Fortinet patches a FortiMail zero-day already exploited to write arbitrary files
CVE-2026-104286, rated CVSS 9.8, lets an unauthenticated attacker write arbitrary files on FortiMail's management interface through a path traversal combined with a NULL byte. No fix is out yet — disable IBE and take the admin console off the internet.
October 1, 2026. Fortinet publishes security advisory FG-IR-26-175 warning that CVE-2026-104286, a critical flaw in FortiMail, is already being exploited in zero-day attacks. October 1, 2026. The vulnerability, rated CVSS 9.8, chains a path traversal (CWE-22) with an improper neutralization of a NULL byte (CWE-158) to let an unauthenticated attacker write arbitrary files on the underlying system. October 1, 2026. No patch is available for most branches yet: Fortinet is asking customers to apply an immediate workaround. Why it matters: FortiMail is a mail gateway sitting at the network edge, and an arbitrary file write on its admin console can turn into full device takeover.
A path traversal doubled with a NULL byte
The mechanism fits in a sentence. FortiMail’s management interface does not properly bound the file paths it receives from a client, and mishandles the NULL byte (\0) that some languages use to truncate a string before it is validated. The result: an attacker sending crafted HTTP or HTTPS requests can make the service write files wherever it chooses, with no authentication at all.
The CWE-22 plus CWE-158 pairing is a path traversal classic that keeps resurfacing on network appliances. Path traversal lets a request escape the intended directory (../../), while the NULL byte tricks a validation layer that stops reading at the end of the string. Together, the two turn a mundane input-validation bug into an arbitrary write primitive — the building block of most remote code execution chains.
The danger is amplified by where FortiMail sits. The gateway processes an organization’s mail flow, holds anti-spam policies, encryption keys, and often privileged accounts. An arbitrary file write can drop a webshell on the console, rewrite configuration files, or patch binaries to survive a reboot.
What an arbitrary write actually buys an attacker
An arbitrary file write primitive is not, strictly speaking, code execution — but it almost always leads there. On an appliance like FortiMail, it opens at least three doors.
The first is dropping a webshell: a file placed in a directory served by the admin web server turns the write into command execution. The second is configuration tampering — for instance altering routing or authentication rules to plant a quiet backdoor. The third is persistence through system file corruption: replacing a binary, a startup script, or a certificate so the compromise survives reboots and later patches.
CVE-2026-104286 is all the more serious because Fortinet says it is exploited in the wild, without any public detail yet on scale or attribution. The CVSS vector — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H — spells out the worst case: reachable over the network, no user interaction, no privileges required, and high impact on confidentiality, integrity, and availability.
A wide footprint and a fix still missing
The advisory lists four affected branches, covering most of the production install base:
- FortiMail 8.0: versions 8.0.0 through 8.0.1 — fix coming in 8.0.2;
- FortiMail 7.6: versions 7.6.0 through 7.6.6 — fix coming in 7.6.7;
- FortiMail 7.4: versions 7.4.0 through 7.4.8 — fix coming in 7.4.9;
- FortiMail 7.2: versions 7.2.0 through 7.2.9 — end-of-life, migration to 7.4 required.
The striking part: no fix has shipped yet. The corrected releases are all marked “upcoming.” That is an unusual posture — a documented, exploited zero-day for which the vendor asks customers to hold without a patch. The flaw was found internally by Gwendal Guégniaud of Fortinet’s Product Security team, which hints at detection ahead of any external disclosure, but does not stop the exploitation observed in the field.
The 7.2 branch deserves special attention: it is already end-of-support, and Fortinet plans no fix at all — the only path is an upgrade to 7.4. For a production mail gateway, that is not a trivial operation, and affected teams should start planning it now.
The two workarounds to apply without waiting
With no patch available, Fortinet offers two workarounds, chosen according to how exposed the appliance is.
The first, and most effective, is to disable the IBE feature (Identity-Based Encryption), which is the vulnerable vector. The CLI is short:
config system encryption ibe
set status disable
end One caution on the workaround: IBE (Identity-Based Encryption) is a niche feature used to encrypt messages without a traditional key exchange — useful for a minority of deployments that need it, but often left enabled by default. Most organizations that do not use IBE will see no functional loss from disabling it, which makes the workaround the default first move rather than a trade-off.
The second, complementary measure is network hygiene that every admin appliance should already follow: take the management interface off the internet or restrict it to a private management network, ideally behind a VPN or a bastion host. A FortiMail console has no business being reachable from the public internet — and that exposure is exactly what the attacker needs.
Neither measure replaces the patch, but both neutralize the vector until it lands. The recommended order is unambiguous: disable IBE first, because it removes the flaw at the source, then segment console access to cover any other weaknesses in the interface.
A prime target in the crosshairs
This zero-day is part of a broader pattern. Network appliances — firewalls, mail gateways, VPN concentrators — have become the preferred targets of attackers, because they are exposed, lightly monitored internally, and rich in access. Fortinet, Cisco, Citrix, Ivanti, WatchGuard: the list of vendors hit by pre-patch exploited flaws keeps growing through 2026.
CVE-2026-104286 illustrates a recurring theme: the management surface is the weak link. Whether it is a path traversal here, an authentication bypass at Cisco last week, or a DTLS flaw at Citrix, the entry point is almost always the interface you expose “because you have to administer it.” The structural answer is simple: no management console should be reachable from the internet.
The lesson is clean. CVE-2026-104286 is defended with two simple moves — disable IBE and take the console off the internet — which together cover most of the risk without waiting for the patch. Those reflexes, more than the upcoming fix, will determine whether you end up with a compromised appliance or just another alert in the RSS feed.
Verdict
If your FortiMail exposes its admin console to the internet, apply the workaround now: disable IBE and restrict access to a management network. The flaw is exploited, rated CVSS 9.8, and no patch is available — you cannot afford to wait. If you run FortiMail 7.2, schedule the migration to 7.4 this week: that branch will receive no fix. Either way, put the patch (8.0.2, 7.6.7, or 7.4.9) at the top of your backlog and apply it the moment it ships — the workaround buys time, it does not replace the fix.