Oct 2
/
Latest News
CISA Adds Actively Exploited Fortinet FortiMail Path Traversal Flaw to KEV Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a critical Fortinet FortiMail vulnerability to its Known Exploited Vulnerabilities (KEV) catalog after confirming active exploitation of a flaw that allows unauthenticated attackers to write arbitrary files to the underlying system.
Tracked as CVE‑2026‑104286 with a CVSS score of 9.8, the issue stems from improper path restriction and improper neutralization of NULL bytes, enabling attackers to deliver crafted HTTP or HTTPS requests that bypass directory controls. Fortinet said the vulnerability affects FortiMail versions 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9, with upgrades required to upcoming fixed releases.
Fortinet acknowledged in‑the‑wild exploitation and advised customers to apply temporary workarounds where patches are not yet available. These include disabling IBE feature support via CLI and restricting external access to the FortiMail management interface. The company credited Gwendal Guégniaud of its Product Security team for identifying and reporting the flaw.
Indicators of compromise shared by Fortinet include malicious or modified files such as /data/lib/liblog.so, /data/bin/webconsole, /data/bin/mailservice, /data/etc/ld.so.preload, and changes to /bin/smit, /data/etc/httpd.conf, and /data/migadmin.tar.gz. Associated IP addresses include 79.141.169[.]187 and 45.129.0[.]192.
Federal Civilian Executive Branch (FCEB) agencies are required to apply patches or workarounds by October 4, 2026 due to confirmed exploitation. The FortiMail flaw joins a growing list of vulnerabilities under active attack across major vendors, including Check Point, Arista VeloCloud Orchestrator, F5 BIG‑IP APM, Cisco Catalyst SD‑WAN Manager, and Citrix NetScaler ADC and Gateway.
Tracked as CVE‑2026‑104286 with a CVSS score of 9.8, the issue stems from improper path restriction and improper neutralization of NULL bytes, enabling attackers to deliver crafted HTTP or HTTPS requests that bypass directory controls. Fortinet said the vulnerability affects FortiMail versions 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9, with upgrades required to upcoming fixed releases.
Fortinet acknowledged in‑the‑wild exploitation and advised customers to apply temporary workarounds where patches are not yet available. These include disabling IBE feature support via CLI and restricting external access to the FortiMail management interface. The company credited Gwendal Guégniaud of its Product Security team for identifying and reporting the flaw.
Indicators of compromise shared by Fortinet include malicious or modified files such as /data/lib/liblog.so, /data/bin/webconsole, /data/bin/mailservice, /data/etc/ld.so.preload, and changes to /bin/smit, /data/etc/httpd.conf, and /data/migadmin.tar.gz. Associated IP addresses include 79.141.169[.]187 and 45.129.0[.]192.
Federal Civilian Executive Branch (FCEB) agencies are required to apply patches or workarounds by October 4, 2026 due to confirmed exploitation. The FortiMail flaw joins a growing list of vulnerabilities under active attack across major vendors, including Check Point, Arista VeloCloud Orchestrator, F5 BIG‑IP APM, Cisco Catalyst SD‑WAN Manager, and Citrix NetScaler ADC and Gateway.
Executive IT Forums, Inc.
Educational Programs on Information Technology, Governance, Risk Management, & Compliance (GRC).
Our Newsletter
Get regular updates on CPE programs, news, and more.
Thank you!
Copyright © 2026 Executive IT Forums, Inc. All Rights Reserved.
Get started
Let us introduce our school
Write your awesome label here.