Critical FortiMail Zero‑Day (CVE‑2026‑104286) Enables Remote File Write via Path Traversal
What It Is — Fortinet disclosed a critical path‑traversal and null‑byte injection flaw (CVE‑2026‑104286) in FortiMail email security gateways that allows unauthenticated attackers to write arbitrary files to the underlying system.
Exploitability — The vulnerability is actively exploited in the wild; it is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. CVSS v3 score 9.8 (Critical).
Affected Products — FortiMail 8.0.0‑8.0.1, 7.6.0‑7.6.6, 7.4.0‑7.4.8, and 7.2.0‑7.2.9. Patches are slated for 8.0.2, 7.6.7, and 7.4.9.
Why It Matters for Trust & Control Assurance
- Demonstrates the need for continuous vulnerability monitoring and rapid patch‑management evidence to satisfy audit requirements.
- Highlights the importance of configuration‑control evidence (e.g., disabling unused features, network‑segmenting management interfaces) as part of a defensible control‑assurance posture.
- Provides a concrete test of the “Vulnerability Management” control objective that maps to multiple frameworks (NIST CSF 2.0, ISO 27001, etc.), showing whether an organization can prove timely remediation.
Recommended Actions
- Apply the FortiMail workaround: disable IBE (
config system encryption ibe; set status disable; end) or isolate the management UI on a trusted network. - Prioritize upgrade to FortiMail 7.4 or later; schedule immediate patching once FortiOS 8.0.2, 7.6.7, or 7.4.9 are released.
- Ingest Fortinet’s shared IOCs (IP addresses, log signatures) into your SIEM and verify no compromise.
- Document the remediation steps and evidence in your control‑mapping repository to demonstrate compliance readiness.
Source: Help Net Security – FortiMail Zero‑Day Exploited in the Wild (CVE‑2026‑104286)