FortiMail Path Traversal Zero-Day Under Active Exploitation
Score: 9/10

FortiMail Path Traversal Zero-Day Under Active Exploitation

Unauthenticated attackers are exploiting CVE-2026-104286, a critical path traversal vulnerability in FortiMail, to write arbitrary files and achieve persistent remote code execution.

Executive Summary

Fortinet has disclosed a critical zero-day vulnerability, CVE-2026-104286 (CVSS 9.8), affecting multiple branches of its FortiMail secure email gateway. The flaw arises from improper limitation of a pathname to a restricted directory (CWE-22) and improper neutralization of NULL bytes (CWE-158) in the web-based management interface. This vulnerability is currently under active exploitation in the wild, allowing unauthenticated remote attackers to write arbitrary files to the underlying system via crafted HTTP or HTTPS requests.

Technical analysis of observed intrusions reveals that attackers are using the file-write primitive to establish persistence by dropping malicious shared libraries and modifying system configurations, including ld.so.preload. Compromised systems show evidence of unauthorized archive accounts (e.g., 'archive234') configured to exfiltrate email data to attacker-controlled infrastructure. At the time of disclosure, official patches were listed as upcoming, placing significant urgency on the implementation of temporary workarounds.

Given that FortiMail appliances occupy highly trusted positions at network boundaries and process sensitive enterprise communications, a compromise represents a total technical impact. Organizations should assume that vulnerability alone does not define risk; if a vulnerable appliance was exposed, a thorough incident response investigation for existing persistence and data exfiltration is required.

Key Details

Threat Name

CVE-2026-104286

Affects

FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9, Fortinet FortiMail 8.0.0–8.0.1, Fortinet FortiMail 7.6.0–7.6.6, Fortinet FortiMail 7.4.0–7.4.8, Fortinet FortiMail 7.2.0–7.2.9, Rejetto HFS, Zammad GmbH, Apple iOS 26.7.1, Apple iPadOS 26.7.1

Adversary

—

Malware/Tools

webconsole, mailservice, liblog.so

Report Score

9out of 10
Quality Score
Excellent
IOC Quality9
TTP Details9
Detection Guidance7
Enterprise Relevance10
Clarity & Structure9
Technical Depth8

Sources