Critical Path Traversal in Fortinet FortiMail Under Active Exploitation (CVE-2026-104286)
Executive Summary
On October 1st, 2026, Fortinet disclosed a critical vulnerability in its FortiMail email security gateway and confirmed it has been exploited in the wild. Tracked as CVE-2026-104286, the flaw lets an unauthenticated, remote attacker write arbitrary files to the underlying system through crafted HTTP or HTTPS requests, which Fortinet states can lead to the execution of unauthorized code or commands. CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog the same day.
FortiMail sits in the mail flow of the organizations that deploy it, inspecting every inbound and outbound message. A compromised appliance gives an attacker a persistent position with direct access to email traffic. Indicators published by Fortinet show attackers implanting persistent code and reconfiguring mail archiving to send copies of messages to attacker infrastructure. Fortinet has named fixed versions, but at the time of writing they are listed as upcoming releases.
Given confirmed zero-day exploitation, the sensitivity of the mail these appliances process, and the frequent targeting of Fortinet edge devices, Beazley Security recommends affected organizations apply the vendor workarounds immediately, upgrade as soon as fixed releases ship, and conduct a thorough review for any signs of compromise.
Affected Systems and Products
Fortinet has confirmed in their advisory that the following versions of FortiMail are vulnerable if they have Identity-Based Encryption (IBE) enabled. This appears to be predicated on the web interface for FortiMail being present and internet accessible. We do not see information that identifies the SMTP component being compromised by this vulnerability.
Product
Affected Version
Fixed Version
FortiMail 8.0
8.0.0 through 8.0.1
8.0.2 or above (upcoming)
FortiMail 7.6
7.6.0 through 7.6.6
7.6.7 or above (upcoming)
FortiMail 7.4
7.4.0 through 7.4.8
7.4.9 or above (upcoming)
Disable IBE feature support from the FortiMail CLI:
config system encryption ibe set status disable end
Disable access to the FortiMail management interface from the internet, or restrict it to trusted private networks only.
Neither workaround removes an attacker who has already compromised the appliance. Before changing configurations, export logs and configuration so evidence is preserved. FortiMail 7.2 customers should note that moving to the 7.4 branch only remediates the flaw once 7.4.9 is installed, since current 7.4 builds remain vulnerable.
Patches
Fortinet has identified FortiMail 8.0.2, 7.6.7, and 7.4.9 as the fixed releases, but they had not shipped at the time of writing. A single upgrade to the fixed release for your branch remediates the vulnerability. Additional information, including release availability, can be found in the official Fortinet advisory FG-IR-26-175.
Indicators of Compromise (IOCs)
The same day as the Fortinet's disclosure CISA added CVE-2026-104286 to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild. Fortinet has not attributed the activity, disclosed when it began, or stated how many organizations were affected.
Fortinet's indicators point to attackers using file writes to establish persistence on the appliance. Review FortiMail systems for the following files, and compare them against the MD5 and SHA256 hashes:
The presence of /data/etc/ld.so.preload or /data/lib/liblog.so is a strong signal of compromise. A preloaded library can hide attacker processes, so a clean process listing on a suspect appliance should not be considered proof of a system being uncompromised.
Fortinet also observed attackers creating a remote mail archive account (named "archive234" in the published sample) that sends archived mail to 79.141.169[.]187 under the /uploads directory.Review archive accounts in the GUI:
For remote destinations or forwarding addresses your team did not configure, along with the archive policies that send mail to them. Search event logs and firewall records for connections involving 79.141.169[.]187 and 45.129.0[.]192, root cron entries referencing /migadmin, admin logouts recorded from a "(null)" interface, IBE decryption errors reporting invalid Base64 data, and admin CLI changes that your organization did not create. The paths listed below are what Fortinet identify as patterns of attack:
Internal user *@domain.tld<mailto:*@domain.tld> failed to log in.
Observed attacker IPs
79[.]141.169.187
45[.]129.0.192
Treat any appliance with a matching indicator as compromised. Fortinet has not published cleanup guidance; in that case, rebuild the appliance from known good firmware and rotate administrator passwords, archive server credentials, and any Microsoft 365 or Google Workspace credentials stored for API integration.
Technical Details
Fortinet discovered the vulnerability internally, crediting Gwendal Guégniaud of its Product Security team, and has released limited technical details. The flaw combines a path traversal weakness with improper handling of NULL bytes in the FortiMail web interface. NULL byte flaws of this kind cause the software to treat input as ended before the input is actually terminated. That behavior enables traversal sequences to bypass validation, and attackers can then leverage the file system to write a file outside its intended directory.
No authentication or user interaction is required, only network access to the FortiMail web interface. Fortinet lists the impact as execution of unauthorized code or commands, and the observed indicators show an added shared library registered for preloading, replaced system binaries, and a modified web server configuration. No working public proof-of-concept is known to be available at the time of writing.
How Beazley Security is Responding
Beazley Security is monitoring client perimeter devices through our Exposure Management Platform to identify impacted devices and support organizations in remediation of any issues found.
We are also conducting threat hunts across our MDR environment to detect potential exploitation attempts against our clients.
If you believe your organization may have been impacted by this attack campaign and need support, please contact our Incident Response team.