FortiMail sits on the inbound path for a lot of enterprise and government mail. Unauthenticated arbitrary write on that appliance is not a “patch next sprint” ticket — especially when the vendor already says it is being exploited and the fixed trains are still listed as upcoming.
Primary: Fortinet FortiGuard PSIRT FG-IR-26-175, published October 1, 2026. Summary: Improper Limitation of a Pathname to a Restricted Directory (CWE-22) plus Improper Neutralization of NULL Byte / NULL Character (CWE-158) may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. Component: GUI. Severity: Critical. Attack type: Unauthenticated. Impact framing on the advisory: execute unauthorized code or commands. CVSS v3 score: 9.8. CVE: CVE-2026-104286. Discovery credit: internally discovered and reported by Gwendal Guégniaud of Fortinet Product Security.
Exploitation — vendor language. Fortinet: “This has been reported to be exploited in the wild, customers are urged to apply the workaround below.” Known Exploited field on the advisory: Yes. The advisory does not publish a victim count, campaign start date, or actor attribution; those remain Undisclosed. CISA KEV — added today. Live KEV JSON catalogVersion 2026.10.01, dateReleased 2026-10-01T19:54:04.9308Z (~12:54 PM PT), dateAdded 2026-10-01, product FortiMail, short description matches Fortinet’s unauth arbitrary-file-write story. Due date 2026-10-04. Forensic triage: Yes. Known ransomware campaign use: Unknown. Required action points at vendor instructions + BOD 26-04. CISA notes link FG-IR-26-175 as the vendor primary. The dated CISA news-events alert URL for Oct 1 returned 404 at desk check — use the live KEV JSON + catalog page.
Affected trains and “upcoming” fixes (Fortinet table): FortiMail 8.0 8.0.0–8.0.1 → upgrade to upcoming 8.0.2+; 7.6 7.6.0–7.6.6 → upcoming 7.6.7+; 7.4 7.4.0–7.4.8 → upcoming 7.4.9+; 7.2 7.2.0–7.2.9 → move to branch 7.4 or above. Until those builds land, the advisory’s workaround is the operational control: disable IBE feature support with config system encryption ibe / set status disable / end, or disable / tightly limit internet access to the FortiMail management interface to trusted private networks only.
Hunt with vendor IoCs before you overwrite evidence. Fortinet lists file indicators (added/modified paths under /data/ and /bin/smit, including hashes for liblog.so, webconsole, mailservice, httpd.conf, ld.so.preload, migadmin.tar.gz), C2-style IPs 79.141.169.187 and 45.129.0.192, and log patterns around cron//migadmin, unexpected admin logout, archive-account remote destinations pointing at those IPs, IBE DecrypterMediaIn Base64 exceptions, and failed internal-user logins. Treat those as Fortinet’s published hunt sheet — preserve images/logs before rebuilds. Do not assume a later upgrade alone cleans a confirmed compromise.
POV for the SOC this afternoon: Edge mail appliance, unauth write, ITW confirmed by the vendor, federal clock to Oct 4, and patches still in the “upcoming” column. Priority order: internet-reachable FortiMail management / IBE surfaces first; apply the IBE disable or management-plane lockdown; pull forensics against Fortinet’s file/IP/log IoCs; schedule the fixed train the hour it ships. Victim numbers remain Undisclosed. Primary: Fortinet FG-IR-26-175 + CISA KEV JSON 2026.10.01.
Desk sheet — Fortinet FG-IR-26-175 Oct 1, 2026: CVE-2026-104286; CVSS 9.8; unauth path traversal + NULL-byte → arbitrary file write via HTTP/HTTPS; GUI component; Known Exploited Yes; workaround disable IBE or lock down mgmt interface; fixed trains upcoming 8.0.2 / 7.6.7 / 7.4.9 / migrate 7.2→7.4+; IoCs files under /data and /bin/smit + IPs 79.141.169.187 / 45.129.0.192. CISA KEV catalog 2026.10.01 dateReleased 2026-10-01T19:54:04Z — dateAdded 2026-10-01; due 2026-10-04; forensic Yes; ransomware Unknown. Victims / actor: Undisclosed.
