FortiMail unauthenticated path traversal hits CISA KEV
How to fix CVE-2026-104286: disable FortiMail IBE (config system encryption ibe / set status disable) or upgrade to upcoming 8.0.2 / 7.6.7 / 7.4.9
Contents
CISA added CVE-2026-104286 to the Known Exploited Vulnerabilities catalog today (2026-10-01). Fortinet FortiMail has a path traversal (CWE-22) plus improper NULL-byte neutralization (CWE-158) in the GUI: an unauthenticated attacker can write arbitrary files on the underlying system over crafted HTTP or HTTPS requests. Fortinet rates it Critical (CVSSv3 9.8), marks Known Exploited Yes, and publishes Indicators of Compromise from active campaigns. Federal KEV due date is 2026-10-04. Forensic triage is Yes under BOD 26-04. Known ransomware campaign use is Unknown.
This page is the operator write-up from Fortinet PSIRT FG-IR-26-175 (published 2026-10-01) and CISA KEV catalogVersion 2026.10.01. The HOL Guard evidence pack for CVE-2026-104286 is the linked source record (title may still read the ADP stub until editorial lands). NVD analysis was empty at publish time.
What breaks
FortiMail is Fortinet's email security appliance. The vulnerable path is the GUI component that backs Identity Based Encryption (IBE). With IBE reachable, a stranger who can hit the HTTP/HTTPS listener can plant files on the box. Fortinet's advisory lists dropped and modified binaries under /data and /bin, a malicious ld.so.preload, altered httpd.conf, and C2 IPs. Impact text is execute unauthorized code or commands. Attack type is Unauthenticated.
Affected trains and Fortinet's stated solutions:
- FortiMail 8.0: 8.0.0 through 8.0.1 → upgrade to upcoming 8.0.2 or above
- FortiMail 7.6: 7.6.0 through 7.6.6 → upgrade to upcoming 7.6.7 or above
- FortiMail 7.4: 7.4.0 through 7.4.8 → upgrade to upcoming 7.4.9 or above
- FortiMail 7.2: 7.2.0 through 7.2.9 → upgrade to branch 7.4 or above
Until those builds ship (or you install them), Fortinet's workaround is to disable IBE, or keep the FortiMail management interface off the public internet and reachable only from a trusted private network.
Who is not in scope
- FortiMail already on the fixed builds once 8.0.2 / 7.6.7 / 7.4.9 (or newer on that train) are installed, or 7.2 fleets moved onto 7.4+.
- Boxes where IBE is already disabled and stays disabled, per Fortinet's CLI workaround. Confirm with your local config, not a dashboard assumption.
- Other Fortinet products (FortiGate, FortiWeb, FortiProxy, and so on). FG-IR-26-175 is FortiMail only.
- Mail delivery paths that never expose the FortiMail GUI / IBE surface to untrusted networks. The advisory still urges applying the workaround or patch; do not invent "air-gapped equals patched."
One operator check
On each FortiMail, confirm product version and whether IBE is enabled:
get system status
# note Version line (8.0.x / 7.6.x / 7.4.x / 7.2.x)
config system encryption ibe
get
# status should be disable after the workaround
end
Also hunt Fortinet's published IoCs from FG-IR-26-175 (example hashes for /data/lib/liblog.so, /bin/smit, /data/bin/webconsole, /data/bin/mailservice, /data/etc/ld.so.preload, and related paths; C2 examples 79.141.169.187 and 45.129.0.192). Match those against disk and egress logs before you declare the box clean. Federal agencies under BOD 26-04 also owe forensic triage; KEV due date is 2026-10-04.
How to fix
Immediate workaround from Fortinet (disable IBE):
config system encryption ibe
set status disable
end
Or lock management/IBE access to a trusted private network and keep the GUI off the public internet.
Then schedule the version upgrade Fortinet lists for your train (upcoming 8.0.2, 7.6.7, or 7.4.9; 7.2 fleets move to 7.4+). Re-run get system status after maintenance. Keep Fortinet's IoC list in your IR playbook until you have a clean forensic pass.
What this is not
This is not a FortiGate firewall CVE, and it is not limited to authenticated admins. Fortinet and CISA both treat it as unauthenticated, Critical, and already exploited. It also is not "wait for NVD CVSS" work: Fortinet published CVSSv3 9.8 and active IoCs on the same day CISA added the KEV row. If your FortiMail GUI or IBE surface can see the internet, treat the clock as started.
References
- Fortinet PSIRT FG-IR-26-175
- CISA Known Exploited Vulnerabilities catalog (CVE-2026-104286) (dateAdded 2026-10-01, dueDate 2026-10-04, catalogVersion 2026.10.01, BOD 26-04)
- NVD CVE-2026-104286
- CVE-2026-104286
Continue reading
All posts
Self-managed GitLab: unauth commits API file read hits CISA KEV
How to fix CVE-2026-85706: upgrade GitLab to 18.11.12 / 19.0.9 / 19.1.8 / 19.2.6 / 19.3.2

Cisco SD-WAN Manager admin API bypass hits CISA KEV
How to fix CVE-2026-76504: upgrade Cisco Catalyst SD-WAN Manager to 20.9.10.1 / 20.12.8.2 / 20.15.6.1 / 20.18.4.1 / 26.1.2.1 / 26.2.1

BREAKING: Cisco SD-WAN Manager admin API open without a login (CVE-2026-76504)
How to fix CVE-2026-76504: upgrade Cisco Catalyst SD-WAN Manager to 20.9.10.1 / 20.12.8.2 / 20.15.6.1 / 20.18.4.1 / 26.1.2.1 / 26.2.1
