Fortinet FortiMail critical path traversal flaw CVE-2026-104286 (FG-IR-26-175) exploited in zero-day attacks

Fortinet FortiMail critical path traversal flaw (TL-2026-2830), also tracked as FG-IR-26-175, is a critical-severity zero-day vulnerability scored CVSS 9.8, first published 2026-10-01. It has no confirmed attribution, affects Fortinet FortiMail, references 1 CVE (CVE-2026-104286), maps to 7 MITRE ATT&CK techniques (T1020, T1036.005, T1114), and is covered by 9 detection rules and 17 indicators of compromise.

Key facts for TL-2026-2830

Threat ID
TL-2026-2830
Also known as
FG-IR-26-175
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
ZERO_DAY
First published
2026-10-01
Last reviewed
2026-10-01
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
government administration, enterprise, email-infrastructure
Target regions
Global
Detection rules
9
Indicators of compromise
17

Fortinet disclosed CVE-2026-104286 (CVSS 9.8), a path traversal / NULL byte neutralization flaw in the FortiMail management interface that lets unauthenticated attackers write arbitrary files via crafted HTTP/HTTPS requests. Fortinet confirmed zero-day exploitation and CISA added the CVE to the KEV catalog with a federal remediation deadline of 2026-10-04.

How Fortinet FortiMail critical path traversal flaw works

CVE-2026-104286 (Fortinet PSIRT FG-IR-26-175) is a combination of CWE-22 (path traversal) and CWE-158 (improper neutralization of NULL byte or NUL character) in the FortiMail management interface. An unauthenticated remote attacker can write arbitrary files on the underlying system through crafted HTTP or HTTPS requests. The CVSS v3.1 base score is 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H); Fortinet's temporal vector is E:P/RL:O/RC:C. NVD (published 2026-10-01 20:17 UTC) marks exploitation as active, the flaw as automatable, and technical impact as total.

Fortinet states the flaw is exploited in the wild as a zero-day. The advisory credits Gwendal Guegniaud of the Fortinet Product Security team, so the issue was found internally. The advisory lists two source IPs associated with the attacks (79.141.169.187 and 45.129.0.192) and a set of files added or modified on compromised appliances: /data/lib/liblog.so, /data/etc/ld.so.preload, /bin/smit, /data/bin/webconsole, /data/bin/mailservice, /data/etc/httpd.conf and /data/migadmin.tar.gz (SHA-256 hashes recorded in the IOC list). The combination of an added shared library, an added ld.so.preload entry, a modified system binary and a modified web server configuration indicates that the arbitrary file write was used to implant persistent, preloaded code on the appliance.

BleepingComputer additionally reports that compromised systems showed archive account configurations pointing to 79.141.169.187 for remote data exfiltration via the /uploads directory, i.e. the appliance's mail archiving function was reconfigured to ship data to attacker infrastructure. The advisory does not attribute the activity to a named actor, name a malware family, or describe the payload's function; none is asserted here. CISA lists known ransomware campaign use as Unknown. BeaconBeagle returned 404 (no record) for 79.141.169.187.

Affected versions per Fortinet: FortiMail 8.0.0-8.0.1, 7.6.0-7.6.6, 7.4.0-7.4.8 and 7.2.0-7.2.9. The NVD CPE data additionally spans 7.0.0-7.0.9. Fixed releases are 8.0.2, 7.6.7 and 7.4.9; BleepingComputer describes them as pending/upcoming, while the PSIRT table lists them as the fixed versions. FortiMail 7.2 users must migrate to 7.4 or later. Workarounds are to disable the IBE (identity-based encryption) feature (config system encryption ibe / set status disable) and to restrict management interface access to trusted private networks, with no Internet-facing management exposure. CISA added the CVE to the KEV catalog on 2026-10-01 with a due date of 2026-10-04 and directs agencies to apply vendor mitigations per BOD 26-04 or discontinue use of the product if mitigations are unavailable; BleepingComputer notes agencies must perform forensic triage and mitigation. Fortinet says it is communicating with relevant government organizations, including CISA.

