~/f4n6 $ grep -r "Fortinet sounds the alarm over actively exploited FortiMail zero-day" ./investigations/ --include="*.md"

Fortinet sounds the alarm over actively exploited FortiMail zero-day

Jeff Davies 02 Oct 2026 7 min read

1. Executive summary

Fortinet has confirmed that CVE-2026-104286, a path traversal and null-byte handling flaw in the FortiMail web interface, is being exploited in the wild. The vulnerability is rated CVSS 9.8 (Critical) and allows an unauthenticated attacker to write arbitrary files to the underlying appliance via crafted HTTP or HTTPS requests; writes to certain paths can lead to code or command execution. CISA added the CVE to its Known Exploited Vulnerabilities catalog on 2026-10-01, with a remediation due date of 2026-10-04 for US federal civilian agencies. Affected branches are FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9. For EMEA financial services clients running FortiMail as an internet-facing email security gateway, the exposure is direct: an unauthenticated file-write primitive on a perimeter device that sits in the mail path, with fixes for several branches still listed as upcoming.

2. Regulatory framing

Article Trigger (the fact in this item) Practical impact
DORA Art. 17 Active exploitation of an internet-facing email security gateway that may already have files or persistence planted on it; applying the workaround does not remove them The incident management process must cover detection, containment and eradication on the appliance, not just patching. Forensic triage is a required step, not optional.
DORA Art. 19 A confirmed exploited vulnerability in a production security control, where compromise of the appliance may not yet be ruled out If triage confirms unauthorised access or impact, the major incident reporting clock to the competent authority starts from classification, not from when the patch lands.
NIS2 Art. 23 Same trigger: an actively exploited flaw in an entity's own network and information system with a plausible path to service disruption Incident notification obligations apply on the same classification logic where the entity is in scope.

No DORA Art. 28/29/30 or NIS2 Art. 21(2)(d) row is included: the source names no third-party or supply-chain dependency specific to this item beyond the vendor relationship itself, which would be true of any vendor patch.

3. Technical analysis & attack chain

Confirmed steps, as described by Fortinet and CISA:

  1. An unauthenticated attacker sends a crafted HTTP or HTTPS request to the FortiMail web interface.
  2. The request exploits a path traversal condition (CWE-22) combined with improper neutralisation of a NULL byte or NULL character (CWE-158) to escape the intended restricted directory.
  3. The attacker writes arbitrary files to the underlying system.
  4. Writing files to certain locations can allow execution of code or commands on the appliance.

Fortinet has not published when exploitation began, who is behind it, or how many customers are affected. No ransomware use is recorded against this CVE in the KEV entry; the field reads "Unknown", so this advisory does not characterise the activity as ransomware.

Affected versions. FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9. Fortinet lists fixes for several affected branches as "upcoming", which means some customers have no patch and must rely on the workarounds below.

Exploited component. The FortiMail web interface, reachable over HTTP or HTTPS. The flaw is unauthenticated, so no credentials or prior access are needed. The write primitive lands on the appliance's underlying filesystem, which is what raises the impact from file write to potential code execution.

Discrepancy note. The verified reference data classifies CVE-2026-104286 as CWE-22 (Path Traversal) only. Fortinet and Help Net Security describe it as CWE-22 combined with CWE-158 (Improper Neutralization of NULL Byte or NULL Character). Both describe the same flaw: the traversal is the escape, the null byte is the technique used to defeat pathname handling. The CVSS 9.8 (Critical) and the CISA KEV status in the verified data are authoritative and are used throughout this advisory.

Vendor-published hunting guidance. Fortinet has published indicators administrators can hunt for, covering suspicious files, configuration changes, and IP addresses associated with the attacks. The specific values are not reproduced in the sources available to this advisory, so they are not listed in §5. Clients should pull the indicator set directly from Fortinet's advisory.

Single-source caveat. The technical mechanism, affected version ranges, and workaround guidance all trace to Fortinet's own advisory as relayed by The Register, Help Net Security, SecurityWeek, and The Hacker News. The CISA KEV entry corroborates the exploitation status and the CWE-22 classification. No independent third-party incident response report or telemetry corroborates the exploitation activity itself, and no threat actor has been named or attributed by any source. Treat attribution as unconfirmed.

Context, not causation. The Register notes a June 2026 incident in which credentials linked to around 75,000 FortiGate firewalls appeared in criminal hands; Fortinet attributed that data to previous incidents and brute-force attacks rather than a fresh breach. That is a separate product and a separate event. It is included only because it is in the source, and it does not indicate the same actor is involved here.

4. Mitigation & containment

P1, within 24 hours

  • Determine whether any FortiMail instance is reachable from the internet on its management interface. If it is, block that exposure now: restrict management access to trusted private networks and internal jump hosts. This is the single control that removes the unauthenticated attack path for unpatched branches.
  • If Identity Based Encryption is not required in your configuration, disable it. Fortinet names this as the primary workaround.
  • Apply the vendor fix on every branch where a fix exists. For branches where Fortinet lists the fix as "upcoming", the workarounds above are the only mitigation until the update ships.
  • Begin forensic triage on every affected appliance. Applying a workaround does not remove files or persistence mechanisms an attacker may already have planted. Pull Fortinet's published indicator set (suspicious files, configuration changes, attacker IP addresses) and hunt against it. If triage finds anything, treat the appliance as compromised and rebuild from known-good configuration rather than cleaning in place.

