No Login, One Request, Any File: FortiMail 9.8 Path-Traversal Zero-Day Was Already Being Exploited

On 1 October 2026 Fortinet published advisory FG-IR-26-175 for CVE-2026-104286, a critical flaw in the FortiMail management interface: an unauthenticated attacker can write arbitrary files to the underlying system with crafted HTTP or HTTPS requests. The NVD-bound rating is CVSS 9.8, the weakness pair is path traversal (CWE-22) plus null-byte neutralization (CWE-158), and Fortinet states plainly that it is being actively exploited. CISA added it to the Known Exploited Vulnerabilities catalog the same day, with forensic triage required and a federal remediation deadline of 4 October — three days, over a weekend.

The uncomfortable detail is the patch situation. At disclosure time there was no fixed release available for the 7.4, 7.6, or 8.0 branches — fixes are promised in upcoming 7.4.9, 7.6.7, and 8.0.2 — and FortiMail 7.2 is told to upgrade to the 7.4 branch or later. A CVSS 9.8 unauthenticated file-write on a mail-security gateway, exploited in the wild, with mitigations-but-no-patch for every supported branch: that is the exact shape of incident this site keeps documenting. Our recent KEV run — Cisco's SD-WAN auth bypass, exploited before most teams finished the advisory, Zimbra's SNMP injection with its webshell-to-root chain, and the NetScaler RCE zero-days — keeps converging on the same lesson: assume post-exploitation first, preserve forensics before you touch anything.

The flaw: traversal plus a null byte

Fortinet's description names two weaknesses working together: improper limitation of a pathname to a restricted directory (CWE-22) and improper neutralization of a null byte (CWE-158), reachable by an unauthenticated attacker through crafted HTTP or HTTPS requests to the management interface. The combination is a classic: the traversal escapes the intended directory, and the null byte truncates whatever suffix the server appends to validate or constrain the path — so the write lands wherever the attacker chooses. The attack surface is the management interface itself, which on too many estates answers on the internet.

The affected versions span four branches: FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9. The flaw was discovered internally by Gwendal Guégniaud of Fortinet's Product Security team — worth noting because the exploitation was already underway when the finder and the vendor were the same organization, which compresses every defender's timeline to zero. Fortinet has not disclosed when exploitation began, how many systems are compromised, or who is behind it, and told press it is coordinating with government agencies including CISA.

What the attackers did: archive accounts and cron lines

Fortinet published indicators of compromise from the active campaigns, and they read like operators settling in rather than opportunists scanning. The advisory lists file hashes added or modified on compromised systems (full set in FG-IR-26-175) plus log entries defenders can hunt directly. The most telling: an archive account named archive234 configured from the CLI to push archived mail to remote host 79.141.169.187, directory /uploads — a compromised mail gateway reconfigured to forward its archive off-site.

Other published log signals include a cron job executing a shell command as root, an administrator logout from a null UI, an IBE decryption error from invalid Base64 input, and failed login bursts. None of this is subtle once you know the strings; the problem is that few teams ship FortiMail management-interface logs anywhere they would be seen. If your appliance's management interface has been internet-reachable, these are the first three places to look before you patch or mitigate — because mitigation without triage destroys the evidence CISA is explicitly requiring agencies to collect.

What to do

  • Triage before you mitigate. CISA's KEV entry mandates forensic triage under BOD 26-04 with an October 4 deadline. Capture management-interface access logs, the archive-account configuration, cron tables, and the IOC file hashes before applying workarounds — then hunt the archive234 account name, the 79.141.169.187 destination, and unexpected cron entries fleet-wide.
  • Apply the IBE workaround now, not after the weekend. Until fixed builds ship, Fortinet's mitigation is disabling IBE feature support via CLI (exact commands in FG-IR-26-175) — and, independently, removing management-interface access from the internet or restricting it to trusted private networks. Do both; neither depends on the other.
  • Plan the upgrade path per branch. Track 7.4.9, 7.6.7, and 8.0.2 for the 7.4, 7.6, and 8.0 lines; FortiMail 7.2 estates must move to the 7.4 branch or later since no 7.2 fix is coming. Treat the mail gateway as already-compromised infrastructure until triage says otherwise — it holds every message it filters.
  • Count the mail gateway as AI-adjacent blast radius. Security gateways like FortiMail increasingly feed automated triage, SOAR playbooks, and agent-driven SOC workflows. A file-write on the appliance that decides what mail your agents and analysts trust is a supply-chain position, not just a perimeter bug — scope downstream consumers of its verdicts, not only the box.

Our write-up is analysis of Fortinet's published advisory and CISA's KEV entry; we did not test the vulnerability. Full IOC hashes and CLI workaround commands are in FG-IR-26-175.

Sources: