VORANT. Threat Intelligence Research Sign in Create a free account

FortiMail path traversal flaw under active exploitation

severe vulnerability technologygovernment-national

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

Unauthenticated attackers are exploiting a FortiMail path traversal/NULL byte injection bug (CVE-2026-104286) to write arbitrary files and achieve code execution.

CISA/MS-ISAC issued an advisory on a vulnerability in Fortinet FortiMail, a secure email gateway product, that allows unauthenticated remote attackers to write arbitrary files to the underlying system via crafted HTTP/HTTPS requests to the publicly reachable GUI. The flaw is a path traversal and NULL byte injection issue tracked as CVE-2026-104286, and successful exploitation could lead to arbitrary command/code execution on the affected appliance. Fortinet has confirmed this vulnerability is being exploited in the wild, making it an active threat requiring immediate attention.

Affected versions span FortiMail 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8, and 7.2.0–7.2.9. Given FortiMail's role as an internet-facing email security gateway, unpatched instances present a direct initial-access vector (MITRE ATT&CK T1190, Exploit Public-Facing Application) for attackers to gain a foothold inside an organization's network.

Defenders should prioritize immediate patching per Fortinet's guidance, as this is confirmed exploited in the wild. Recommended mitigations include automated patch management, vulnerability scanning, network segmentation to isolate FortiMail from internal networks, use of DMZ for internet-facing services, and penetration testing of critical applications. Organizations running affected versions should treat this as an urgent remediation priority.

Mentioned in this report

Vulnerabilities CVE-2026-104286KEV

Source reporting: https://www.cisecurity.org/advisory/a-vulnerability-in-fortinet-fortimail-could-allow-for-arbitrary-code-execution_2026-108

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 10,646 reports from 152 sources, 506 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs