Skip to finding
§
High
Edge
Provisional
CVE-2026-104286

Attackers are exploiting an unauthenticated FortiMail path before the effective fix ships.

The public management interface yields arbitrary file write and command execution.

Affects

Fortinet FortiMail, a physical, virtual or cloud-deployed secure email gateway appliance.

What it enables

Unauthenticated arbitrary file write and command execution on a FortiMail appliance

An unauthenticated attacker reaches an affected FortiMail HTTP or HTTPS GUI.→↓A crafted request exploits path traversal and NULL-byte handling to escape the intended directory.→↓The attacker writes a file to the underlying appliance filesystem.→↓The written file is used to execute unauthorized commands in the FortiMail system context.
Why this matters

Observed exploitation and the absence of a shipped effective fix turn exposed management interfaces into an immediate containment problem.

Detail and 4 sources
Required access

Network reachability to the affected FortiMail HTTP or HTTPS GUI

Affected versions

FortiMail 8.0.0–8.0.1, FortiMail 7.6.0–7.6.6, FortiMail 7.4.0–7.4.8, FortiMail 7.2.0–7.2.9

An unauthenticated caller can reach the path through an affected FortiMail HTTP or HTTPS management interface.

Path traversal and NULL-byte handling let that caller write attacker-chosen files to the appliance filesystem.

The written file can then be used to execute unauthorized commands in the FortiMail system context.

Exploitation is occurring while the effective correction remains announced rather than shipped, and pre-fix images remain accepted.

Evidence
Fortinet's exploitation statement, primitive and workaround are independently relayed by Canadian, French and Italian government security authorities.The live Fortinet advisory was directly readable.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, October 3, 2026