T

Threats

Fortinet FortiMail Critical Path Traversal Vulnerability

Overview

  • CVE: CVE-2026-104286

  • Severity: Critical

  • CVSS: 9.8, CVSS

  • Vendor / Product: Fortinet FortiMail

  • Advisory publication date: 2 October 2026

Fortinet has disclosed one critical vulnerability in FortiMail, rated CVSS 9.8. An unauthenticated attacker can use crafted HTTP or HTTPS requests to write arbitrary files on affected systems, with unauthorised code or command execution listed as the impact. Fortinet reports exploitation in the wild and urges customers to apply its workarounds while the identified fixed releases remain listed as upcoming.


Affected Versions

The following ranges and upgrade targets are specified in Fortinet's FortiMail security advisory FG-IR-26-175. Fortinet describes 8.0.2, 7.6.7 and 7.4.9 as upcoming, not as already available patches.

FortiMail 8.0

FortiMail 7.6

FortiMail 7.4

FortiMail 7.2

  • Affected: 7.2.0 through 7.2.9.

  • Fixed: No patched 7.2 release is listed. Fortinet directs customers to migrate to branch 7.4 or above. Select a release identified as fixed in the destination branch, such as upcoming 7.4.9 or above, once available. Moving to an affected 7.4, 7.6 or 8.0 release does not resolve this vulnerability.

  • Source: Fortinet FortiMail 7.2 affected versions and migration guidance.

Not affected: The advisory does not explicitly list unaffected version ranges, platforms or configurations. Disabling IBE or restricting management-interface access is vendor workaround guidance, not a statement that the installed firmware is fixed.

Vulnerability Breakdown

CVE-2026-104286 - Path traversal and NULL-byte handling

  • Severity: Critical.

  • CVSS: 9.8, CVSS v3.

  • Description: Improper pathname restriction, CWE-22, and improper neutralisation of NULL bytes or characters, CWE-158, allow an unauthenticated attacker to write arbitrary files on the underlying system using crafted HTTP or HTTPS requests.

  • Impact: Arbitrary file writes. Fortinet also lists unauthorised code or command execution as the impact.

  • Conditions: The attack is unauthenticated and uses HTTP or HTTPS requests against an affected FortiMail system. The advisory identifies the GUI component.

  • Notes: Fortinet reports exploitation in the wild and provides indicators of compromise. It lists no virtual patch.

Mitigation

  • Apply an immediate workaround. Fortinet recommends disabling Identity-Based Encryption, IBE, feature support. Its CLI sequence is: config system encryption ibe, then set status disable, then end. Follow the Fortinet IBE workaround instructions.

  • Alternatively, restrict management access. Disable access to the FortiMail management interface from the internet, or limit access to a trusted private network, as directed in the Fortinet management-interface workaround.

  • Prepare the firmware upgrade. Confirm availability of the fixed release for your branch and follow the vendor's supported upgrade path. FortiMail 7.2 customers must plan a move to a fixed release in branch 7.4 or above. Use the Fortinet security advisory's solution matrix, not a generic recommendation to install any newer version.

  • Back up before upgrading. Fortinet's FortiMail 8.0.0 release notes and upgrade guidance direct administrators to back up configuration and stored data before a firmware change, and verify the version and build afterwards. These notes are upgrade-planning context; 8.0.0 is affected by this vulnerability.

  • Review indicators of compromise. Check the file, IP and log indicators published in the Fortinet advisory's indicators of compromise. Escalate any matches for incident investigation.

Summary for IT Teams

  • Products: Fortinet FortiMail 8.0, 7.6, 7.4 and 7.2, within the affected ranges above.

  • Threat Level: Critical, CVSS 9.8. Exploitation in the wild is confirmed by Fortinet.

  • Action Required: Apply the IBE or management-access workaround now. Review the vendor's indicators of compromise. Upgrade to the appropriate fixed release when available, following the supported upgrade path.

Reference

Need Help?

If your organisation needs assistance assessing FortiMail exposure, applying workarounds or investigating indicators of compromise, the Secure ISS SOC team is ready to help.

Call 1300 769 460 or email the Secure ISS SOC team. We are here to help you strengthen your cybersecurity posture.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.