
CVE-2026-104286 FortiMail path traversal enables unauthenticated file writes, added to CISA KEV with active IOCs
FortiMail zero-day CVE-2026-104286 permits unauthenticated file writes and is under active exploitation. CISA mandates mitigation by early October while Fortinet lists specific IOCs. The case reveals recurring exposure patterns in internet-facing security appliances.
The flaw stems from CWE-22 and CWE-158 in the IBE encryption feature, allowing crafted HTTP requests to write files such as /data/lib/liblog.so and modify ld.so.preload. Fortinet supplied four IOC IP addresses and seven file artifacts, confirming in-the-wild use before any public patch for older branches. Workarounds require disabling IBE or restricting management interface access.
This incident fits a documented pattern across 2026 where email and SD-WAN appliances from Fortinet, Check Point, F5, and Citrix face repeated unauthenticated write primitives. Procurement records show these devices often expose management planes to the internet despite vendor guidance, creating persistent attack surfaces that KEV listings later ratify.
Independent verification of exploitation remains limited to the IOCs Fortinet released; no third-party sandbox traces or victim telemetry have surfaced yet. CISA's October 4, 2026 deadline for FCEB agencies will likely accelerate scanning campaigns and force rapid branch upgrades.
Next indicators to watch are new samples of /data/bin/webconsole and changes to httpd.conf on exposed instances, which historically precede ransomware staging on mail gateways.
CISA: At least 200 additional FortiMail instances show IOC matches by 15 October 2026
Sources (3)
- [1]Fortinet PSIRT Advisory(https://www.fortinet.com/psirt/FG-IR-26-104286)
- [2]CISA Known Exploited Vulnerabilities Catalog(https://www.cisa.gov/known-exploited-vulnerabilities-catalog)
- [3]The Hacker News Report(https://thehackernews.com/2026/10/critical-fortimail-zero-day-flaw.html)