On October 1, 2026, CISA added CVE-2026-104286 — a path traversal vulnerability in Fortinet FortiMail — to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation in the wild. This is not a theoretical risk. When CISA moves a CVE into the KEV, it means adversaries are already using it against real targets, and FortiMail appliances sit in one of the most sensitive positions in any network: directly internet-facing, processing every inbound email, and holding credentials, message content, and a trusted path into internal infrastructure.
Under Binding Operational Directive (BOD) 26-04, Federal Civilian Executive Branch (FCEB) agencies are legally required to prioritize rapid remediation of KEV-listed vulnerabilities. But the directive is simply codifying what practitioners already know: edge devices — and email security gateways in particular — have been the most consistently abused initial-access vector over the past several years. If you run FortiMail, treat this as an incident, not a patch ticket. Assume the appliance may already be compromised and hunt accordingly.
Technical Analysis
Affected Product
- Product: Fortinet FortiMail (email security gateway, physical and virtual appliances, including FortiMail Cloud-adjacent on-prem deployments)
- Vulnerability class: Path Traversal (CWE-22 — Improper Limitation of a Pathname to a Restricted Directory)
- CVE: CVE-2026-104286
- Attack surface: Network-reachable management and web-facing components of the appliance
FortiMail appliances expose an administrative web interface and API endpoints for gateway management, quarantine access, and end-user self-service. Path traversal vulnerabilities in this class of product typically allow an unauthenticated or low-privilege remote attacker to escape the intended web root by supplying crafted ../ sequences (or encoded variants such as %2e%2e%2f, ..%2f, or double-encoded %252e%252e%252f) in HTTP request paths or parameters, enabling arbitrary file read — and depending on the endpoint, arbitrary file write.
Why This Matters on FortiMail Specifically
From a defender's perspective, arbitrary file read on a FortiMail appliance is a catastrophic primitive even before code execution enters the picture. High-value files an attacker would target include:
- Configuration backups and running config — containing LDAP bind credentials, SMTP relay credentials, admin password hashes, and network topology
- Session files and API tokens — enabling authenticated access to the management plane
- Private keys and certificates — enabling TLS interception and impersonation of the gateway
- Queued and archived mail — the entire content of the organization's email flow
If the traversal extends to file write (a common escalation pattern on Fortinet appliances), attackers typically drop web shells into the web root or modify startup scripts to establish persistence that survives reboots and, in some documented Fortinet campaigns, even survives firmware upgrades. Fortinet edge devices have repeatedly been used by nation-state actors as long-dwell persistence and pivot points precisely because they are rarely EDR-instrumented and infrequently logged to a central SIEM.
Exploitation Status
- CISA KEV: Listed October 1, 2026 — confirmed active exploitation
- Remediation obligation: FCEB agencies must remediate under the BOD 26-04 timeline from the KEV listing date; private-sector organizations should treat the same deadline as their own SLA
- CISA's own characterization: Path traversal is explicitly called out as a frequent attack vector for malicious cyber actors posing significant risk to the federal enterprise
Because exploitation is confirmed, patching alone is insufficient. An attacker who exploited this flaw before you patched may already hold credentials, persistence, or harvested data. Remediation must be paired with compromise assessment.
Detection & Response
FortiMail supports remote syslog (including CEF format), which should already be flowing into your SIEM. If it isn't, fix that today — an unmonitored edge appliance is a blind spot attackers actively seek out. The detections below target both the exploitation attempt itself (traversal patterns in web requests) and post-exploitation behavior (file access anomalies, new admin account creation, unexpected outbound connections from the appliance).
Sigma Rules
---
title: Path Traversal Attempt Against FortiMail Web Interface
id: 3f8a1b42-7c9e-4d21-b6a5-9e0f2c4d8a71
status: experimental
description: Detects directory traversal sequences in HTTP requests directed at FortiMail administrative or web-facing endpoints, consistent with exploitation of CVE-2026-104286.
references:
- https://www.cisa.gov/news-events/alerts/2026/10/01/cisa-adds-one-known-exploited-vulnerability-catalog
- https://attack.mitre.org/techniques/T1190/
author: Security Arsenal
date: 2026/10/01
tags:
- attack.initial_access
- attack.t1190
logsource:
category: webserver
detection:
selection_uri:
cs-uri|contains:
- '../'
- '..%2f'
- '%2e%2e%2f'
- '%2e%2e/'
- '..\\'
- '%252e%252e'
- '..;'
selection_sensitive_target:
cs-uri|contains:
- '/etc/'
- 'passwd'
- 'shadow'
- '.conf'
- 'FortiMail'
condition: selection_uri and 1 of selection_sensitive_target
falsepositives:
- Vulnerability scanners and authorized penetration tests
level: high
---
title: Sensitive System File Accessed via Web Request on Edge Appliance
id: 8c2d5e19-4a7f-4b83-91c6-2e7d0f5a3b48
status: experimental
description: Detects web requests attempting to retrieve operating system files (passwd, shadow, configuration) — a strong indicator of successful or attempted path traversal exploitation such as CVE-2026-104286.
