Fortinet FortiMail Path Traversal Vulnerability
TL;DR 📌
- Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
- Listed in CISA KEV (2026-10-01) — this is being exploited in the wild.
- Check the advisory for fixed releases — remediation detail is in the vendor link below.
- CVEs: CVE-2026-104286.
What it is
CVE-2026-104286 is a path traversal vulnerability in Fortinet FortiMail, combined with improper neutralisation of NULL byte or NULL character sequences. The combination allows an attacker to manipulate file paths handled by the product’s web-facing component.
The access path is unauthenticated: an attacker sends crafted HTTP or HTTPS requests to FortiMail and does not need valid credentials to trigger the flaw. This places the vulnerability on FortiMail’s management or web interface rather than requiring any prior foothold on the device.
The impact is arbitrary file write on the underlying system. An attacker who can write files outside the intended directory structure can potentially place content that leads to further compromise of the host running FortiMail, though the specifics of what can be written and where are not detailed beyond the path traversal and NULL byte mechanism.
This CVE is listed in CISA’s Known Exploited Vulnerabilities catalogue, added on 2026-10-01, meaning it is known to be exploited.
What to do
- Treat this as urgent given its presence in the KEV catalogue. Prioritise patching or isolating affected FortiMail instances immediately.
- No fixed version is stated here — consult Fortinet’s advisory directly for the patched release applicable to your FortiMail version and apply it as soon as it is available.
- Restrict exposure of the FortiMail HTTP/HTTPS management interface to trusted networks only; do not leave it reachable from the general internet while remediation is pending.
- Review FortiMail web server and system logs for unusual file write activity or unexpected requests containing path traversal sequences (e.g.
../) or NULL byte characters (%00), as these are the mechanism described for this flaw. - If CISA KEV deadlines apply to your organisation, confirm this CVE’s remediation due date and track it accordingly.
For leadership 🧭
Executive summary. FortiMail’s web-facing management interface can be tricked into writing files outside its intended directory to anyone who can reach it over HTTP or HTTPS, with no credentials needed, and it is already being exploited in the wild. This should be treated as a same-day priority: isolate exposed interfaces now and apply Fortinet’s fix as soon as it is available.
Why it matters:
- The flaw sits in FortiMail’s HTTP/HTTPS management interface, so any attacker who can reach that interface over the network can trigger it without a valid account.
- Arbitrary file write on the underlying host gives an attacker a foothold to plant content that can lead to further compromise of the mail server.
- The CVE is in CISA’s KEV catalogue, confirming it is being actively exploited rather than a theoretical risk.
- No patched version is specified, meaning teams must consult Fortinet directly to find the correct fix for their FortiMail build.
Now / Next / Later:
- Now: Check whether FortiMail’s HTTP/HTTPS management interface is reachable from the internet or untrusted networks and restrict it to trusted management networks immediately.
- Next: Obtain and apply the Fortinet-supplied patched release for your FortiMail version in the next available change window, confirming the fix against Fortinet’s own advisory since no version details are given here.
- Later: Establish a standing rule that FortiMail (and similar appliance) management interfaces are never exposed directly to the internet, and build log monitoring for path traversal and NULL byte patterns into routine detection.