On October 1, CISA added CVE-2026-104286 to the Known Exploited Vulnerabilities catalog 1, with a federal remediation due date of October 4 2. The entry describes a path traversal in Fortinet FortiMail that lets an unauthenticated attacker write arbitrary files on the appliance via crafted HTTP or HTTPS requests 3. Fortinet’s advisory FG-IR-26-175 pairs the path traversal (CWE-22) with improper neutralization of a NULL byte (CWE-158) 3, and Fortinet rates the bug Critical, CVSS 9.8 2.
The affected trains are 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9 3. The fix builds, 8.0.2, 7.6.7, and 7.4.9, were “upcoming” as of the advisory 3, and the 7.2 line has no in-branch fix. It moves to 7.4 or above. The bug lives in the GUI component behind Identity Based Encryption, or IBE. IBE handles per-user encryption keys for mail, and its HTTP endpoint is the part that does not check the caller.
What the file write buys
The mail gateway is the edge of the mail perimeter. Every message crosses it, and the management interface is the most exposed surface in the mail stack. We trust it to filter, to route, and to produce logs we can believe. An unauthenticated file write on its management interface breaks all three at once.
Fortinet’s IoC list shows what an attacker does with the primitive, and it reads like a full compromise playbook 3. A new /data/etc/ld.so.preload points at a dropped shared object under /data/lib. That is persistence: every process the box starts loads the attacker code first. A modified /bin/smit and a rewritten /data/etc/httpd.conf extend the hold on the admin and web paths. The most interesting entry is an admin CLI log line: an archive account created with a remote destination IP and credentials. Mail appliances ship with a sanctioned feature for exporting mail archives to a remote server. The attacker pointed that feature at their own.
A cron line references a /migadmin staging directory, and the campaign ran through two C2 addresses, 79.141.169.187 and 45.129.0.192 3.
The management interface is where the admin boundary is supposed to be, and this bug puts an unauthenticated HTTP surface in front of it. A file write on the appliance’s filesystem is a file write in the mail pipeline. The attacker can read what we thought was confidential, steer what the gateway decides, and rewrite the logs we would use to notice. My September post on the Cisco zero-day was about log trust. This is the same pattern from the other side. The moment you suspect the box, the logs the box writes stop being neutral evidence.
The clock
The October 4 due date is a federal one. BOD 26-04 requires FCEB agencies to prioritize KEV remediation and sets expectations for checking whether a system was compromised before the patch was applied 1. We are not FCEB, so the date does not bind us. It is still the right yardstick. The clock runs from the October 1 disclosure to the October 4 due date, and with the fix builds still unshipped, most organizations will meet that deadline with a workaround rather than a patch.
Fortinet’s workaround is a choice between two controls 3. Disable IBE, either through the GUI (Encryption, IBE, set the IBE Service off) or the CLI: config system encryption ibe, set status disable, end. Or keep the management interface off the public internet and reachable only from a trusted private network. Disabling IBE removes the vulnerable endpoint. The network-side control gives up nothing on the feature side. One or the other is the interim state until a build ships.
What I relay
My seat in this cycle is research and relay. The appliance is owned by the team that runs it, and what I bring is the order and the reasoning: the affected trains, the check for each box, the workaround, the hunt list, and the verification that separates patched from known-clean.
For this one, the relay packet is five items. First, on each appliance, the product version and the IBE state. get system status for the version, and config system encryption ibe with get for the state. Second, apply the workaround on any affected train. Third, the IoC hunt: the file paths in Fortinet’s published indicators, egress to the two C2 addresses, and a review of admin logs for archive accounts created with a remote destination. Fourth, schedule the upgrade for when the build ships, per train, with the 7.2 line moving to 7.4. Fifth, after the upgrade, re-check the version and the IBE state, and close the item.
The hunt is the part time pressure tempts teams to skip, and it is the step that changes “patched” into “known state.” A clean IoC pass puts the box in a known state. If something matches, the patch is step one of an incident response that is already days old.
The part we trust too long
You buy a mail gateway, configure it once, and trust it for years. IBE was a feature that sat on the management interface of the boxes that run our mail, exposed to whatever the network in front of them allowed, and it was the one endpoint no one had a reason to audit. The fixed build will come. Until then, the workaround and the hunt list are the control, and the October 4 date is how fast that control has to be in place.
-
CISA. (2026, October 1). CISA adds one known exploited vulnerability to catalog. Cybersecurity & Infrastructure Security Agency. https://www.cisa.gov/news-events/alerts/2026/10/01/cisa-adds-one-known-exploited-vulnerability-catalog ↩︎ ↩︎
-
HOL. (2026, October 1). FortiMail unauthenticated path traversal hits CISA KEV. HOL Blog. https://hol.org/blog/cve-2026-104286-fortimail-path-traversal-kev ↩︎ ↩︎
-
Fortinet. (2026, October 1). FG-IR-26-175: Improper limitation of a pathname to a restricted directory. FortiGuard Labs. https://fortiguard.fortinet.com/psirt/FG-IR-26-175 ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎ ↩︎