What happened
Fortinet’s advisory FG-IR-26-175 warns that FortiMail versions 7.2‑0 through 8.0‑1 contain a critical path‑traversal and NULL‑byte flaw (CVE‑2026‑104286) with a CVSS score of 9.8. The company says the bug is already being weaponised in zero‑day attacks.
Technical specifics
The defect lets an unauthenticated attacker send a specially crafted HTTP or HTTPS request that tricks the mail gateway into writing arbitrary files anywhere on the filesystem. By appending a NULL byte to the filename the server bypasses normal validation.
Who’s affected
Any deployment running one of the following firmware releases is vulnerable:
- 7.2.0‑7.2.9
- 7.4.0‑7.4.8
- 7.6.0‑7.6.6
- 8.0.0‑8.0.1
Indicators of compromise
Fortinet published a short list of IOCs that have been seen in the wild:
- File paths with accompanying SHA‑256 hashes (exact paths omitted for brevity)
- IP address 79.141.169.187
- IP address 45.129.0.192
Mitigation and remediation
Until a patch lands, administrators can take two practical steps:
- Disable the IBE feature:
config system encryption ibe; set status disable; end - Block Internet access to the FortiMail management UI or restrict it to trusted private networks.
Fortinet says fixed firmware will be released in the upcoming 7.4.9, 7.6.7 and 8.0.2 builds. Apply them as soon as they are available.
Regulatory note
CISA has added CVE‑2026‑104286 to its Known Exploited Vulnerabilities catalog and set an October 4 mitigation deadline for federal agencies.
