Fortinet FortiMail critical path traversal flaw CVE-2026-104286 (FG-IR-26-175) exploited in zero-day attacks
Fortinet FortiMail critical path traversal flaw (TL-2026-2830), also tracked as FG-IR-26-175, is a critical-severity zero-day vulnerability scored CVSS 9.8, first published 2026-10-01. It has no confirmed attribution, affects Fortinet FortiMail, references 1 CVE (CVE-2026-104286), maps to 7 MITRE ATT&CK techniques (T1020, T1036.005, T1114), and is covered by 9 detection rules and 17 indicators of compromise.
Key facts for TL-2026-2830
- Threat ID
- TL-2026-2830
- Also known as
- FG-IR-26-175
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- ZERO_DAY
- First published
- 2026-10-01
- Last reviewed
- 2026-10-01
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, enterprise, email-infrastructure
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 17
Fortinet disclosed CVE-2026-104286 (CVSS 9.8), a path traversal / NULL byte neutralization flaw in the FortiMail management interface that lets unauthenticated attackers write arbitrary files via crafted HTTP/HTTPS requests. Fortinet confirmed zero-day exploitation and CISA added the CVE to the KEV catalog with a federal remediation deadline of 2026-10-04.
How Fortinet FortiMail critical path traversal flaw works
CVE-2026-104286 (Fortinet PSIRT FG-IR-26-175) is a combination of CWE-22 (path traversal) and CWE-158 (improper neutralization of NULL byte or NUL character) in the FortiMail management interface. An unauthenticated remote attacker can write arbitrary files on the underlying system through crafted HTTP or HTTPS requests. The CVSS v3.1 base score is 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H); Fortinet's temporal vector is E:P/RL:O/RC:C. NVD (published 2026-10-01 20:17 UTC) marks exploitation as active, the flaw as automatable, and technical impact as total.
Fortinet states the flaw is exploited in the wild as a zero-day. The advisory credits Gwendal Guegniaud of the Fortinet Product Security team, so the issue was found internally. The advisory lists two source IPs associated with the attacks (79.141.169.187 and 45.129.0.192) and a set of files added or modified on compromised appliances: /data/lib/liblog.so, /data/etc/ld.so.preload, /bin/smit, /data/bin/webconsole, /data/bin/mailservice, /data/etc/httpd.conf and /data/migadmin.tar.gz (SHA-256 hashes recorded in the IOC list). The combination of an added shared library, an added ld.so.preload entry, a modified system binary and a modified web server configuration indicates that the arbitrary file write was used to implant persistent, preloaded code on the appliance.
BleepingComputer additionally reports that compromised systems showed archive account configurations pointing to 79.141.169.187 for remote data exfiltration via the /uploads directory, i.e. the appliance's mail archiving function was reconfigured to ship data to attacker infrastructure. The advisory does not attribute the activity to a named actor, name a malware family, or describe the payload's function; none is asserted here. CISA lists known ransomware campaign use as Unknown. BeaconBeagle returned 404 (no record) for 79.141.169.187.
Affected versions per Fortinet: FortiMail 8.0.0-8.0.1, 7.6.0-7.6.6, 7.4.0-7.4.8 and 7.2.0-7.2.9. The NVD CPE data additionally spans 7.0.0-7.0.9. Fixed releases are 8.0.2, 7.6.7 and 7.4.9; BleepingComputer describes them as pending/upcoming, while the PSIRT table lists them as the fixed versions. FortiMail 7.2 users must migrate to 7.4 or later. Workarounds are to disable the IBE (identity-based encryption) feature (config system encryption ibe / set status disable) and to restrict management interface access to trusted private networks, with no Internet-facing management exposure. CISA added the CVE to the KEV catalog on 2026-10-01 with a due date of 2026-10-04 and directs agencies to apply vendor mitigations per BOD 26-04 or discontinue use of the product if mitigations are unavailable; BleepingComputer notes agencies must perform forensic triage and mitigation. Fortinet says it is communicating with relevant government organizations, including CISA.
MITRE ATT&CK techniques used in TL-2026-2830
Exfiltration
Defense Evasion
T1036.005 Match Legitimate Resource Name or Location; T1574.006 Dynamic Linker Hijacking
Collection
Initial Access
T1190 Exploit Public-Facing Application
Persistence
T1505 Server Software Component; T1554 Compromise Host Software Binary
stealth
Affected products and versions in Fortinet FortiMail critical path traversal flaw
- Fortinet — FortiMail
Vulnerable versions: 8.0.0-8.0.1; 7.6.0-7.6.6; 7.4.0-7.4.8; 7.2.0-7.2.9; 7.0.0-7.0.9 (NVD record only)
Fixed in: 8.0.2; 7.6.7; 7.4.9; 7.2 users: upgrade to 7.4 or later
Remediation for Fortinet FortiMail critical path traversal flaw
Patches
- Upgrade FortiMail 7.4 to 7.4.9 or later
- Upgrade FortiMail 7.6 to 7.6.7 or later
- Upgrade FortiMail 8.0 to 8.0.2 or later
- Migrate FortiMail 7.2 to 7.4 or later
Immediate actions
- Disable the IBE feature: config system encryption ibe / set status disable
- Restrict FortiMail management interface access to trusted private networks and remove Internet-facing management exposure
- Block 79.141.169.187 and 45.129.0.192 and hunt for the Fortinet-listed IOC files and hashes on appliances
- Review FortiMail archive account configurations for entries pointing to 79.141.169.187 or other unrecognized destinations
- Perform forensic triage of appliances per CISA/BOD 26-04 guidance before and after mitigation
Workarounds
- Disable IBE support
- Allow management interface access from trusted networks only
Longer-term hardening
- Keep FortiMail management planes off the public Internet
- Monitor appliance file integrity for unexpected shared libraries and ld.so.preload entries
CVEs associated with Fortinet FortiMail critical path traversal flaw
Weaknesses (CWE) in Fortinet FortiMail critical path traversal flaw
CWE-22, CWE-158
Timeline of Fortinet FortiMail critical path traversal flaw
- Fortinet states it is communicating with relevant government organizations, including CISA, about the exploitation.
- BleepingComputer reports the zero-day exploitation, listing attacker IPs 79.141.169.187 and 45.129.0.192, the modified/added files, and archive account configurations pointing to 79.141.169.187 for exfiltration via /uploads.
- CISA adds CVE-2026-104286 to the Known Exploited Vulnerabilities catalog; known ransomware campaign use is listed as Unknown; required action references BOD 26-04.
- Fixed FortiMail releases 7.4.9, 7.6.7 and 8.0.2 are named in the advisory (BleepingComputer describes them as pending); FortiMail 7.2 users are told to migrate to 7.4 or later.
- NVD publishes the CVE-2026-104286 record at 20:17 UTC (CVSS 3.1 base 9.8, CWE-22; CPE ranges 7.0.0 through 8.0.1) and updates it about an hour later.
- Fortinet publishes PSIRT advisory FG-IR-26-175 for CVE-2026-104286, confirming active exploitation in the wild; the flaw was found internally by Fortinet Product Security (credit: Gwendal Guegniaud).
- CISA federal agency remediation deadline: apply vendor mitigations per BOD 26-04 and perform forensic triage, or discontinue use of the product.
Sources cited for Fortinet FortiMail critical path traversal flaw
More in zero day
- Kiteworks Urges Customers to Shut Down Systems After Federal Threat Intelligence Warning of Possible Zero-Day Attack
- UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880) to Deploy CLEANGULP Malware
- Kiteworks Urges Customers to Take Systems Offline Amid Suspected Zero-Day Threat
- Kiteworks Urges Global Customers to Shut Down Servers for 6-9 Hours Over Federally-Warned Potential Zero-Day Targeting
- Lazarus Exploits CVE-2026-68820 Zero-Day via Malicious PDF Viewer in Operation Dream Job Against Defense Industry
Detection coverage for TL-2026-2830
As of 2026-10-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2830 across Splunk SPL, Microsoft KQL and Sigma, covering 17 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.