Back to Intelligence

CVE-2026-104286: Fortinet FortiMail Path Traversal Actively Exploited — Detection and Remediation Guide

SA
Security Arsenal Team
October 1, 2026
10 min read

On October 1, 2026, CISA added CVE-2026-104286 to the Known Exploited Vulnerabilities (KEV) catalog, confirming that a path traversal and improper NULL byte neutralization vulnerability in Fortinet FortiMail is being actively exploited in the wild. The flaw allows an unauthenticated remote attacker to write arbitrary files on the underlying system using crafted HTTP or HTTPS requests against the FortiMail appliance.

Let me be blunt about what this means: FortiMail sits at the email perimeter of thousands of organizations, processing every inbound message for spam, phishing, and malware. It is, by design, internet-facing. A pre-authentication arbitrary file write on that class of device is functionally equivalent to remote code execution — an attacker who can write files to arbitrary paths on a Linux-based appliance can drop a webshell into the web service directory, plant a cron job, overwrite an executable invoked by a privileged service, or tamper with SSH authorized keys. Every organization running FortiMail should treat this as an active-incident scenario, not a routine patch Tuesday item.

Technical Analysis

Affected Component and Attack Chain

FortiMail is Fortinet's secure email gateway appliance, available as hardware, VM, and cloud-hosted instances. The vulnerability chain in CVE-2026-104286 combines two weaknesses:

  1. Path traversal (CWE-22): The HTTP/HTTPS request handler fails to properly sanitize directory traversal sequences (../ and encoded variants such as %2e%2e%2f, ..%2f, and double-encoded %252e%252e) in request URIs or parameters handled by the FortiMail web services (admin GUI, webmail, and API endpoints typically listening on TCP/443).
  2. Improper NULL byte neutralization (CWE-158): The application fails to reject or sanitize NULL bytes (%00) embedded in the request. On the underlying C-style string handling, the NULL byte truncates the path string at a different point than the application's validation logic sees — so a request like /safe/path/..%00../../etc/cron.d/payload may pass validation against the visible prefix while the filesystem operation resolves the full traversal. This is the classic trick that defeats naive allowlist/extension checks on file write operations.

The combination yields an unauthenticated arbitrary file write. No credentials, no user interaction, no prior foothold — just crafted requests to an exposed HTTPS service.

Why Arbitrary File Write Equals RCE Here

Defenders should model realistic post-exploitation paths on the appliance:

  • Webshell drop: Writing a .jsp/.php/script file into a web-served directory gives the attacker a persistent, interactive foothold reachable over the same 443 service.
  • Cron / rc script injection: Writing to scheduled-task locations achieves privileged execution at the next cycle or reboot.
  • Persistence and credential access: Once on the box, attackers can harvest mail content, administrator credentials, LDAP bind accounts, and API tokens — FortiMail holds all of these by design.
  • Pivot point: A compromised email gateway is an ideal launchpad for internal phishing, mail interception, and lateral movement with trusted-sender identity.

Exploitation Status

  • CISA KEV: Confirmed active exploitation (added 2026-10-01).
  • Federal civilian agencies are directed to remediate under CISA BOD 26-04 — Prioritizing Security Updates Based on Risk, and CISA's KEV entry additionally references its Forensics Triage Requirements — a strong signal that CISA expects responders to preserve evidence and assume pre-patch compromise.
  • Given Fortinet's history as a top target for initial-access brokers and nation-state operators, expect exploitation to scale rapidly now that KEV listing has drawn broad attention.

Affected versions: Consult the Fortinet PSIRT advisory for the definitive affected/fixed version matrix for your FortiMail train (7.x/6.x). Because KEV listing implies mass scanning and exploitation, do not wait to confirm your version before beginning the hunt steps below.

Detection & Response

The highest-fidelity detections for this vulnerability focus on two observable behaviors: (1) traversal and NULL byte sequences in HTTP requests destined for the FortiMail web services, and (2) post-exploitation file writes and process anomalies on the appliance. Forward FortiMail logs (HTTP access, system event, and admin logs) via syslog/CEF to your SIEM if you are not already doing so — without those logs you are blind to both the exploit attempt and the intrusion.

