8 min read
By: RedLegg's Cyber Threat Intelligence Team
About:
CVE-2026-104286 is a critical path traversal and NULL byte handling vulnerability affecting Fortinet FortiMail.
An unauthenticated attacker can exploit the vulnerability through crafted HTTP or HTTPS requests to write arbitrary files to the underlying system. Fortinet has confirmed active exploitation, and CISA has added CVE-2026-104286 to its Known Exploited Vulnerabilities (KEV) Catalog.
Patched versions are not currently available for affected FortiMail 7.4, 7.6, and 8.0 branches, while the 7.2 branch will require migration. Until fixes are released, Fortinet recommends disabling IBE feature support as the primary workaround and restricting management interface access to trusted networks.
RedLegg will occasionally communicate vulnerabilities released outside the usual release schedule to provide additional value to our customers. These emergency bulletins describe vulnerabilities or threats we classify as the highest severity level and warrant out-of-band emergency patching or mitigation action.
VULNERABILITIES
Unauthenticated Arbitrary File Write via Path Traversal in Fortinet FortiMail
Identifier: CVE-2026-104286
PoC or Exploitation: Confirmed actively exploited. Fortinet reports this vulnerability has been exploited in the wild. CISA added this vulnerability to its Known Exploited Vulnerabilities catalog.
CVSS Score: 9.8 (Critical, CVSS v3.1)
Update / Patch:
Description:
CVE-2026-104286 is a path traversal and NULL byte handling vulnerability in Fortinet FortiMail.
An unauthenticated attacker can exploit this flaw to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
Mitigation Recommendation: