda4d5c7973ed64c25783a, SHA256: 8015f34dc84922b03688399d7f9fe7a00361789f7e420c7e2a2cdb23e75cef84[MODIFIED] /bin/smit — MD5: 5241738a3e9988404239e12243f6d35b, SHA256: 77324ac428bde86d351fc5fc06f6d64a6bfe737dfb2743df1d4c5ac2418a5b6a[ADDED] /data/bin/webconsole — MD5: ae0ea6502d3fa5f0664bceb73189eb54, SHA256: 7a6cea9f5c9e2e9994d4e3c4da73f86cf5acd05ea5d312c066c9d1dafd69ee38[ADDED] /data/bin/mailservice — MD5: f90fa81a5f521d785f2b2f765e3ab897, SHA256: 4000276a150a165d3c2537d1e19fb393c4de8333076a16655e28059cae82157b[MODIFIED] /data/etc/httpd.conf — MD5: 61af1c4bce1c2eebc8ff689ca5337791, SHA256: 703e97c64e61e41dc3aaba580d82bb2aa7b6a11b54ee6fb467ed5d5a3bffdef5[ADDED] /data/etc/ld.so.preload — MD5: 8eb64f25d2a8e18e05aae058629473cf, SHA256: 8953ec7960b09f544a880b072ad4e6cfda7a8303f486251d3478dcfdfbac23b6[MODIFIED] /data/migadmin.tar.gz — MD5: 49a7156a7d043cc8f9f680579db22f86, SHA256: d6fe51c22b91776f4c961ea58bcac5917f15d560a619d7ce726d3d51795609d379.141.169.187 (attacker-controlled archive/exfiltration server)45.129.0.192type=event subtype=system pri=debug user=system ui=cron msg="(root) CMD (/bin/sh -c 'O=/migadmin ..." — indicates cron-based persistencetype=kevent subtype=config ... msg="Added 'archive234' to 'archive account' ... remote-ip[79.141.169.187]" — unauthorized archive account creation pointing to attacker IPtype=kevent subtype=admin ... action=logout status=success reason=unknown msg="User admin logged out from (null)." — anomalous admin session activityFortiMail::IBE::DecrypterMediaIn ... Caught BufferException(2) ... Invalid Base64 Encoding — may indicate exploitation attemptsInternal user *@domain.tld failed to log in — potential credential probing (FortiGuard Advisory)Fortinet has released patched versions and organizations should upgrade immediately: FortiMail 8.0 → 8.0.2 or later; FortiMail 7.6 → 7.6.7 or later; FortiMail 7.4 → 7.4.9 or later; FortiMail 7.2 → upgrade to branch 7.4 or above (no 7.2.x patch available). As an immediate workaround, disable the IBE feature via CLI: config system encryption ibe → set status disable → end. Alternatively, restrict or block internet access to the FortiMail management interface, limiting access to trusted private networks only. CISA's BOD 26-04 requires federal agencies to apply mitigations by October 4, 2026, and also mandates forensic triage of potentially compromised systems (FortiGuard Advisory, CISA KEV).
Fortinet's PSIRT published advisory FG-IR-26-175 on October 1, 2026, confirming active exploitation and urging immediate mitigation (FortiGuard Advisory). BleepingComputer reported on the zero-day attacks, generating significant community discussion on Reddit (r/SecOpsDaily), Mastodon, and Bluesky (BleepingComputer). Security researchers at watchTowr published an FAQ on the vulnerability, and runZero published a blog post on detection and asset identification. The CISA KEV tracker Mastodon account flagged the addition immediately, and the security community broadly characterized this as a high-urgency incident given the three-day remediation window imposed by CISA's BOD 26-04.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."