SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Open Door: Critical FortiMail Zero-Day Exploited to Write Arbitrary Files

Open Door: Critical FortiMail Zero-Day Exploited to Write Arbitrary Files

Fortinet has disclosed CVE-2026-104286, a critical unauthenticated path traversal and NULL-byte handling vulnerability in FortiMail that allows arbitrary file writes via crafted HTTP or HTTPS requests. The issue is reported as exploited in the wild and is listed in the CISA KEV catalog. This article covers impact, affected versions, workarounds, fixed-build guidance, and indicators of compromise.

Oct 5, 2026By Bapanapalli Prem Sai Siddhik

Summary

Fortinet has published advisory FG-IR-26-175 for CVE-2026-104286, a critical vulnerability involving path traversal and improper NULL-byte handling in FortiMail. The vulnerability allows an unauthenticated attacker to write arbitrary files to the underlying system through crafted HTTP or HTTPS requests. Fortinet reports that the vulnerability has been exploited in the wild. The flaw has also been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. Until fixed builds are applied, Fortinet urges customers to use the published workarounds.

Vulnerability Details

CVE IDCVSS ScoreEPSS ScoreType
CVE-2026-1042869.82.201%CWE-22: Path Traversal
CWE-158: Improper Neutralization of NULL Byte or NULL Character

Technical Information

Critical Zero-Day Unauthenticated No User Interaction Actively Exploited Path Traversal

CVE-2026-104286 — Improper Limitation of a Pathname to a Restricted Directory

An improper limitation of a pathname to a restricted directory (path traversal) combined with improper neutralization of a NULL byte or NULL character may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

Fortinet lists the affected component as the GUI and the attack type as unauthenticated. The published impact is execute unauthorized code or commands.

Impact

  • Arbitrary file write leading to system compromise An unauthenticated attacker with network access to the FortiMail interface over HTTP or HTTPS can write arbitrary files on the underlying system. That can enable unauthorized code or command execution and further post-exploitation activity on the host.

Affected Versions

As per the Fortinet advisory :

VersionAffected
FortiMail 8.08.0.0 through 8.0.1
FortiMail 7.67.6.0 through 7.6.6
FortiMail 7.47.4.0 through 7.4.8
FortiMail 7.27.2.0 through 7.2.9

MITRE ATT&CK Mapping

Technique IDTechnique NameTactic IDTactic
T1190Exploit Public-Facing ApplicationTA0001Initial Access
T1105Ingress Tool TransferTA0011Command and Control

Mitigation and Recommendations

Fortinet urges customers to apply the workaround below and to upgrade when fixed builds are available.

Workaround

Disable the IBE feature via the GUI (Encryption → IBE → IBE Service set to off) or with the following CLI commands:

  • config system encryption ibe
  • set status disable
  • end

Alternatively:

  • Disable access to the FortiMail webmail interface from the internet, or limit access to trusted private networks only.
  • If a web application firewall sits in front of FortiMail, block POST requests to /ibe that contain ../.

Fixed builds

  • FortiMail 8.0.2 or above (upcoming)
  • FortiMail 7.6.7 or above (upcoming)
  • FortiMail 7.4.9 or above (upcoming)
  • FortiMail 7.2.x: upgrade to branch 7.4 or above

Recommended actions

  • Apply the IBE disable workaround immediately on affected systems if a fixed build is not yet installed.
  • Restrict internet exposure of FortiMail webmail and management interfaces where possible.
  • Upgrade to a fixed build when Fortinet releases the listed versions for the branch in use.
  • Check systems for the indicators of compromise listed below to identify potential compromise.

Indicators of Compromise

Fortinet published the following Indicators of Compromise (IoCs):

IP addresses:

  • 79.141.169.187
  • 45.129.0.192

System event logs:

  • type=event subtype=system pri=debug user=system ui=cron msg="(root) CMD (/bin/sh -c 'O=/migadmin ...
  • type=kevent subtype=admin pri=information user=admin ui=(null) action=logout status=success reason=unknown msg="User admin logged out from (null)."
  • type=kevent subtype=config pri=information user=admin ui=cli module=unknown submodule=unknown msg="Added 'archive234' to 'archive account' : rotation-size[50]rotation-time[1] rotation-hour[14]destination[remote]remote-ip[79.141.169.187]remote-username[archive234]remote-password[***]remote-directory[/uploads] (user: admin, from: cli)"

Encryption logs:

  • FortiMail::IBE::DecrypterMediaIn::DecrypterMediaIn(FortiMail::MediaIn&, const FortiMail::IBE::KeyFinder&, const FortiMail::EmailAddress&, const FortiMail::Buffer&, FortiMail::IBE::DecrypterMediaIn::Version): Caught BufferException(2), BufferImpl.cpp:973, 'Invalid Base64 Encoding at pos 0. Character=0x2a'
  • Internal user *@domain.tld failed to log in.

Instantly Fix Risks with Saner Patch Management

Saner patch management is a continuous, automated, and integrated solution that helps you quickly remediate risks, including critical network infrastructure updates. It supports Windows, Linux, macOS, and 550+ third-party applications.

You can stage patches in a safe testing environment before production deployment and roll back if needed.

Experience the fastest and most accurate patching software here.

Featured Posts

Open CVE-2026-90970: GitLab Strengthens AI Gateway Security Following Critical Vulnerability
CVE-2026-90970: GitLab Strengthens AI Gateway Security Following Critical Vulnerability

CVE Research

CVE-2026-90970: GitLab Strengthens AI Gateway Security Following Critical Vulnerability

Oct 5, 2026

Open WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels
WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

CVE Research

WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

Oct 1, 2026

Open OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure
OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure

CVE Research

OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure

Oct 1, 2026

Open Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions
Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions

CVE Research

Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions

Two critical vulnerabilities added to CISA KEV on September 24, 2026 reveal sharply different exploitation timelines. CVE-2026-71362 saw publicly documented exploitation roughly one day after Adobe's patch release, while CVE-2026-5430 had a 133-day vendor-remediation-to-observed-exploitation interval.

Oct 1, 2026