What it is
CVE-2026-104286 is an unauthenticated vulnerability affecting Fortinet FortiMail. An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through...
Vulnerability report
FortiMail Path traversal
Fortinet / FortiMail · 8.0.0
Decision summary
Direct answers before the deeper technical record.
What it is
CVE-2026-104286 is an unauthenticated vulnerability affecting Fortinet FortiMail. An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through...
Is it exploited?
Yes. Previdian tracks this CVE as a known exploited vulnerability. Confidence is confirmed. Listed in CISA KEV. Also confirmed by third-party sources.
Who is affected?
Fortinet / FortiMail 8.0.0.
What should we do?
Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
Overview
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
Exploitation evidence
Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.
FortiGuard Center - Outbreak Alerts
A trusted third party reported exploitation.
GitHub
Public scanner or PoC coverage increases practical exploitability.
Per-source evidence links for KEV attestations are available through the Previdian Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| FortiGuard Center - Outbreak Alerts First | 2026-10-01 19:38 UTC |
| FortiGuard | 2026-10-01 19:47 UTC |
| CISA | 2026-10-01 20:01 UTC |
| The Hacker News | 2026-10-02 06:21 UTC |
| Security Affairs | 2026-10-02 07:21 UTC |
| CERT Polska | 2026-10-02 09:21 UTC |
| TheRegister | 2026-10-02 11:20 UTC |
Detection
Make the evidence actionable in scanner, SOC, and edge-control workflows.
Request targets and User-Agents available in Pro. Callback host details available in Enterprise.
No scanner integrations recorded yet.
No Previdian virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.
Learn about virtual patches →No detection artifacts or sensor request patterns are available for this CVE yet.
Check back as sensor telemetry and scanner integrations are updated.
Risk and context
CVSS v3.1
Potential damage if exploited. Separate from whether attackers are using it.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
EPSS
—
Estimated chance of exploitation in the next 30 days. Previdian's warning comes from evidence, not this score.
Recent mention · TheRegister
No login required, exploitation underway, and some admins are still waiting for patches
Read full advisoryRecent mention · TheRegister
Fortinet sounds the alarm over actively exploited FortiMail zero-dayTheRegister · 02 Oct 2026
No login required, exploitation underway, and some admins are still waiting for patches
Recent mention · CERT Polska
Krytyczna podatność w FortiMail aktywnie wykorzystywana w atakachCERT Polska · 02 Oct 2026
Zespół CERT Polska informuje o krytycznej podatności w FortiMail.Podatność, oznaczona jako CVE-2026-104286, umożliwia nieuwierzytelnionemu atakującemu zapisywanie dowolnych plików w systemie i w konsekwencji wykonanie dowolnego kodu, poprzez specjalnie sformatowane żądania HTTP. Wykorzystanie podatności wymaga dostępu do interfejsu zarządzania FortiMail. Producent potwierdza, że luka jest aktywnie wykorzystywana w atakach.Podatność dotyczy następujących wersji:FortiMail 8.0: 8.0.0 - 8.0.1FortiMail 7.6: 7.6.0 - 7.6.6FortiMail 7.4: 7.4.0 - 7.4.8FortiMail 7.2: 7.2.0 - 7.2.9Na moment publikacji...
Recent mention · NCSC Security Advisories
NCSC-2026-0398 [1.00] [M/H] Kwetsbaarheid verholpen in Fortinet FortiMailNCSC Security Advisories · 02 Oct 2026
Fortinet heeft een kwetsbaarheid verholpen in FortiMail. FortiMail bevat een kritieke kwetsbaarheid (CVE-2026-104286) in de verwerking van bestandspaden, veroorzaakt door een combinatie van Path Traversal (CWE-22) en onvoldoende neutralisatie van NULL-bytes (CWE-158). Een niet-geauthenticeerde aanvaller kan via speciaal vervaardigde HTTP- of HTTPS-verzoeken willekeurige bestanden op het onderliggende systeem schrijven. De kwetsbaarheid wordt actief geëxploiteerd. Getroffen zijn FortiMail 7.2.0–7.2.9, 7.4.0–7.4.8, 7.6.0–7.6.6 en 8.0.0–8.0.1 waarbij de functionaliteit IBE (Identity Based...
Recent mention · Security Affairs
U.S. CISA adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs · 02 Oct 2026
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Fortinet FortiMail flaw, tracked as CVE-2026-104286 (CVSS score of 9.8), to its Known Exploited Vulnerabilities (KEV) catalog. The flaw is a path traversal vulnerability that can be triggered through […]
Recent mention · The Hacker News
Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File WritesThe Hacker News · 02 Oct 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerability, tracked as CVE-2026-104286 (CVSS score: 9.8), allows unauthenticated attackers to write arbitrary files on the underlying system. "An improper
Recent mention · FortiGuard
Improper limitation of a pathname to a restricted directoryFortiGuard · 01 Oct 2026
CVSSv3 Score: 9.8 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] and Improper Neutralization of NULL Byte or NULL Character [CWE-158] vulnerability may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.This has been reported to be exploited in the wild, customers are urged to apply the workaround below. Revised on 2026-10-01 00:00:00
These PoCs are unverified and could contain malware. Use at your own risk.
github · Created 2026-10-01 22:15:42 UTC · 0 stars · AI assessment 85%
Timeline
11:20 UTC
Exploitation attested by an external source
09:21 UTC
Exploitation attested by an external source
07:21 UTC
Exploitation attested by an external source
06:21 UTC
Exploitation attested by an external source
22:15 UTC
Public proof-of-concept code published
20:01 UTC
Listed in the CISA Known Exploited Vulnerabilities catalog
19:47 UTC
Exploitation attested by an external source
19:38 UTC
High-confidence, third-party attested exploitation
19:17 UTC
Vulnerability disclosed publicly
19:12 UTC
Identifier reserved by the CNA
Pro API
Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
GET /api/v2/pro/kevs/CVE-2026-104286
Free JSON includes basic KEV fields{
"cve_id": "CVE-2026-104286",
"confidence": "Confirmed",
"cvss_score": 9.8,
"cvss_estimated": false,
"epss_score": null,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": false
},
"sensor_telemetry": { "attempts": 0, "sensors": 0 }
}