1. Executive summary
CVE-2026-104286 is a path traversal flaw in Fortinet FortiMail, rated CVSS 9.8 CRITICAL, that allows an unauthenticated attacker to write arbitrary files on the underlying system through crafted HTTP or HTTPS requests. The vulnerability is not listed in CISA KEV, and the reference data records no known ransomware campaign use. The primary impact for EMEA financial services is on internet-facing FortiMail email security gateways: an unauthenticated write primitive on the mail gateway is a direct route to mail flow manipulation, configuration tampering, and potential code execution depending on what the attacker can overwrite. The CISA advisory carries a remediation due date of 2026-10-04, which is three days from issue.
2. Regulatory framing
| Article | Trigger (the fact in this item) | Practical impact |
|---|---|---|
| DORA Art. 28 | The affected component is an internet-facing FortiMail gateway, an ICT third-party product from Fortinet. | Firms must confirm the FortiMail deployment is captured in their register of ICT third-party arrangements and that the contract supports the vendor's mitigation and notification obligations. |
| NIS2 Art. 21(2)(d) | The flaw is in a third-party email security product that sits in the supply chain of the entity's mail path. | Entities in scope must be able to evidence supply chain security measures covering this product, including how vendor patches are assessed and applied. |
No DORA incident-reporting article is engaged on the facts available: the reference data records no exploitation, no confirmed compromise, and no ransomware use. If a firm confirms exploitation against its own FortiMail, DORA Art. 17, 18 and 19 become engaged and the classification and reporting clock starts.
3. Technical analysis & attack chain
The confirmed mechanism, from the NVD entry, is a path traversal combined with improper neutralization of NULL byte or NULL character. The two weaknesses work together: the traversal component lets the attacker escape the intended directory, and the NULL byte handling lets the attacker truncate a path or filename so that a validation check passes on one string while the filesystem acts on a shorter one. The result is an unauthenticated arbitrary file write on the underlying system via crafted HTTP or HTTPS requests.
Confirmed attack chain:
- The attacker sends a crafted HTTP or HTTPS request to the FortiMail web interface. No authentication is required.
- The request carries a path containing traversal sequences and a NULL byte, which the application fails to neutralize.
- The application writes attacker-controlled content to a path outside the intended directory on the underlying system.
- The attacker gains an arbitrary file write primitive on the FortiMail host.
The source material does not specify the affected FortiMail versions, the exact request parameter or endpoint, the filesystem path written to, or whether the write primitive has been chained to code execution in the wild. Those specifics are missing from the provided sources and should be taken from Fortinet's own advisory before remediation is scoped.
What the write primitive is worth to an attacker on a mail gateway: overwriting configuration files, mail routing rules, or web-accessible content on the appliance. Whether that reaches code execution depends on which paths are writable, and the sources do not say. Treat the write primitive itself as the confirmed impact and do not assume code execution.
No exploitation in the wild is recorded. CVE-2026-104286 is not in CISA KEV, and the reference data records no known ransomware campaign use. The CISA entry carries a due date of 2026-10-04, which is a remediation deadline, not evidence of exploitation.
Context on the wider Fortinet estate, single-sourced and to be treated as such: The Register reported in June 2026 that three FortiSandbox flaws (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) were under active exploitation according to threat-intel firm Defused, with exploitation observed over a single weekend. That reporting concerns FortiSandbox, not FortiMail, and the exploitation claim rests on one vendor's LinkedIn post. It is relevant only as background on attacker interest in Fortinet edge products. It does not establish exploitation of CVE-2026-104286.
Attribution: no actor is named in the source material for CVE-2026-104286, and the reference data contains no MITRE ATT&CK profile for any actor in connection with this CVE. Any attribution would be unconfirmed. None is offered.
4. Mitigation & containment
P1 (within 24 hours)
- Identify every FortiMail instance and classify each by internet exposure. The CISA entry states stakeholders are responsible for evaluating each asset's internet exposure; do that first, because it determines the order of everything below.
- Apply the vendor mitigation. The source directs: apply mitigations in accordance with vendor instructions. The specific fixed FortiMail versions are not given in the provided material; obtain them from Fortinet's advisory for CVE-2026-104286 before scheduling the upgrade.
- Where a fixed version is not yet available or cannot be applied inside the window, the CISA guidance is explicit: follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. For an internet-facing FortiMail with no fix, that means taking the management and web interfaces off the public internet.
- Restrict HTTP and HTTPS access to the FortiMail administrative interface to known management networks. The exploit vector is crafted HTTP/HTTPS requests, so reducing who can reach the interface reduces exposure even before patching.
P2 (within 72 hours)
- Review FortiMail logs for HTTP/HTTPS requests containing traversal sequences (../, ..%2f, encoded variants) or NULL byte encodings (%00) in path or filename parameters. The source does not provide a signature, so this is a hunt, not a detection.
