# FortiMail path traversal flaw under active exploitation

Published: 2026-10-02 · Severity: severe · Sectors: technology, government-national
Canonical: https://vorant.io/reports/9f2d3e5b-f7b1-56ba-8cdf-ecbf0a45724d/fortimail-path-traversal-flaw-under-active-exploitation

> Unauthenticated attackers are exploiting a FortiMail path traversal/NULL byte injection bug (CVE-2026-104286) to write arbitrary files and achieve code execution.

CISA/MS-ISAC issued an advisory on a vulnerability in Fortinet FortiMail, a secure email gateway product, that allows unauthenticated remote attackers to write arbitrary files to the underlying system via crafted HTTP/HTTPS requests to the publicly reachable GUI. The flaw is a path traversal and NULL byte injection issue tracked as CVE-2026-104286, and successful exploitation could lead to arbitrary command/code execution on the affected appliance. Fortinet has confirmed this vulnerability is being exploited in the wild, making it an active threat requiring immediate attention.

Affected versions span FortiMail 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8, and 7.2.0–7.2.9. Given FortiMail's role as an internet-facing email security gateway, unpatched instances present a direct initial-access vector (MITRE ATT&CK T1190, Exploit Public-Facing Application) for attackers to gain a foothold inside an organization's network.

Defenders should prioritize immediate patching per Fortinet's guidance, as this is confirmed exploited in the wild. Recommended mitigations include automated patch management, vulnerability scanning, network segmentation to isolate FortiMail from internal networks, use of DMZ for internet-facing services, and penetration testing of critical applications. Organizations running affected versions should treat this as an urgent remediation priority.

## Mentioned in this report

- Vulnerabilities: CVE-2026-104286 (KEV)

Source reporting: https://www.cisecurity.org/advisory/a-vulnerability-in-fortinet-fortimail-could-allow-for-arbitrary-code-execution_2026-108

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/9f2d3e5b-f7b1-56ba-8cdf-ecbf0a45724d/fortimail-path-traversal-flaw-under-active-exploitation.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
