AI description
CVE-2026-104286 is a path traversal and NULL byte neutralization vulnerability affecting the web management interface of Fortinet FortiMail. The flaw allows an unauthenticated attacker to send crafted HTTP or HTTPS requests to write arbitrary files outside of intended directories on the underlying system. By placing files onto the system, attackers can potentially execute unauthorized commands or code, which could lead to full control over the mail gateway. The vulnerability affects FortiMail versions 7.2.0 through 7.2.9, 7.4.0 through 7.4.8, 7.6.0 through 7.6.6, and 8.0.0 through 8.0.1. It has been added to the Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog following reports of active exploitation in the wild. To mitigate the issue, Fortinet recommends disabling Identity-Based Encryption (IBE) support or restricting access to the FortiMail management interface from the internet until official patches are released.
- Description
- An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
- Source
- psirt@fortinet.com
- NVD status
- Analyzed
- Products
- fortimail
CVSS 3.1
- Type
- Secondary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
Data from CISA
- Vulnerability name
- Fortinet FortiMail Path Traversal Vulnerability
- Exploit added on
- Oct 1, 2026
- Exploit action due
- Oct 4, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- psirt@fortinet.com
- CWE-22
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
4
🐦 🚨 Two actively exploited 0-days hit CISA KEV: Fortinet FortiMail CVE-2026-104286 (CVSS 9.8, path traversal → arbitrary file write) and Cisco Catalyst SD-WAN Manager CVE-2026-76504 (auth bypass → admin access). Patch immediately. #infosec #CVE #KEV
@ita_ipo
2 Oct 2026
23 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Critical FortiMail zero-day exploited in the wild (CVE-2026-104286) www.helpnetsecurity.com/2026/10/02/fortinet-fortimail-vulnerability-cve-2026-104286/ https://t.co/i80PDHV9AC
@TheCyberSecHub
2 Oct 2026
1432 Impressions
0 Retweets
4 Likes
0 Bookmarks
0 Replies
0 Quotes
Critical FortiMail zero-day exploited in the wild (CVE-2026-104286): Fortinet is warning customers that attackers are exploiting a zero-day vulnerability (CVE-2026-104286) in FortiMail, its… www.helpnetsecurity.com/2026/10/02/fortinet-fortimail-vulnerability-cve-2026-1042
@shah_sheikh
2 Oct 2026
39 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 FortiMail Path Traversal Flaw CVE-2026-104286 Exploited in the Wild Critical Vulnerability Alert! Fortinet FortiMail is affected by CVE-2026-104286. 🔍 Identify Targets via ZoomEye: Search Dork: app="FortiMail" Exposure: 3.9k instances identified globally. ZoomEye Sear
@zoomeyebot
2 Oct 2026
21 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
FortiMail CVE-2026-104286 FortiMail is supposed to stop the payload. This time, FortiMail was the payload. CVE-2026-104286: no auth → path traversal/null-byte bug → arbitrary file write → preload persistence → attacker-controlled archiving. Actively exploited as a 0-d
@zeeshankghouri
2 Oct 2026
61 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CRITICAL: CVE-2026-104286 - Fortinet FortiMail path traversal flaw allows unauthenticated attackers to write arbitrary files via crafted requests. CISA KEV listed. Patch immediately. #CVE #PatchNow #ThreatIntel https://t.co/lAFs2ZDo0I
@DFIR_Lab
2 Oct 2026
26 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Fortinet disclosed CVE-2026-104286, a critical FortiMail flaw with a 9.8 CVSS score, actively exploited in zero-day attacks to write files and run unauthorized code. #Fortinet #FortiMail #CVE-2026-104286 https://t.co/jozYbbZ4JR
@TweetThreatNews
2 Oct 2026
200 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-104286: Critical Arbitrary File Write in Fortinet FortiMail Fortinet FortiMail faces a critical path traversal flaw (CVE-2026-104286) allowing unauthenticated attackers to drop files via HTTP. Full write-up → link in bio #cybersecurity #infosec #cve #kev #fortinet ht
@HotaSamit
2 Oct 2026
27 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2026-104286: Fortinet FortiMail Path Traversal Actively Exploited — Detecti… "On October 1, 2026, CISA added CVE-2026-104286 to the Known Exploited…" 🔗 https://t.co/LExvAUQlX8 #CyberSecurity #ThreatIntel #cve2026104286 #critical #cisakev
@SecurityAr58409
2 Oct 2026
34 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
NØØT Security Alerts Classification: High CVE: CVE-2026-104286 Product: See CISA advisory Summary: The advisory involves CVE-2026-104286. Priority should be given to identifying exposed systems and validating whether they are actually affected. Evidence: active exploitation;
@Python_s_
1 Oct 2026
38 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:fortinet:fortimail:*:*:*:*:*:*:*:*",
"matchCriteriaId": "77C9CE10-1038-4100-81E0-234822E6373B",
"versionEndIncluding": "7.4.8",
"versionStartIncluding": "7.2.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:fortinet:fortimail:*:*:*:*:*:*:*:*",
"matchCriteriaId": "1EA73418-A7A1-4247-BA3E-969550962E0E",
"versionEndIncluding": "7.6.6",
"versionStartIncluding": "7.6.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:fortinet:fortimail:*:*:*:*:*:*:*:*",
"matchCriteriaId": "DDAF1B20-36CA-4DD4-9483-6B605001B9DA",
"versionEndIncluding": "8.0.1",
"versionStartIncluding": "8.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]