Edge mail gateways do not get to wait for a tidy patch train. On October 1, 2026, Fortinet published FG-IR-26-175 for CVE-2026-104286: an unauthenticated path traversal plus NULL-byte neutralization flaw (CWE-22 / CWE-158) in the FortiMail GUI that can let crafted HTTP or HTTPS requests write arbitrary files on the underlying system. Severity: Critical. CVSSv3: 9.8. Known exploited: Yes. The same day, CISA added the CVE to the Known Exploited Vulnerabilities catalog with a federal due date of October 4, 2026 and forensic-triage expectations under BOD 26-04.
What is actually fixed — and what is not. Fortinet’s advisory lists affected releases as FortiMail 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8, and 7.2.0–7.2.9. Solutions are framed as upgrades to upcoming 8.0.2, 7.6.7, and 7.4.9; 7.2 customers are told to move to the 7.4 branch or above. That wording matters. Until those builds ship, the operational answer is workaround plus hunt — not a calendar invite for “patch Tuesday.”
Compensate now. Fortinet’s published workarounds: disable Identity-Based Encryption (IBE) support via GUI (Encryption → IBE → IBE Service off) or CLI (config system encryption ibe / set status disable / end); alternatively, disable internet access to the FortiMail management interface or limit it to trusted private networks. For FCEB agencies, CISA’s KEV entry requires mitigations per vendor guidance, BOD 26-04 prioritization, and forensics triage — not a shrug until 8.0.2 appears in the download portal.
Hunt tip — treat the mailbox as a beachhead. Fortinet published IoCs: IPs 79.141.169.187 and 45.129.0.192; system logs showing cron activity around /migadmin; admin logout events from (null); and a config add for archive account archive234 pointing remote archival at 79.141.169.187 /uploads. Encryption logs may show IBE Base64 decode failures (Invalid Base64 Encoding… Character=0x2a) and failed internal-user logins. BleepingComputer also reprints Fortinet file hashes for added/modified paths such as /data/lib/liblog.so, /bin/smit, /data/bin/webconsole, and /data/etc/ld.so.preload. If those land, assume the gateway is not just “vulnerable” — assume it is exfiltrating.
POV — KEV without a fixed build is a compensation test. Boards that measure vuln management only by “mean time to patch” will fail this one. Edge email appliances sit on the same trust path as identity and DLP. Unauthenticated file write on the management plane is a path to code execution and silent archival. Victim count and actor attribution: Undisclosed (Fortinet has not published either). What is public is enough: ITW, KEV, three-day federal clock, workarounds that change encryption posture or management exposure. Do those first. Then forensics. Then the fixed build when Fortinet ships it — not before you pretend the risk is theoretical.
Desk sheet — sourced only: Fortinet FG-IR-26-175 (Oct 1, 2026) — CVE-2026-104286; CVSS 9.8; ITW; affected version ranges; upcoming fixed builds; IBE disable + mgmt lockdown workarounds; IoC IPs and log patterns. CISA KEV feed — dateAdded 2026-10-01; dueDate 2026-10-04; forensicTriage Yes; BOD 26-04 notes. BleepingComputer Oct 1, 2026 — file SHA-256 table and Fortinet statement on CISA coordination. Victim count / first-seen exploit date / actor: Undisclosed.
