DKDKCISSPSearch
Vulnerabilities

Fortinet FortiMail bug exploited in the wild, added to CISA KEV list

Fortinet on Oct. 1 warned that a path traversal vulnerability in Fortinet FortiMail was being exploited in the wild and urged customers to patch right away.

DKCISSP News DeskSC Media3 Oct 2026, 12:20 am
Fortinet FortiMail bug exploited in the wild, added to CISA KEV list
Image courtesy of SC Media. Original report
DKCISSP REPORT

The CVSS 9.8 bug — CVE-2026-104286 — was also added to the known exploited vulnerabilities (KEV) catalog yesterday by the Cybersecurity and Infrastructure Security Agency (CISA), which gave federal agencies until Oct.

1 warned that a path traversal vulnerability in Fortinet FortiMail was being exploited in the wild and urged customers to patch right away.

In its advisory, Fortinet said the bug lets an unauthenticated attacker write arbitrary files onto the underlying system through crafted web requests.

Security pros were concerned about this one because the Fortinet FortiMail management interface operates as the admin console for the appliance that filters an organization's email and decides what gets delivered, quarantined or blocked.

An attacker who controls the email gateway can see the mail flowing through it, collect credentials and password reset links, and change the filtering so their own phishing gets through.

Initial access brokers look for exactly this kind of foothold: a trusted device at the network edge that a ransomware affiliate or fraud crew can pick up later.” Seemant Sehgal, chief executive officer at BreachLock, said an unauthenticated path traversal allowing arbitrary file writes gives an attacker effective control of the appliance, which means they can plant a web shell, route email through attacker-controlled infrastructure, intercept administrator credentials, and use the gateway as a foothold into the broader network.

Sannikov explained that the list includes changes to ld.so.preload, a Linux mechanism that loads a library into every process on the system, along with an added liblog.so file and a modified web server configuration.

Sannikov, global research coordinator at iCounter, said the indicators of compromise Fortinet published show attackers are using it to dig into the enterprise.

Sannikov said that combination points to attackers setting up persistent access, so they can stay on the device after the initial intrusion.

This essentially gives threat actors control of part of an organization's security infrastructure, letting the attackers decide what’s allowed in, said Sannikov.

What happened

The CVSS 9.8 bug — CVE-2026-104286 — was also added to the known exploited vulnerabilities (KEV) catalog yesterday by the Cybersecurity and Infrastructure Security Agency (CISA), which gave federal agencies until Oct.

1 warned that a path traversal vulnerability in Fortinet FortiMail was being exploited in the wild and urged customers to patch right away.

Who is affected

In its advisory, Fortinet said the bug lets an unauthenticated attacker write arbitrary files onto the underlying system through crafted web requests.

Security pros were concerned about this one because the Fortinet FortiMail management interface operates as the admin console for the appliance that filters an organization's email and decides what gets delivered, quarantined or blocked.

Why it matters

An attacker who controls the email gateway can see the mail flowing through it, collect credentials and password reset links, and change the filtering so their own phishing gets through.

Initial access brokers look for exactly this kind of foothold: a trusted device at the network edge that a ransomware affiliate or fraud crew can pick up later.” Seemant Sehgal, chief executive officer at BreachLock, said an unauthenticated path traversal allowing arbitrary file writes gives an attacker effective control of the appliance, which means they can plant a web shell, route email through attacker-controlled infrastructure, intercept administrator credentials, and use the gateway as a foothold into the broader network.

Technical details

Sannikov explained that the list includes changes to ld.so.preload, a Linux mechanism that loads a library into every process on the system, along with an added liblog.so file and a modified web server configuration.

Attribution

SC Media: 1 warned that a path traversal vulnerability in Fortinet FortiMail was being exploited in the wild and urged customers to patch right away.

What to watch next

Watch for new exploitation reports and updated indicators of compromise.

Watch for updated vendor guidance and fixed-version details.

MORE IN VULNERABILITIES

More cybersecurity reporting

Out-of-band Exchange Server update fixes high-severity mailbox access bug (CVE-2026-96940) - Help Net SecurityHelp Net Security · 5 Oct 2026, 4:08 pmAttackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCEThe Hacker News · 5 Oct 2026, 1:39 pmAttackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOTThe Hacker News · 5 Oct 2026, 1:00 pmCVE-2023-36025 (SmartScreen Bypass) Vulnerability: Analysis & Detection | HuntressHuntress · 4 Oct 2026, 5:30 am