- Check the FortiMail filesystem for unexpected or recently modified files outside the normal configuration and mail store paths. The source does not name the target path, so establish a baseline of expected writable locations and diff against it.
- Confirm the CISA due date of 2026-10-04 is met or that a documented exception with compensating controls is in place.
P3 (within 7 days)
- Add FortiMail to the patch cycle for the Fortinet estate alongside FortiSandbox, FortiSIEM, FortiOS and the remote access products referenced in the related sources, so that Fortinet edge exposure is tracked as one programme rather than per-CVE.
- Verify that the FortiMail contract and vendor notification path satisfy DORA Art. 28 and, where in scope, NIS2 Art. 21(2)(d) supply chain evidence requirements.
5. Indicators of compromise
No indicators of compromise available in the source material.
The sources describe no hashes, domains, IP addresses, file paths, or command lines tied to CVE-2026-104286. The related Fortinet items in the corpus concern different products (FortiSandbox, FortiSIEM, FortiOS) and different CVEs, and none of them supply atomic indicators for this flaw. No copyable indicator block is provided because there is nothing to put in it.
Behavioural indicators, for hunting only, derived from the confirmed mechanism rather than from any observed intrusion:
| behaviour | where to observe | confidence |
|---|---|---|
| HTTP/HTTPS requests to the FortiMail web interface containing traversal sequences in path or filename parameters | FortiMail web/reverse-proxy access logs | Medium (derived from the confirmed mechanism, not from observed traffic) |
| HTTP/HTTPS requests containing NULL byte encodings (%00) in path or filename parameters | FortiMail web/reverse-proxy access logs | Medium (derived from the confirmed mechanism, not from observed traffic) |
| Unexpected file creation or modification outside normal FortiMail configuration and mail store paths | FortiMail host filesystem integrity monitoring | Low (target path not specified in sources) |
These are hypotheses for log review. They are not confirmed indicators and should not be used for automated blocking without validation against normal traffic.
6. Detection
Insufficient indicators to author detection rules.
The source material provides no distinctive strings, command-line flags, mutex names, scheduled-task or service names, file names or paths, registry keys, ransom-note text, or hard-coded values associated with CVE-2026-104286. The only artefacts available are the CVE identifier and the product name, which are reporting artefacts, not threat artefacts, and a rule built on them would detect coverage of the vulnerability rather than exploitation of it. No YARA or Sigma rule is emitted.
If Fortinet's advisory or subsequent telemetry supplies the affected endpoint, parameter names, or target paths, detection content can be authored against those.
CVE assessment
1 referenced CVE — 1 critical (CVSS ≥ 9.0)
| CVE | CVSS | Exploited | EPSS | Summary |
|---|---|---|---|---|
| CVE-2026-104286 | 9.8 Critical | — | — | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 thr… |
7. Sources
- NVD, CVE-2026-104286, https://nvd.nist.gov/vuln/detail/CVE-2026-104286, published 2026-09-30.
- CISA Known Exploited Vulnerabilities, CVE-2026-25089 (Fortinet FortiSandbox OS command injection), https://nvd.nist.gov/vuln/detail/CVE-2026-25089.
- CISA Known Exploited Vulnerabilities, CVE-2026-39808 (Fortinet FortiSandbox OS command injection), https://nvd.nist.gov/vuln/detail/CVE-2026-39808.
- CISA Known Exploited Vulnerabilities, CVE-2025-25249 (Fortinet Multiple Products heap-based buffer overflow), https://nvd.nist.gov/vuln/detail/CVE-2025-25249.
- BSI Germany, Fortinet FortiSIEM: Schwachstelle ermöglicht Manipulation von Daten, https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2813.
- The Register, Three critical Fortinet sandbox bugs splattered by unknown attackers, https://www.theregister.com/security/2026/06/16/three-critical-fortinet-sandbox-bugs-splattered-by-unknown-attackers/5256461, 2026-06-16.
- SecurityWeek, Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks, https://www.securityweek.com/fortinet-code-execution-flaw-exploited-in-pivotc2-rat-attacks/.
8. Adverse Trace position
Adverse Trace assesses CVE-2026-104286 as CVSS 9.8 CRITICAL, not in CISA KEV, with no known ransomware campaign use recorded in the reference data. The severity is high because the flaw is unauthenticated and yields an arbitrary file write on an internet-facing mail gateway, but the absence of KEV listing and of any confirmed exploitation means this is a patch-window problem, not an active-incident problem, for most clients. The CISA due date of 2026-10-04 is the operative deadline. Clients running FortiMail with an internet-facing web interface should treat that date as binding and confirm a fixed version from Fortinet's advisory, which the provided sources do not name. We will track Fortinet's advisory for the affected version list and the fixed builds, and we will re-issue this note if CVE-2026-104286 is added to KEV or if exploitation is reported. Clients who cannot confirm their FortiMail exposure or patch state should contact their Adverse Trace handler before the due date.
Published via PulseTrace — Adverse Trace threat intelligence.