FortiMail unauthenticated path traversal hits CISA KEV

FortiMail unauthenticated path traversal hits CISA KEV

How to fix CVE-2026-104286: disable FortiMail IBE (config system encryption ibe / set status disable) or upgrade to upcoming 8.0.2 / 7.6.7 / 7.4.9

3 min read648 words
Contents

CISA added CVE-2026-104286 to the Known Exploited Vulnerabilities catalog today (2026-10-01). Fortinet FortiMail has a path traversal (CWE-22) plus improper NULL-byte neutralization (CWE-158) in the GUI: an unauthenticated attacker can write arbitrary files on the underlying system over crafted HTTP or HTTPS requests. Fortinet rates it Critical (CVSSv3 9.8), marks Known Exploited Yes, and publishes Indicators of Compromise from active campaigns. Federal KEV due date is 2026-10-04. Forensic triage is Yes under BOD 26-04. Known ransomware campaign use is Unknown.

This page is the operator write-up from Fortinet PSIRT FG-IR-26-175 (published 2026-10-01) and CISA KEV catalogVersion 2026.10.01. The HOL Guard evidence pack for CVE-2026-104286 is the linked source record (title may still read the ADP stub until editorial lands). NVD analysis was empty at publish time.

What breaks

FortiMail is Fortinet's email security appliance. The vulnerable path is the GUI component that backs Identity Based Encryption (IBE). With IBE reachable, a stranger who can hit the HTTP/HTTPS listener can plant files on the box. Fortinet's advisory lists dropped and modified binaries under /data and /bin, a malicious ld.so.preload, altered httpd.conf, and C2 IPs. Impact text is execute unauthorized code or commands. Attack type is Unauthenticated.

Affected trains and Fortinet's stated solutions:

  • FortiMail 8.0: 8.0.0 through 8.0.1 → upgrade to upcoming 8.0.2 or above
  • FortiMail 7.6: 7.6.0 through 7.6.6 → upgrade to upcoming 7.6.7 or above
  • FortiMail 7.4: 7.4.0 through 7.4.8 → upgrade to upcoming 7.4.9 or above
  • FortiMail 7.2: 7.2.0 through 7.2.9 → upgrade to branch 7.4 or above

Until those builds ship (or you install them), Fortinet's workaround is to disable IBE, or keep the FortiMail management interface off the public internet and reachable only from a trusted private network.

Who is not in scope

  • FortiMail already on the fixed builds once 8.0.2 / 7.6.7 / 7.4.9 (or newer on that train) are installed, or 7.2 fleets moved onto 7.4+.
  • Boxes where IBE is already disabled and stays disabled, per Fortinet's CLI workaround. Confirm with your local config, not a dashboard assumption.
  • Other Fortinet products (FortiGate, FortiWeb, FortiProxy, and so on). FG-IR-26-175 is FortiMail only.
  • Mail delivery paths that never expose the FortiMail GUI / IBE surface to untrusted networks. The advisory still urges applying the workaround or patch; do not invent "air-gapped equals patched."

One operator check

On each FortiMail, confirm product version and whether IBE is enabled:

get system status
# note Version line (8.0.x / 7.6.x / 7.4.x / 7.2.x)

config system encryption ibe
get
# status should be disable after the workaround
end

Also hunt Fortinet's published IoCs from FG-IR-26-175 (example hashes for /data/lib/liblog.so, /bin/smit, /data/bin/webconsole, /data/bin/mailservice, /data/etc/ld.so.preload, and related paths; C2 examples 79.141.169.187 and 45.129.0.192). Match those against disk and egress logs before you declare the box clean. Federal agencies under BOD 26-04 also owe forensic triage; KEV due date is 2026-10-04.

How to fix

Immediate workaround from Fortinet (disable IBE):

config system encryption ibe
set status disable
end

Or lock management/IBE access to a trusted private network and keep the GUI off the public internet.

Then schedule the version upgrade Fortinet lists for your train (upcoming 8.0.2, 7.6.7, or 7.4.9; 7.2 fleets move to 7.4+). Re-run get system status after maintenance. Keep Fortinet's IoC list in your IR playbook until you have a clean forensic pass.

What this is not

This is not a FortiGate firewall CVE, and it is not limited to authenticated admins. Fortinet and CISA both treat it as unauthenticated, Critical, and already exploited. It also is not "wait for NVD CVSS" work: Fortinet published CVSSv3 9.8 and active IoCs on the same day CISA added the KEV row. If your FortiMail GUI or IBE surface can see the internet, treat the clock as started.

References

Continue reading

All posts