Sigma Rules

YAML
---
title: FortiMail Path Traversal Attempt via Crafted HTTP Request
id: 3f9c2a71-8b4d-4e62-a1c9-7d5e2f8b9301
status: experimental
description: Detects directory traversal sequences (raw and encoded) in HTTP request URIs targeting web services, consistent with CVE-2026-104286 exploitation against Fortinet FortiMail.
references:
  - https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  - https://attack.mitre.org/techniques/T1190/
author: Security Arsenal
date: 2026/10/02
tags:
  - attack.initial_access
  - attack.t1190
logsource:
  category: webserver
detection:
  selection_traversal:
    cs-uri|contains:
      - '../'
      - '..\\'
      - '%2e%2e'
      - '..%2f'
      - '%2e%2e%2f'
      - '..%5c'
      - '%252e%252e'
      - '..;/'
  condition: selection_traversal
falsepositives:
  - Rare; some legacy applications legitimately use relative paths in parameters. Baseline against your environment and alert on spikes.
level: high
---
title: NULL Byte Injection in HTTP Request URI
id: 8d4e6b12-5c7a-4f39-b2e8-1a6d9c3e4472
status: experimental
description: Detects NULL byte (%00) sequences in HTTP request URIs, a hallmark of the improper NULL byte neutralization weakness chained with path traversal in CVE-2026-104286 (Fortinet FortiMail).
references:
  - https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  - https://attack.mitre.org/techniques/T1190/
author: Security Arsenal
date: 2026/10/02
tags:
  - attack.initial_access
  - attack.t1190
logsource:
  category: webserver
detection:
  selection:
    cs-uri|contains:
      - '%00'
      - '%2500'
      - '\x00'
  condition: selection
falsepositives:
  - Essentially none in legitimate traffic; NULL bytes in URIs are almost always malicious or a misbehaving scanner.
level: critical
---
title: Script or Webshell Dropped in Web-Served Directory on Linux Appliance
id: c17a9f34-2e8b-4d51-9a6c-4b3e7f1d8825
status: experimental
description: Detects creation of script files (jsp, php, py, sh, pl) in web-served or world-writable directories, a common post-exploitation artifact of arbitrary file write vulnerabilities such as CVE-2026-104286.
references:
  - https://attack.mitre.org/techniques/T1505/003/
  - https://www.cisa.gov/known-exploited-vulnerabilities-catalog
author: Security Arsenal
date: 2026/10/02
tags:
  - attack.persistence
  - attack.t1505.003
logsource:
  category: file_event
  product: linux
detection:
  selection_ext:
    TargetFilename|endswith:
      - '.jsp'
      - '.jspx'
      - '.php'
      - '.py'
      - '.pl'
      - '.sh'
  selection_path:
    TargetFilename|contains:
      - '/htdocs/'
      - '/www/'
      - '/webroot/'
      - '/html/'
      - '/tmp/'
      - '/var/tmp/'
      - '/dev/shm/'
  condition: selection_ext and selection_path
falsepositives:
  - Legitimate administrative or update activity; correlate with change windows and FortiMail firmware upgrade timelines.
level: high

KQL Hunt (Microsoft Sentinel / Defender)

This query hunts FortiMail syslog/CEF telemetry in Sentinel for traversal and NULL byte sequences in requested URLs. It also surfaces outbound connections from the appliance to rare destinations — a proxy for post-exploitation webshell callbacks.

KQL — Microsoft Sentinel / Defender
// Hunt 1: Exploit attempts — traversal / NULL byte patterns in requests to FortiMail
let timeframe = 30d;
let traversal_patterns = dynamic(["../", "%2e%2e", "..%2f", "%2e%2e%2f", "..%5c", "%252e%252e", "%00", "%2500", "..;/"]);
CommonSecurityLog
| where TimeGenerated > ago(timeframe)
| where DeviceVendor =~ "Fortinet" or DeviceProduct has "FortiMail" or Computer has "fortimail"
| where isnotempty(RequestURL)
| extend UrlLower = tolower(RequestURL)
| where UrlLower has_any (traversal_patterns)
| project TimeGenerated, SourceIP, SourcePort, DestinationIP, DestinationPort, RequestMethod, RequestURL, DeviceAction, DeviceSeverity, Message
| order by TimeGenerated desc;
// Hunt 2: Suspicious outbound connections from the FortiMail appliance (possible webshell/C2 callback)
DeviceNetworkEvents
| where TimeGenerated > ago(7d)
| where DeviceName has_any ("fortimail", "fml") or LocalIP in (dynamic(["<FORTIMAIL_IP_HERE>"]))
| where RemoteIP !in ("8.8.8.8", "update.fortiguard.com", "fortiguard.net") // tune to your egress baseline
| summarize Connections = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated) by DeviceName, LocalIP, RemoteIP, RemotePort, InitiatingProcessFileName
| order by Connections asc; // rare, low-count destinations are the interesting ones

Velociraptor VQL

FortiMail appliances don't run endpoint agents, but if you've identified post-exploitation activity pivoting from the gateway — or you run FortiMail VM on a monitored hypervisor/Linux host — this artifact hunts for the classic arbitrary-file-write aftermath: recently dropped scripts in writable directories and unexpected listening/outbound connections.

VQL — Velociraptor
-- Hunt for recently created script files in web-served and world-writable paths
-- plus anomalous network connections, consistent with arbitrary file write exploitation
LET recent_scripts = SELECT FullPath, Size, Mtime, Ctime
FROM glob(globs=['/tmp/**.sh', '/tmp/**.py', '/var/tmp/**.sh', '/var/tmp/**.py',
                 '/dev/shm/**', '/var/www/**/*.jsp', '/var/www/**/*.php',
                 '/opt/**/htdocs/**/*.jsp', '/opt/**/htdocs/**/*.php'],
          accessor='file')
WHERE Mtime > now() - 7 * 24 * 3600
ORDER BY Mtime DESC;

SELECT * FROM recent_scripts;

-- Correlate with unusual established outbound connections
SELECT Pid, Name, LocalAddr, LocalPort, RemoteAddr, RemotePort, State
FROM netstat()
WHERE State =~ 'ESTABLISHED|LISTEN'
  AND NOT RemoteAddr =~ '^(10\\.|172\\.(1[6-9]|2[0-9]|3[01])\\.|192\\.168\\.|127\\.)'
ORDER BY RemoteAddr;

Verification and Hardening Script

Run the following on the FortiMail CLI (SSH) to verify firmware state, hunt logs for exploit indicators, and lock down management-plane exposure. Capture the output to your IR evidence store before upgrading — per CISA's Forensics Triage Requirements, assume the appliance may already be compromised and preserve evidence first.

Bash / Shell
#!/bin/bash
# CVE-2026-104286 — FortiMail triage and hunting helper (run via SSH admin session)
# 1) Record current firmware version and build for advisory comparison
get system status | tee /tmp/fml_status_$(date +%Y%m%d).txt

# 2) Hunt HTTP/admin logs for traversal and NULL byte exploit patterns
#    (adjust log paths per your FortiMail log configuration)
for log in $(ls /var/log/http* /var/log/gui* 2>/dev/null); do
  echo "=== Scanning $log ==="
  grep -Eia '\.\./|%2e%2e|\.\.%2f|\.\.%5c|%252e%252e|%00|%2500|\.\.;/' "$log" \
    | tee -a /tmp/fml_traversal_hits_$(date +%Y%m%d).txt
done

# 3) Enumerate recently modified files in web-served and world-writable dirs (last 14 days)
find /tmp /var/tmp /dev/shm -type f -mtime -14 -ls 2>/dev/null | tee /tmp/fml_recent_files.txt
find / -type d \( -name htdocs -o -name webroot -o -name www \) 2>/dev/null | while read d; do
  find "$d" -type f \( -name '*.jsp' -o -name '*.php' -o -name '*.sh' -o -name '*.py' \) -mtime -14 -ls
done | tee -a /tmp/fml_recent_files.txt

# 4) Review unexpected scheduled tasks and startup items
ls -la /etc/cron.d /var/spool/cron 2>/dev/null
cat /etc/crontab 2>/dev/null

# 5) Audit admin access — restrict management interface to trusted admin subnets ONLY
#    (execute interactively; example shown — adapt interface and subnet to your environment)
# config system interface
#   edit port1
#     set allowaccess ping ssh snmp
#     unset allowaccess https http  # GUI/API off the untrusted side; manage via out-of-band/VPN
#   next
# end

# 6) List established sessions to spot unknown admin logins
execute log display 2>/dev/null | grep -iE 'login|admin' | tail -n 100

Remediation

  1. Apply vendor fixes immediately. Follow the Fortinet PSIRT advisory for CVE-2026-104286 and upgrade FortiMail to the fixed release for your train. Do not defer: this is a KEV-listed, actively exploited, pre-authentication flaw on an internet-facing appliance.
  2. Comply with BOD 26-04 and KEV directives. Federal civilian agencies must remediate within the BOD 26-04 / KEV-mandated timeline. Private-sector organizations should adopt the same deadline as an internal SLA — this is exactly the class of vulnerability those directives exist for.
  3. Forensic triage before patching. Per CISA's Forensics Triage Requirements referenced in the KEV entry: image or snapshot the appliance/VM, export and preserve all logs (HTTP, admin, system event, mail), and hunt for post-exploitation artifacts (webshells, rogue cron entries, new admin accounts, unexpected outbound connections) before the upgrade wipes volatile evidence. If you find indicators, treat it as a confirmed intrusion — rotate all credentials stored on the device (admin, LDAP bind, API keys, certificates) and scope for lateral movement.
  4. Reduce attack surface now. The management GUI/API should never be reachable from the internet or untrusted segments. Restrict allowaccess on interfaces, place administration behind a VPN/jump host, and apply ACLs limiting HTTPS access to the mail-processing functions that must be exposed.
  5. If no mitigation is available, discontinue use. CISA's required action is explicit: follow BOD 26-04 guidance for cloud services or take the product out of service if mitigations cannot be applied. For a device holding your entire inbound mail flow and directory credentials, an unpatched, exploited gateway is worse than a controlled outage.
  6. Add detections permanently. Deploy the Sigma/KQL content above against forwarded FortiMail logs, and alert on any administrative-interface authentication from non-admin subnets.

If you need help validating exposure, hunting across your Fortinet estate, or scoping a suspected compromise of your email gateway, our IR team runs these engagements regularly — the difference between a patched vulnerability and a breach disclosure is usually the first 48 hours of evidence collection.

Related Resources

Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.

CVE-2026-104286: Fortinet FortiMail Path Traversal Actively Exploited — Detection and Remediation Guide | Security Arsenal | Security Arsenal