Open Door: Critical FortiMail Zero-Day Exploited to Write Arbitrary Files
Fortinet has disclosed CVE-2026-104286, a critical unauthenticated path traversal and NULL-byte handling vulnerability in FortiMail that allows arbitrary file writes via crafted HTTP or HTTPS requests. The issue is reported as exploited in the wild and is listed in the CISA KEV catalog. This article covers impact, affected versions, workarounds, fixed-build guidance, and indicators of compromise.
Summary
Fortinet has published advisory FG-IR-26-175 for CVE-2026-104286, a critical vulnerability involving path traversal and improper NULL-byte handling in FortiMail. The vulnerability allows an unauthenticated attacker to write arbitrary files to the underlying system through crafted HTTP or HTTPS requests. Fortinet reports that the vulnerability has been exploited in the wild. The flaw has also been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. Until fixed builds are applied, Fortinet urges customers to use the published workarounds.
Vulnerability Details
| CVE ID | CVSS Score | EPSS Score | Type |
|---|---|---|---|
| CVE-2026-104286 | 9.8 | 2.201% | CWE-22: Path Traversal CWE-158: Improper Neutralization of NULL Byte or NULL Character |
Technical Information
Critical Zero-Day Unauthenticated No User Interaction Actively Exploited Path Traversal
CVE-2026-104286 — Improper Limitation of a Pathname to a Restricted Directory
An improper limitation of a pathname to a restricted directory (path traversal) combined with improper neutralization of a NULL byte or NULL character may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
Fortinet lists the affected component as the GUI and the attack type as unauthenticated. The published impact is execute unauthorized code or commands.
Impact
- Arbitrary file write leading to system compromise An unauthenticated attacker with network access to the FortiMail interface over HTTP or HTTPS can write arbitrary files on the underlying system. That can enable unauthorized code or command execution and further post-exploitation activity on the host.
Affected Versions
As per the Fortinet advisory :
| Version | Affected |
|---|---|
| FortiMail 8.0 | 8.0.0 through 8.0.1 |
| FortiMail 7.6 | 7.6.0 through 7.6.6 |
| FortiMail 7.4 | 7.4.0 through 7.4.8 |
| FortiMail 7.2 | 7.2.0 through 7.2.9 |
MITRE ATT&CK Mapping
| Technique ID | Technique Name | Tactic ID | Tactic |
|---|---|---|---|
| T1190 | Exploit Public-Facing Application | TA0001 | Initial Access |
| T1105 | Ingress Tool Transfer | TA0011 | Command and Control |
Mitigation and Recommendations
Fortinet urges customers to apply the workaround below and to upgrade when fixed builds are available.
Workaround
Disable the IBE feature via the GUI (Encryption → IBE → IBE Service set to off) or with the following CLI commands:
config system encryption ibeset status disableend
Alternatively:
- Disable access to the FortiMail webmail interface from the internet, or limit access to trusted private networks only.
- If a web application firewall sits in front of FortiMail, block POST requests to
/ibethat contain../.
Fixed builds
- FortiMail 8.0.2 or above (upcoming)
- FortiMail 7.6.7 or above (upcoming)
- FortiMail 7.4.9 or above (upcoming)
- FortiMail 7.2.x: upgrade to branch 7.4 or above
Recommended actions
- Apply the IBE disable workaround immediately on affected systems if a fixed build is not yet installed.
- Restrict internet exposure of FortiMail webmail and management interfaces where possible.
- Upgrade to a fixed build when Fortinet releases the listed versions for the branch in use.
- Check systems for the indicators of compromise listed below to identify potential compromise.
Indicators of Compromise
Fortinet published the following Indicators of Compromise (IoCs):
IP addresses:
79.141.169.18745.129.0.192
System event logs:
type=event subtype=system pri=debug user=system ui=cron msg="(root) CMD (/bin/sh -c 'O=/migadmin ...type=kevent subtype=admin pri=information user=admin ui=(null) action=logout status=success reason=unknown msg="User admin logged out from (null)."type=kevent subtype=config pri=information user=admin ui=cli module=unknown submodule=unknown msg="Added 'archive234' to 'archive account' : rotation-size[50]rotation-time[1] rotation-hour[14]destination[remote]remote-ip[79.141.169.187]remote-username[archive234]remote-password[***]remote-directory[/uploads] (user: admin, from: cli)"
Encryption logs:
FortiMail::IBE::DecrypterMediaIn::DecrypterMediaIn(FortiMail::MediaIn&, const FortiMail::IBE::KeyFinder&, const FortiMail::EmailAddress&, const FortiMail::Buffer&, FortiMail::IBE::DecrypterMediaIn::Version): Caught BufferException(2), BufferImpl.cpp:973, 'Invalid Base64 Encoding at pos 0. Character=0x2a'Internal user *@domain.tld failed to log in.
Instantly Fix Risks with Saner Patch Management
Saner patch management is a continuous, automated, and integrated solution that helps you quickly remediate risks, including critical network infrastructure updates. It supports Windows, Linux, macOS, and 550+ third-party applications.
You can stage patches in a safe testing environment before production deployment and roll back if needed.
Experience the fastest and most accurate patching software here.




