Fortinet published a critical advisory on October 1, 2026 for FortiMail, its email security gateway. According to advisory FG-IR-26-175, CVE-2026-104286 is a path traversal flaw (CWE-22) combined with a null byte handling flaw (CWE-158) that may let an unauthenticated attacker write arbitrary files on the underlying system through crafted HTTP or HTTPS requests. Fortinet rates it CVSS 9.8 and marks it as known exploited, saying it “has been reported to be exploited in the wild”.

The affected builds are FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8 and 7.2.0 through 7.2.9. The fixed releases are listed as upcoming: 8.0.2, 7.6.7 and 7.4.9, with the 7.2 branch told to move to 7.4 or above. Until then Fortinet’s workaround is to turn off the IBE service under Encryption, or to block internet access to the FortiMail management interface and allow it only from trusted private networks. The advisory also lists indicators of compromise, including added and modified files and two IP addresses, and credits Fortinet’s own Product Security team with the discovery.

Why it matters: with no patch to install yet, the workaround is the only control, and the advisory’s list of modified files means a device that was exposed before today may need checking, not just configuring. Mail gateways sit in the path of every inbound message, so a file-write flaw on one deserves the same urgency as the exploited Cisco SD-WAN Manager flaw we covered yesterday. Our read: the 7.2 branch is the awkward case, because its fix is a version-branch migration rather than a point release, and teams on it should schedule that work now. The argument in our opinion on replacing exploited edge appliances applies if the indicators match.

Source: Fortinet PSIRT, FG-IR-26-175: Improper limitation of a pathname to a restricted directory