P2, within 72 hours

  • For any FortiMail instance that was internet-exposed on the management interface and cannot be shown to be clean, rotate all credentials that were stored on or transited through the appliance, including mail relay credentials, LDAP or AD bind accounts, and any API keys.
  • Review FortiMail configuration against a known-good baseline for unauthorised changes, with particular attention to mail routing rules, relay permissions, and any new administrative accounts.
  • Confirm whether the appliance sits in a path that would let a compromised instance read or alter mail in transit. If it does, scope the potential data exposure before you close the incident.

P3, within 7 days

  • Track Fortinet's advisory for the "upcoming" fixes and apply them on release. Do not leave branches on workarounds longer than the vendor's patch timeline allows.
  • Add the FortiMail management interface to your external attack surface monitoring so that any future re-exposure is caught automatically.
  • Review whether the appliance's position in the mail path is documented in your asset inventory and incident response runbooks. An email security gateway that is not in the runbook will not be triaged in the first hour of the next incident.

5. Indicators of compromise

No atomic indicators of compromise are available in the source material. Fortinet has published suspicious files, configuration changes, and attacker IP addresses in its own advisory, but the specific values are not reproduced in any source available to this advisory. Pull them directly from Fortinet.

The sources describe observable behaviours but no atomic indicators. Those behaviours are listed below.

Behavioural indicators

behaviour where to observe confidence
Crafted HTTP or HTTPS request to the FortiMail web interface carrying path traversal sequences and null-byte characters FortiMail web interface access logs, reverse proxy or WAF logs in front of the appliance High (mechanism confirmed by Fortinet and CISA)
Arbitrary files written to the FortiMail underlying filesystem outside expected paths File integrity monitoring on the appliance, FortiMail filesystem audit High (mechanism confirmed)
Unexpected configuration changes on the appliance FortiMail configuration audit, change management records Medium (Fortinet names configuration changes as a hunting indicator; specific changes not published)
Code or command execution originating from the FortiMail appliance EDR or host telemetry on the appliance, outbound network connections from the appliance Medium (Fortinet states writes to certain locations can lead to execution; no execution artefacts published)

6. Detection

The sources do not contain distinctive strings, command-line flags, mutex names, file paths, registry keys, or hard-coded values from the exploit or any payload. The only artefacts named are the CVE identifier, the product name, and the CWE classifications, none of which are artefacts of the threat itself. A rule built on those would detect reporting about the vulnerability, not exploitation of it.

Insufficient indicators to author detection rules.

CVE assessment

1 referenced CVE — 1 actively exploited (CISA KEV), 1 critical (CVSS ≥ 9.0)

CVE CVSS Exploited EPSS Summary
CVE-2026-104286 9.8 Critical ⚠ KEV 2026-10-01 — An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 thr…

7. Sources

  • The Register, "Fortinet sounds the alarm over actively exploited FortiMail zero-day", https://www.theregister.com/security/2026/10/02/fortinet-sounds-the-alarm-over-actively-exploited-fortimail-zero-day/5300803, 2026-10-02
  • Help Net Security, "Critical FortiMail zero-day exploited in the wild (CVE-2026-104286)", https://www.helpnetsecurity.com/2026/10/02/fortinet-fortimail-vulnerability-cve-2026-104286/, 2026-10-02
  • CISA Known Exploited Vulnerabilities, CVE-2026-104286, Fortinet FortiMail Path Traversal Vulnerability, https://nvd.nist.gov/vuln/detail/CVE-2026-104286, KEV added 2026-10-01
  • SecurityWeek, "Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action", https://www.securityweek.com/exploited-fortinet-fortimail-zero-day-calls-for-urgent-action/, 2026-10-02
  • The Hacker News, "Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes", https://thehackernews.com/2026/10/critical-fortimail-zero-day-flaw.html, 2026-10-02
  • The Register, "Three critical Fortinet sandbox bugs splattered by unknown attackers", https://www.theregister.com/security/2026/06/16/three-critical-fortinet-sandbox-bugs-splattered-by-unknown-attackers/5256461, 2026-06-16 (context only, separate product and event)

8. Adverse Trace position

Adverse Trace assesses CVE-2026-104286 as CVSS 9.8 (Critical), in CISA KEV since 2026-10-01, with active exploitation confirmed by the vendor and no named threat actor. The risk to EMEA financial services clients is concentrated in one configuration: a FortiMail instance whose management interface is reachable from the internet, on a branch where Fortinet has not yet shipped a fix. That combination gives an unauthenticated attacker a file-write primitive on a device sitting in the mail path, and the vendor's own guidance is explicit that applying the workaround does not remove anything already planted. Clients on affected branches should treat triage as the priority action, not patching, because a clean patch on a compromised appliance leaves the attacker in place. The exploitation activity itself is single-sourced to Fortinet as relayed by the trade press, with no independent IR corroboration and no attribution; we are not assigning this to any actor. We will track Fortinet's advisory for the "upcoming" fixes and for the specific indicator values, and will issue a follow-up when either is published.


Read the original source →

Published via PulseTrace — Adverse Trace threat intelligence.

Post this to LinkedIn
Formatting is converted automatically — headings, bullets, a link back & hashtags. Paste straight in.
J
Jeff Davies