MITRE ATT&CK techniques used in TL-2026-2830

Exfiltration

T1020 Automated Exfiltration

Defense Evasion

T1036.005 Match Legitimate Resource Name or Location; T1574.006 Dynamic Linker Hijacking

Collection

T1114 Email Collection

Initial Access

T1190 Exploit Public-Facing Application

Persistence

T1505 Server Software Component; T1554 Compromise Host Software Binary

stealth

T1574.006 Dynamic Linker Hijacking

Affected products and versions in Fortinet FortiMail critical path traversal flaw

  • Fortinet — FortiMail
    Vulnerable versions: 8.0.0-8.0.1; 7.6.0-7.6.6; 7.4.0-7.4.8; 7.2.0-7.2.9; 7.0.0-7.0.9 (NVD record only)
    Fixed in: 8.0.2; 7.6.7; 7.4.9; 7.2 users: upgrade to 7.4 or later

Remediation for Fortinet FortiMail critical path traversal flaw

Patches

  • Upgrade FortiMail 7.4 to 7.4.9 or later
  • Upgrade FortiMail 7.6 to 7.6.7 or later
  • Upgrade FortiMail 8.0 to 8.0.2 or later
  • Migrate FortiMail 7.2 to 7.4 or later

Immediate actions

  • Disable the IBE feature: config system encryption ibe / set status disable
  • Restrict FortiMail management interface access to trusted private networks and remove Internet-facing management exposure
  • Block 79.141.169.187 and 45.129.0.192 and hunt for the Fortinet-listed IOC files and hashes on appliances
  • Review FortiMail archive account configurations for entries pointing to 79.141.169.187 or other unrecognized destinations
  • Perform forensic triage of appliances per CISA/BOD 26-04 guidance before and after mitigation

Workarounds

  • Disable IBE support
  • Allow management interface access from trusted networks only

Longer-term hardening

  • Keep FortiMail management planes off the public Internet
  • Monitor appliance file integrity for unexpected shared libraries and ld.so.preload entries

CVEs associated with Fortinet FortiMail critical path traversal flaw

CVE-2026-104286

Weaknesses (CWE) in Fortinet FortiMail critical path traversal flaw

CWE-22, CWE-158

Timeline of Fortinet FortiMail critical path traversal flaw

  • Fortinet states it is communicating with relevant government organizations, including CISA, about the exploitation.
  • BleepingComputer reports the zero-day exploitation, listing attacker IPs 79.141.169.187 and 45.129.0.192, the modified/added files, and archive account configurations pointing to 79.141.169.187 for exfiltration via /uploads.
  • CISA adds CVE-2026-104286 to the Known Exploited Vulnerabilities catalog; known ransomware campaign use is listed as Unknown; required action references BOD 26-04.
  • Fixed FortiMail releases 7.4.9, 7.6.7 and 8.0.2 are named in the advisory (BleepingComputer describes them as pending); FortiMail 7.2 users are told to migrate to 7.4 or later.
  • NVD publishes the CVE-2026-104286 record at 20:17 UTC (CVSS 3.1 base 9.8, CWE-22; CPE ranges 7.0.0 through 8.0.1) and updates it about an hour later.
  • Fortinet publishes PSIRT advisory FG-IR-26-175 for CVE-2026-104286, confirming active exploitation in the wild; the flaw was found internally by Fortinet Product Security (credit: Gwendal Guegniaud).
  • CISA federal agency remediation deadline: apply vendor mitigations per BOD 26-04 and perform forensic triage, or discontinue use of the product.

Sources cited for Fortinet FortiMail critical path traversal flaw

More in zero day

Detection coverage for TL-2026-2830

As of 2026-10-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2830 across Splunk SPL, Microsoft KQL and Sigma, covering 17 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats