Fortinet rates FortiMail CVE-2026-104286 critical at CVSS 9.8; FG-IR-26-175 lists fixes as upcoming and publishes only an IBE or management-interface workaround

Operators of exposed FortiMail gateways have a vendor-confirmed unauthenticated file-write flaw, a known-exploited flag, and no shipped patch on the 8.0, 7.6, or 7.4 branches.

IN BRIEF: On October 1, 2026, Fortinet published PSIRT advisory FG-IR-26-175 for CVE-2026-104286, a critical FortiMail path-traversal flaw scored CVSS 9.8 that the vendor says has been reported exploited in the wild, with upgrades listed as upcoming and a workaround of disabling IBE or removing the management interface from the internet.

Fortinet published FG-IR-26-175 on October 1, 2026, and marked CVE-2026-104286 critical. The CVSSv3 score is 9.8. The vector on the advisory is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C. The component is the GUI. The attack type is unauthenticated. The stated impact is “Execute unauthorized code or commands.” Known Exploited is Yes. Virtual Patch is No.

The summary describes an Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) [CWE-22] and Improper Neutralization of NULL Byte or NULL Character [CWE-158]. Fortinet writes that the vulnerability “may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.” The next sentence is direct: “This has been reported to be exploited in the wild, customers are urged to apply the workaround below.” Discovery is internal. Acknowledgement names Gwendal Guégniaud of the Fortinet Product Security team. The timeline entry is a single line: 2026-10-01, initial publication. The advisory does not state a customer remediation deadline.

The affected range covers four branches, and none of the current branches has a version Fortinet describes as already shipped. FortiMail 8.0 is affected from 8.0.0 through 8.0.1; the solution column says upgrade to upcoming 8.0.2 or above. FortiMail 7.6 is affected from 7.6.0 through 7.6.6; the solution is upcoming 7.6.7 or above. FortiMail 7.4 is affected from 7.4.0 through 7.4.8; the solution is upcoming 7.4.9 or above. FortiMail 7.2 is affected from 7.2.0 through 7.2.9; the solution is “Upgrade to branch 7.4 or above.” That prescribed move lands on a branch the same table still lists as affected through 7.4.8, with 7.4.9 also upcoming. The published vector includes RL:O, the temporal mark for an official fix, while every solution cell on 8.0, 7.6, and 7.4 uses the word upcoming.

The only controls Fortinet publishes are operational. Customers are told to disable IBE feature support with this CLI block:

config system encryption ibe
set status disable
end

The alternative is to “Disable access to the FortiMail management interface from the internet or limit the access only from trusted private network.” There is no virtual patch. For a mail gateway, disabling Identity-Based Encryption is a feature loss, not a configuration tidy-up. Pulling the management interface off the internet is the other published option, and it is the control that matches the attack description: crafted HTTP or HTTPS requests, no privileges required, no user interaction, network-reachable, high impact on confidentiality, integrity, and availability.

Fortinet also published indicators. Added files include /data/lib/liblog.so (MD5 64c90a00c7fda4d5c7973ed64c25783a, SHA256 8015f34dc84922b03688399d7f9fe7a00361789f7e420c7e2a2cdb23e75cef84), /data/bin/webconsole (MD5 ae0ea6502d3fa5f0664bceb73189eb54, SHA256 7a6cea9f5c9e2e9994d4e3c4da73f86cf5acd05ea5d312c066c9d1dafd69ee38), /data/bin/mailservice (MD5 f90fa81a5f521d785f2b2f765e3ab897, SHA256 4000276a150a165d3c2537d1e19fb393c4de8333076a16655e28059cae82157b), and /data/etc/ld.so.preload (MD5 8eb64f25d2a8e18e05aae058629473cf, SHA256 8953ec7960b09f544a880b072ad4e6cfda7a8303f486251d3478dcfdfbac23b6). Modified files include /bin/smit (MD5 5241738a3e9988404239e12243f6d35b, SHA256 77324ac428bde86d351fc5fc06f6d64a6bfe737dfb2743df1d4c5ac2418a5b6a), /data/etc/httpd.conf (MD5 61af1c4bce1c2eebc8ff689ca5337791, SHA256 703e97c64e61e41dc3aaba580d82bb2aa7b6a11b54ee6fb467ed5d5a3bffdef5), and /data/migadmin.tar.gz (MD5 49a7156a7d043cc8f9f680579db22f86, SHA256 d6fe51c22b91776f4c961ea58bcac5917f15d560a619d7ce726d3d51795609d3). Listed addresses are 79[.]141.169.187 and 45[.]129.0.192. One published log line records an admin CLI change that added archive account “archive234,” with remote-ip[79.141.169.187], remote-username[archive234], and remote-directory[/uploads]. Another records a cron event running a root shell command beginning “O=/migadmin”. A further line names FortiMail::IBE::DecrypterMediaIn and an invalid Base64 exception. The file set is not a scan artifact. It shows added libraries, a preload entry, modified admin and web configuration, and a remote archive account tied to one of the listed addresses.

For a founder selling into enterprises that still run FortiMail as the inbound mail boundary, the advisory is a buyer question, not a vendor footnote. The product is the control plane for mail. The flaw is unauthenticated, the vendor has marked it known exploited, and the fix column does not name a version customers can download today. An investor reading a security stack that depends on FortiMail should treat internet-reachable management interfaces, and any deployment that cannot disable IBE, as unmitigated until 8.0.2, 7.6.7, or 7.4.9 exists. An enterprise buyer should ask when those builds ship, whether the management interface was ever reachable, and whether the published file hashes and the archive234 remote-account log are absent. Reputation exposure sits with the operator who leaves the GUI on the internet, and with any supplier who cannot show the workaround was applied on October 1.

WHY IT MATTERS: Fortinet has told customers the flaw is already reported in the wild and has given them a workaround rather than a build. Until the upcoming releases exist, the published choice is disable IBE or take the management interface off the internet, and the indicator set is specific enough to hunt now.

Subscribe — you own it

No tracking, no middleman. Follow by RSS (nothing is collected) — or add your email to our self-hosted list.

RSS feed →
Subscribe
Notify of
0 Comments
Oldest
Newest Most Voted
0
Would love your thoughts, please comment.x
()
x