Fortinet FortiMail path traversal exploited in wild
Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.
An actively exploited critical FortiMail path traversal flaw lets unauthenticated attackers write arbitrary files when IBE is enabled.
NCSC-NL published an advisory on CVE-2026-104286, a critical vulnerability in Fortinet FortiMail caused by a combination of path traversal (CWE-22) and improper neutralization of NULL bytes (CWE-158). An unauthenticated attacker can send specially crafted HTTP or HTTPS requests to write arbitrary files to the underlying system. The vulnerability carries a CVSS v3 score of 9.8 and is confirmed to be actively exploited in the wild.
Affected versions are FortiMail 7.2.0–7.2.9, 7.4.0–7.4.8, 7.6.0–7.6.6 and 8.0.0–8.0.1, but only where the Identity Based Encryption (IBE) feature is enabled — this feature allows encrypted communication to third parties without known certificates. Fortinet has released security updates to address the flaw and has published Indicators of Compromise (IoCs) to help organizations determine whether they have been targeted or compromised.
Defenders running FortiMail with IBE enabled should prioritize patching immediately given active exploitation, and should also perform forensic investigation using Fortinet's published IoCs as part of compromise assessment, even after patching. Further mitigation guidance is available in Fortinet's FG-IR-26-175 advisory.
Mentioned in this report
Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0398.html
What this brief leaves out
This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.
It sits in a corpus of 10,597 reports from 152 sources, 505 of them written in the last seven days, and it grows through the day.
A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.
Create a free account What it costs