Fortinet FortiMail Path Traversal Flaw Actively Exploited to Compromise Servers
Attackers are exploiting critical FortiMail path-traversal CVE-2026-104286 to write files and compromise email appliances.
Fortinet advisory FG-IR-26-175 discloses CVE-2026-104286, a CVSS 9.8 path-traversal flaw in FortiMail that lets unauthenticated attackers write arbitrary files through crafted HTTP or HTTPS requests. Fortinet says the bug is being exploited and that file writes could lead to code or command execution. Affected versions include 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8, and 7.2.0–7.2.9; fixes 8.0.2, 7.6.7, and 7.4.9 are identified, while 7.2 users are told to move to 7.4 or later. Until patches, Fortinet advises disabling Identity-Based Encryption or limiting management exposure, and published IOCs including suspicious files and IPs 79.141.169.187 and 45.129.0.192.
- CVE-2026-104286 scores CVSS 9.8 and allows unauthenticated arbitrary file writes.
- Fortinet confirms real-world exploitation but has not named a threat actor.
- Affected builds span FortiMail 7.2, 7.4, 7.6, and 8.0; several fixes are upcoming.
- Workaround: disable Identity-Based Encryption or restrict public management access.
- IOCs include ld.so.preload, webconsole, and IPs 79.141.169.187 and 45.129.0.192.
Vulnerabilities mentionedAll →
- CVE-2026-1042869.82%Unauthenticated path traversal file write in Fortinet FortiMailpublished · Fortinet FortiMail KEV PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-104286 |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| ipv4 | 45.129.0.192 | vity has been linked to the IP addresses 79.141.169.187 and 45.129.0.192, as well as a suspicious archive-account configuration poin |
| ipv4 | 79.141.169.187 | .gz. Malicious activity has been linked to the IP addresses 79.141.169.187 and 45.129.0.192, as well as a suspicious archive-account c |
Full article459 words · extracted from gbhackers.com · click to collapse
Fortinet has disclosed a critical vulnerability in FortiMail that attackers are actively exploiting to compromise vulnerable email security appliances.
This flaw, tracked as CVE-2026-104286, has a CVSS v3.1 score of 9.8. It enables unauthenticated attackers to write arbitrary files to the underlying system via specially crafted HTTP or HTTPS requests.
Fortinet FortiMail Path Traversal Flaw
The issue, detailed in Fortinet advisory FG-IR-26-175, arises from improper limitations on a pathname, commonly known as path traversal (CWE-22), combined with an improper neutralization of NULL bytes or NULL characters (CWE-158).
By exploiting how the FortiMail GUI processes crafted file paths, a remote attacker could bypass intended directory restrictions and write files to locations that should not be writable.
Fortinet rates this vulnerability as critical because arbitrary file writes could allow for unauthorized code execution or command execution on the appliance.
Affected products include FortiMail versions 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9. Fortinet has identified versions 8.0.2, 7.6.7, and 7.4.9 as upcoming fixed versions for the affected branches.
Organizations using FortiMail 7.2 are advised to upgrade to the 7.4 branch or later. Since versions within the 7.4 branch are affected up to 7.4.8, administrators should confirm the exact installed build before considering an upgrade as a remediation.
Until security updates are deployed, Fortinet recommends that administrators disable Identity-Based Encryption (IBE) support using the following CLI configuration:
config system encryption ibe
set status disable
end
For administrators who cannot disable IBE, immediately remove FortiMail management interface access from the public internet or restrict it to trusted private management networks.
The advisory does not provide a virtual patch, underscoring the need to reduce exposure and apply the workaround without delay.
Additionally, Fortinet has released indicators of compromise (IOCs) associated with the observed activity. Suspicious files to look out for include /data/lib/liblog.so, /data/bin/webconsole, /data/bin/mailservice, and /data/etc/ld.so.preload.
Investigators should also examine changes to /bin/smit, /data/etc/httpd.conf, and /data/migadmin.tar.gz. Malicious activity has been linked to the IP addresses 79.141.169.187 and 45.129.0.192, as well as a suspicious archive-account configuration pointing to 79.141.169.187, with uploads directed to /uploads.
Security teams should preserve FortiMail logs before making major changes, compare file hashes against Fortinet’s published IOCs, investigate unauthorized administrative configuration changes, and review cron execution records.
Notable log artifacts include unexpected /migadmin commands, anomalous IBE Base64 parsing errors, unusual archive account creation, and failed logins involving wildcard internal-user addresses.
While Fortinet’s advisory confirms real-world exploitation, it does not publicly identify the responsible threat actor or provide a complete exploitation chain.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.