ZeroDayAlert

CVE-2026-104286: Fortinet FortiMail Path Traversal Vulnerability

Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

Fortinet FortiMail Added to KEV 2026-10-01 Federal due 2026-10-04 Known ransomware use

Required action — quoted from CISA

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Where this comes from. The identifier, product, dates and required action above are copied verbatim from the CISA Known Exploited Vulnerabilities catalog. The action plan below is written by an AI agent from that record and published automatically. AssurePort has not independently tested this vulnerability and makes no claim about whether any specific system is affected.

Who is affected

Fortinet FortiMail is targeted. The vulnerability allows an unauthenticated attacker to write arbitrary files to the system via crafted HTTP or HTTPS requests, meaning any FortiMail instance reachable over the network—whether on-premises or cloud-hosted—is at risk. The record does not specify affected version ranges, patch availability timelines, or whether specific deployment modes (gateway, appliance, or cloud service variant) carry different risk.

How to check whether this touches you

  • Inventory: search your asset register and network diagrams for any FortiMail deployment, including backup or secondary instances, and note whether each is internet-facing.
  • Reachability: confirm whether your FortiMail instances accept HTTP or HTTPS connections from untrusted networks (the public internet, partner networks, or cloud infrastructure you do not control).
  • Version confirmation: log into each FortiMail admin interface and record the running firmware version; this is a signal only—Fortinet may have backported fixes to multiple release lines.
  • Patch status: check Fortinet's security advisory for the affected versions and available patches; cross-reference your inventory against that list.

What to do

  1. Obtain Fortinet's official security advisory for CVE-2026-104286 and confirm which versions are affected and which patches are available.
  2. If your instances are internet-facing and you cannot patch immediately, restrict HTTP and HTTPS access to FortiMail to a whitelist of trusted source IP addresses or move the service behind a network boundary that filters untrusted inbound traffic.
  3. Enable detailed request logging on FortiMail, capturing the full HTTP method, URL path, headers, and source IP for all requests; retain logs for at least 90 days.
  4. Plan patching according to CISA BOD 26-04 guidance (federal deadline 4 October 2026 if this is a federal system; others should treat it as critical priority). If patches are unavailable or cannot be deployed within your change window, escalate to your security and business continuity teams to evaluate discontinuing use of the product.

If you find you were exposed

Exploitation of path traversal flaws often precedes public disclosure by weeks or months, so assume your logs may contain evidence of attack attempts dating back several months before this advisory. Focus your forensic triage on the periods when the service was publicly routable and logs were retained; search for requests containing path traversal sequences (such as ../, URL-encoded variants, or NULL bytes) or attempts to write files to unexpected locations. If you discover successful exploitation, treat it as a potential compromise and initiate incident response according to your playbook, including filesystem integrity checks and review of modified files for persistence mechanisms.

Get these the morning they land.

One email, only when a vulnerability is newly confirmed as exploited — the CISA record plus our action plan. No more than one a day, and nothing on quiet days.

Knowing it exists is not the same as knowing you are exposed.

This page can tell you that CVE-2026-104286 is being exploited. It cannot tell you whether FortiMail is running somewhere of yours that is reachable. That question is what a scan answers.

Check your own surface →