Fortinet Warns of Exploited FortiMail Path Traversal
Quick Answer
Fortinet published FG-IR-26-175 for an exploited FortiMail path-traversal flaw. Restrict management access, disable IBE where operationally acceptable, preserve Fortinet-listed indicators and logs, and deploy the supported fixed release as soon as it is available.
Confirm Scope And Apply The Supported Fix
What to do now: Identify affected FortiMail appliances, isolate management access from untrusted networks, apply Fortinet's IBE workaround where approved, inspect the advisory-listed files, hashes, IP addresses, and logs, and upgrade to the supported fixed release when available.
Last verified: 2026-10-01 UTC. Recheck the authoritative advisory and supported distribution channel before changing production.
Scope And Authority
| Product scope | FortiMail 8.0, 7.6, 7.4, and 7.2 release families in the advisory-listed ranges |
|---|---|
| Advisory | FG-IR-26-175 / CISA KEV CVE-2026-104286 |
| CVE | CVE-2026-104286 |
| Authoritative release date | 2026-10-01 00:00:00 UTC |
| Authority revision date | 2026-10-01 00:00:00 UTC |
| Affected versions | FortiMail 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8, and 7.2.0–7.2.9. |
| Fixed version | FortiMail 8.0.2, 7.6.7, or 7.4.9 when available; migrate 7.2 deployments to 7.4 or later |
| CVSS base score | 9.8 (official CVSS v3.1) |
| CVSS severity | Critical |
| Exploitation status | Fortinet confirms exploitation in the wild; CISA added the CVE to KEV on 2026-10-01; no exploitation claim is inferred. |
What Changed
Fortinet reports an unauthenticated path-traversal and NULL-byte issue that can permit arbitrary file writes through crafted HTTP or HTTPS requests. Fortinet and CISA confirm exploitation.
What To Validate Now
- Inventory. Locate FortiMail 8.0, 7.6, 7.4, and 7.2 release families in the advisory-listed ranges deployments, versions, enabled features, exposure paths, owners, and dependent services.
- Establish applicability. Compare each deployment with the authority's affected-version statement: FortiMail 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8, and 7.2.0–7.2.9. Do not infer applicability from product family or severity alone.
- Remediate. Install FortiMail 8.0.2, 7.6.7, or 7.4.9 when Fortinet makes the matching release available; migrate 7.2 systems to 7.4 or later. Until then, disable IBE or remove internet management access and restrict management to a trusted private network.
- Validate. Confirm management-plane restrictions and IBE state, compare the appliance with Fortinet's current indicators, preserve relevant logs and files before cleanup, validate mail flow and encryption workflows, and confirm the final fixed version.
- Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.
Operational Cautions
A clean indicator review does not prove absence of compromise. Preserve volatile and appliance evidence before eradication, coordinate IBE changes with mail operations, and recheck Fortinet because the fixed releases were marked upcoming when verified.
Evidence To Retain
- Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
- UTC timestamps, authority revision, approved change record, installer or package-manager output, and resulting version.
- Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.
Related TechGeeks Resources
Authoritative References
Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.

