Oct 2 / Latest News

CISA Adds Actively Exploited Fortinet FortiMail Path Traversal Flaw to KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a critical Fortinet FortiMail vulnerability to its Known Exploited Vulnerabilities (KEV) catalog after confirming active exploitation of a flaw that allows unauthenticated attackers to write arbitrary files to the underlying system.

Tracked as CVE‑2026‑104286 with a CVSS score of 9.8, the issue stems from improper path restriction and improper neutralization of NULL bytes, enabling attackers to deliver crafted HTTP or HTTPS requests that bypass directory controls. Fortinet said the vulnerability affects FortiMail versions 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9, with upgrades required to upcoming fixed releases.

Fortinet acknowledged in‑the‑wild exploitation and advised customers to apply temporary workarounds where patches are not yet available. These include disabling IBE feature support via CLI and restricting external access to the FortiMail management interface. The company credited Gwendal Guégniaud of its Product Security team for identifying and reporting the flaw.

Indicators of compromise shared by Fortinet include malicious or modified files such as /data/lib/liblog.so, /data/bin/webconsole, /data/bin/mailservice, /data/etc/ld.so.preload, and changes to /bin/smit, /data/etc/httpd.conf, and /data/migadmin.tar.gz. Associated IP addresses include 79.141.169[.]187 and 45.129.0[.]192.

Federal Civilian Executive Branch (FCEB) agencies are required to apply patches or workarounds by October 4, 2026 due to confirmed exploitation. The FortiMail flaw joins a growing list of vulnerabilities under active attack across major vendors, including Check Point, Arista VeloCloud Orchestrator, F5 BIG‑IP APM, Cisco Catalyst SD‑WAN Manager, and Citrix NetScaler ADC and Gateway.