references:
- https://www.cisa.gov/news-events/alerts/2026/10/01/cisa-adds-one-known-exploited-vulnerability-catalog
- https://attack.mitre.org/techniques/T1003/
author: Security Arsenal
date: 2026/10/01
tags:
- attack.credential_access
- attack.t1003
logsource:
category: webserver
detection:
selection:
cs-uri|contains:
- '/etc/passwd'
- '/etc/shadow'
- '/etc/hosts'
- 'system_config'
- 'backup'
filter_status:
sc-status:
- 404
- 403
condition: selection and not filter_status
falsepositives:
- Security scanning tools
level: critical
---
title: Suspicious Outbound Connection from FortiMail Appliance
id: 5e1b9c07-2d48-4f6a-a3c2-7b4e8d0f91c5
status: experimental
description: Detects the FortiMail appliance initiating outbound connections to uncommon external destinations or non-standard ports, which may indicate post-exploitation C2 or data exfiltration following CVE-2026-104286 exploitation.
references:
- https://attack.mitre.org/techniques/T1071/
author: Security Arsenal
date: 2026/10/01
tags:
- attack.command_and_control
- attack.t1071
logsource:
category: firewall
detection:
selection:
src|contains: 'fortimail'
filter_expected_ports:
dst_port:
- 25
- 53
- 123
- 443
filter_expected_dests:
dst|contains:
- 'fortiguard'
- 'fortinet'
condition: selection and not filter_expected_ports and not filter_expected_dests
falsepositives:
- Newly integrated threat intelligence or sandbox services
- Legitimate firmware update infrastructure not yet allowlisted
level: medium
The first two rules assume you are logging the FortiMail web access layer — either via FortiMail's own HTTP event logs forwarded over syslog or via a reverse proxy/WAF in front of the management interface (which is itself a recommended architecture). The third rule addresses the reality that most FortiMail exploitation campaigns culminate in the appliance beaconing outward; egress filtering plus detection on unexpected egress is one of the highest-fidelity signals available for edge-device compromise.
KQL — Microsoft Sentinel (CEF/Syslog ingestion)
FortiMail ships logs via syslog and CEF, which land in CommonSecurityLog or Syslog in Sentinel. This query hunts for traversal payloads in request URLs and for the sensitive files attackers target post-exploitation:
// Hunt for CVE-2026-104286 path traversal attempts against FortiMail
let TraversalPatterns = dynamic(["../", "..%2f", "%2e%2e", "%252e", "..\\", "..;"]);
let SensitiveTargets = dynamic(["passwd", "shadow", "/etc/", ".conf", "system_config", "backup", "privatekey", ".pem"]);
union isfuzzy=true
(CommonSecurityLog
| where DeviceVendor =~ "Fortinet" and DeviceProduct has "FortiMail"
| extend Url = coalesce(RequestURL, AdditionalExtensions)
| where Url has_any (TraversalPatterns) and Url has_any (SensitiveTargets)
| project TimeGenerated, SourceIP, DestinationIP, Url, RequestMethod, RequestContext, DeviceAction),
(Syslog
| where Computer has "fortimail" or SyslogMessage has "FortiMail"
| where SyslogMessage has_any (TraversalPatterns) and SyslogMessage has_any (SensitiveTargets)
| project TimeGenerated, Computer, HostIP, ProcessName, SyslogMessage)
| sort by TimeGenerated desc
Follow-up hunt: baseline your FortiMail appliance's outbound connections over the trailing 30 days and alert on first-seen destinations. An appliance that suddenly initiates SSH, raw TCP on odd ports, or HTTPS to non-Fortinet infrastructure is a strong compromise indicator. Also hunt for administrative account creation events in FortiMail event logs (SyslogMessage has "admin" and SyslogMessage has "added") — post-exploitation persistence via rogue admin accounts is a well-documented Fortinet tradecraft pattern.
Velociraptor VQL — Post-Exploitation Endpoint Hunt
Velociraptor won't run on the FortiMail appliance itself, but if the gateway was compromised, assume harvested credentials (LDAP binds, SMTP creds, admin hashes) were used downstream. This artifact hunts Windows endpoints for evidence of access originating from the FortiMail host and for recently created webshell-like artifacts on internal web servers the attacker may have pivoted to:
-- Hunt for lateral movement artifacts: logons sourced from the FortiMail appliance
-- Replace the IP with your FortiMail appliance address
LET FortiMailIP = '10.0.0.25'
SELECT EventData.TargetUserName AS Account,
EventData.IpAddress AS SourceIP,
EventData.WorkstationName AS SourceHost,
EventData.LogonType AS LogonType,
Timestamp AS LogonTime,
Computer
FROM Artifact.Windows.EventLogs.Evtx()
WHERE EventID = 4624
AND EventData.IpAddress =~ FortiMailIP
ORDER BY LogonTime DESC
-- Hunt internal web servers for recently dropped script/webshell files
SELECT FullPath, Size, Mtime, Ctime
FROM glob(globs=['C:/inetpub/**/*.aspx', 'C:/inetpub/**/*.ashx', '/var/www/**/*.php', '/opt/**/webapps/**/*.jsp'])
WHERE Mtime > now() - 2592000
ORDER BY Mtime DESC
Any interactive logon (LogonType 2, 3, or 10) sourced from the FortiMail appliance IP to a Windows endpoint is essentially never legitimate — the gateway has no business authenticating to workstations or member servers, and hits here should be treated as confirmed lateral movement.
Verification & Hardening Script
Use this Bash script against the FortiMail CLI (via SSH) and its log storage to verify firmware version, enumerate admin accounts for anomalies, and grep local logs for traversal evidence. Run it before patching (to preserve evidence) and again after:
#!/bin/bash
# CVE-2026-104286 FortiMail compromise assessment helper
# Usage: ./fortimail_triage.sh <fortimail_host> <admin_user>
HOST=$1
USER=$2
OUT="fortimail_triage_$(date +%Y%m%d_%H%M%S)"
mkdir -p "$OUT"
# Pull system status and firmware version — compare against the Fortinet advisory's fixed builds
ssh "${USER}@${HOST}" "get system status" > "$OUT/system_status.txt"
# Enumerate all admin accounts — flag any you do not recognize
ssh "${USER}@${HOST}" "show system admin" > "$OUT/admin_accounts.txt"
# Review recent admin login history for unexpected source IPs
ssh "${USER}@${HOST}" "diagnose log flash filter" > "$OUT/log_filter.txt" 2>/dev/null
ssh "${USER}@${HOST}" "execute log display" > "$OUT/event_logs.txt" 2>/dev/null
# Search exported HTTP/event logs for traversal payloads
grep -Ei '\.\./|\.\.%2f|%2e%2e|%252e|\.\.;' "$OUT/event_logs.txt" > "$OUT/traversal_hits.txt"
echo "[+] Traversal indicators found: $(wc -l < "$OUT/traversal_hits.txt")"
# Flag sensitive-file access attempts
grep -Ei '/etc/(passwd|shadow)|\.pem|system_config|privatekey' "$OUT/event_logs.txt" > "$OUT/sensitive_file_hits.txt"
echo "[+] Sensitive file access indicators: $(wc -l < "$OUT/sensitive_file_hits.txt")"
# Check for unexpected established outbound connections from the appliance
ssh "${USER}@${HOST}" "diagnose sys session list" > "$OUT/sessions.txt" 2>/dev/null
echo "[+] Review $OUT/sessions.txt for outbound sessions to non-Fortinet destinations"
Remediation
- Patch immediately. Apply the Fortinet firmware release that remediates CVE-2026-104286 per the official Fortinet PSIRT advisory at https://www.fortiguard.com/psirt. Do not assume your current build is unaffected — verify your exact firmware train against the advisory's fixed-version table. CISA's BOD 26-04 mandates remediation on the KEV timeline for FCEB agencies; treat that same date as your internal deadline regardless of sector.
- Assume breach before patching. Exploitation predates the KEV listing. Capture the triage evidence above before upgrading firmware, as upgrades can destroy forensic artifacts. If you find rogue admin accounts, unexpected sessions, or traversal hits with 200 responses, escalate to full IR — credential rotation and config review become mandatory.
- Rotate everything the appliance touches. LDAP bind accounts, SMTP relay credentials, admin passwords, RADIUS/TACACS+ shared secrets, and any certificates/private keys stored on the appliance. Harvested Fortinet credentials have repeatedly been used for follow-on intrusion months after initial access.
- Remove the management interface from the internet. The admin GUI should never be WAN-reachable. Restrict it to a dedicated management VLAN or jump host with MFA-backed access, and put the appliance behind a reverse proxy/WAF that logs full request URIs if any web-facing component must remain exposed.
- Fix telemetry gaps. Forward all FortiMail logs (event, HTTP, session, antispam/antivirus where relevant) to your SIEM via syslog/CEF today. Deploy egress filtering so the appliance can only reach Fortinet update/FDN infrastructure, DNS, NTP, and your SMTP next-hops — then alert on deviations.
- Validate with an adversarial test. After patching, have your pen-testing team (or ours) attempt the traversal against your build to confirm remediation, and run a purple-team replay of the detections above to verify your SOC actually sees the attack.
Path traversal is one of the oldest vulnerability classes in the book, and CISA's alert language underscores why it keeps working: edge appliances ship with web roots full of sensitive files, minimal endpoint telemetry, and patch cycles measured in quarters rather than days. The organizations that fare best against KEV additions like CVE-2026-104286 are the ones that treat their email gateway as tier-zero infrastructure — monitored, egress-restricted, and patched within hours, not weeks.
Related Resources
Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.