Emergency Security Bulletin: Unauthenticated Arbitrary File Write via Path Traversal in Fortinet FortiMail

https://www.redlegg.com/hubfs/Theme-2024/overlay-red.png featured image

By: RedLegg's Cyber Threat Intelligence Team

About:

CVE-2026-104286 is a critical path traversal and NULL byte handling vulnerability affecting Fortinet FortiMail.

An unauthenticated attacker can exploit the vulnerability through crafted HTTP or HTTPS requests to write arbitrary files to the underlying system. Fortinet has confirmed active exploitation, and CISA has added CVE-2026-104286 to its Known Exploited Vulnerabilities (KEV) Catalog.

Patched versions are not currently available for affected FortiMail 7.4, 7.6, and 8.0 branches, while the 7.2 branch will require migration. Until fixes are released, Fortinet recommends disabling IBE feature support as the primary workaround and restricting management interface access to trusted networks.

RedLegg will occasionally communicate vulnerabilities released outside the usual release schedule to provide additional value to our customers. These emergency bulletins describe vulnerabilities or threats we classify as the highest severity level and warrant out-of-band emergency patching or mitigation action.


VULNERABILITIES

Unauthenticated Arbitrary File Write via Path Traversal in Fortinet FortiMail

Identifier: CVE-2026-104286
PoC or Exploitation: Confirmed actively exploited. Fortinet reports this vulnerability has been exploited in the wild. CISA added this vulnerability to its Known Exploited Vulnerabilities catalog.
CVSS Score: 9.8 (Critical, CVSS v3.1)

Update / Patch:

No patched version is currently available for most affected branches. Fortinet's workaround is the only remediation available at this time.
 
Affected versions include:
FortiMail 8.0.0 through 8.0.1
FortiMail 7.6.0 through 7.6.6
FortiMail 7.4.0 through 7.4.8
FortiMail 7.2.0 through 7.2.9
 
Fixed versions include:
FortiMail 8.0.0 through 8.0.1: fix upcoming in 8.0.2 or above, not yet available
FortiMail 7.6.0 through 7.6.6: fix upcoming in 7.6.7 or above, not yet available
FortiMail 7.4.0 through 7.4.8: fix upcoming in 7.4.9 or above, not yet available
FortiMail 7.2.0 through 7.2.9: no fix for this branch; migrate to branch 7.4 or above, noting 7.4 itself has no released fix yet either
 
No virtual patch or IPS signature is currently available for this vulnerability.
 
Workaround - currently the only available remediation:
Disable IBE feature support, either via the GUI under Encryption, then IBE, then setting IBE Service to off, or using the CLI commands config system encryption ibe, set status disable, end.
Alternatively or in addition, disable access to the FortiMail management interface from the internet, or restrict access to a trusted private network only.
 
Fortinet PSIRT Advisory FG-IR-26-175:


Description:
 CVE-2026-104286 is a path traversal and NULL byte handling vulnerability in Fortinet FortiMail.
An unauthenticated attacker can exploit this flaw to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. 

Mitigation Recommendation:

Apply the IBE-disable workaround immediately on all affected FortiMail appliances.
 
If IBE cannot be disabled, restrict access to the FortiMail management interface so it cannot be reached from the internet.
 
Check for the following file-integrity indicators of compromise on FortiMail appliances.
 
Review encryption logs for BufferException errors referencing invalid Base64 encoding in the IBE decryption path.
 
Block outbound and inbound traffic to the known indicator IP addresses 79.141.169.187 and 45.129.0.192 at the network perimeter.
 
Monitor Fortinet's advisory for the release of patched versions for the 7.4, 7.6, and 8.0 branches and apply them as soon as they become available.