# Fortinet FortiMail path traversal exploited in wild

Published: 2026-10-02 · Severity: high · Sectors: technology
Canonical: https://vorant.io/reports/94e76bed-82d7-5c0e-aa51-87a8a8ef3400/fortinet-fortimail-path-traversal-exploited-in-wild

> An actively exploited critical FortiMail path traversal flaw lets unauthenticated attackers write arbitrary files when IBE is enabled.

NCSC-NL published an advisory on CVE-2026-104286, a critical vulnerability in Fortinet FortiMail caused by a combination of path traversal (CWE-22) and improper neutralization of NULL bytes (CWE-158). An unauthenticated attacker can send specially crafted HTTP or HTTPS requests to write arbitrary files to the underlying system. The vulnerability carries a CVSS v3 score of 9.8 and is confirmed to be actively exploited in the wild.

Affected versions are FortiMail 7.2.0–7.2.9, 7.4.0–7.4.8, 7.6.0–7.6.6 and 8.0.0–8.0.1, but only where the Identity Based Encryption (IBE) feature is enabled — this feature allows encrypted communication to third parties without known certificates. Fortinet has released security updates to address the flaw and has published Indicators of Compromise (IoCs) to help organizations determine whether they have been targeted or compromised.

Defenders running FortiMail with IBE enabled should prioritize patching immediately given active exploitation, and should also perform forensic investigation using Fortinet's published IoCs as part of compromise assessment, even after patching. Further mitigation guidance is available in Fortinet's FG-IR-26-175 advisory.

## Mentioned in this report

- Vulnerabilities: CVE-2026-104286 (KEV)

## Detection guidance (public sample)

### Web Request Combining Path Traversal and NULL Byte Sequences

ATT&CK: T1190

Detects HTTP/HTTPS requests to a public-facing server containing both directory traversal and NULL-byte (%00) sequences, the CWE-22/CWE-158 combination used against FortiMail IBE (CVE-2026-104286) for arbitrary file write. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: Web Request Combining Path Traversal and NULL Byte Sequences
id: 4c00829a-8175-55ca-a02e-99638cbb7e3c
status: experimental
description: Detects HTTP/HTTPS requests whose URI or query string contains both directory
  traversal sequences (plain or encoded) and a NULL byte (%00). This combination of
  path traversal and improper NULL-byte neutralisation is the exploitation pattern
  described for the FortiMail IBE vulnerability (CVE-2026-104286) and is rare in legitimate
  traffic. It does not depend on a specific endpoint path.
tags:
- attack.initial-access
- attack.t1190
logsource:
  category: webserver
detection:
  trav_query:
    cs-uri-query|contains:
    - ../
    - ..\
    - '%2e%2e%2f'
    - '%2e%2e/'
    - ..%2f
    - '%2e%2e%5c'
    - ..%5c
    - '%252e%252e'
  trav_stem:
    cs-uri-stem|contains:
    - ../
    - ..\
    - '%2e%2e%2f'
    - '%2e%2e/'
    - ..%2f
    - '%2e%2e%5c'
    - ..%5c
    - '%252e%252e'
  null_query:
    cs-uri-query|contains:
    - '%00'
    - \x00
  null_stem:
    cs-uri-stem|contains:
    - '%00'
    - \x00
  condition: 1 of trav_* and 1 of null_*
falsepositives:
- Authorised vulnerability scanners or penetration tests probing path traversal and
  NULL-byte handling
- Web application firewalls or security appliances replaying malicious test strings
level: high
author: Vorant
references:
- https://advisories.ncsc.nl/2026/ncsc-2026-0398.html
```

### Successful State-Changing Web Request With Path Traversal Sequences

ATT&CK: T1190

Detects POST/PUT requests containing directory traversal sequences that return a success status, indicating possible arbitrary file write against a public-facing appliance such as FortiMail. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: Successful State-Changing Web Request With Path Traversal Sequences
id: 8d138063-c51d-54d5-adb2-e555f34f3522
status: experimental
description: Detects POST or PUT requests whose URI or query contains plain or encoded
  directory traversal sequences and which return an HTTP 2xx status. Against an internet-facing
  mail gateway with a path-traversal file-write flaw (such as CVE-2026-104286 in FortiMail
  with IBE enabled), this suggests a successful exploitation attempt. Review the requested
  path and any files written afterwards.
tags:
- attack.initial-access
- attack.t1190
- attack.discovery
- attack.t1083
logsource:
  category: webserver
detection:
  selection_method:
    cs-method:
    - POST
    - PUT
  selection_status:
    sc-status:
    - 200
    - 201
    - 202
    - 204
  trav_query:
    cs-uri-query|contains:
    - ../
    - ..\
    - '%2e%2e%2f'
    - ..%2f
    - '%2e%2e%5c'
    - ..%5c
  trav_stem:
    cs-uri-stem|contains:
    - ../
    - ..\
    - '%2e%2e%2f'
    - ..%2f
    - '%2e%2e%5c'
    - ..%5c
  condition: selection_method and selection_status and 1 of trav_*
falsepositives:
- Web applications that legitimately pass relative paths in POST parameters, such
  as file managers or CMS editors
- Authorised security testing against the appliance
level: medium
author: Vorant
references:
- https://advisories.ncsc.nl/2026/ncsc-2026-0398.html
```

Behavioural rules are generated from public reporting — validate in your environment before deploying.

Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0398.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/94e76bed-82d7-5c0e-aa51-87a8a8ef3400/fortinet-fortimail-path-traversal-exploited-in-wild.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
