Fortinet FortiMail Path Traversal Exploitation (CVE-2026-104286)
Detects exploitation attempts against CVE-2026-104286, a path traversal vulnerability (CWE-22 / CWE-158) in Fortinet FortiMail that is actively exploited in the wild (CISA KEV). Attackers leverage directory traversal sequences and improper handling of null/escape characters in HTTP requests to the FortiMail administrative and webmail interfaces to read arbitrary files, access configuration, or achieve code execution. This detection identifies traversal payloads (../, encoded variants, null-byte truncation) in requests to FortiMail management endpoints, anomalous file access, and post-exploitation indicators.
Vulnerability Intelligence
KEV — Known ExploitedAffected Software
- Vendor
- Fortinet
- Product
- FortiMail
Timeline
- Disclosed
- October 1, 2026
References & Proof of Concept
- https://fortiguard.fortinet.com/psirt/FG-IR-26-175
- https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk
- https://nvd.nist.gov/vuln/detail/CVE-2026-104286
- https://www.bleepingcomputer.com/news/security/fortinet-warns-of-critical-fortimail-flaw-exploited-in-zero-day-attacks/
CVSS
What is CVE-2026-104286 Fortinet FortiMail Path Traversal Exploitation (CVE-2026-104286)?
Fortinet FortiMail Path Traversal Exploitation (CVE-2026-104286) (CVE-2026-104286) maps to the Initial Access and Collection and Defense Evasion tactics — the adversary is trying to get into your network in MITRE ATT&CK.
This page provides production-ready detection logic for Fortinet FortiMail Path Traversal Exploitation (CVE-2026-104286), covering the data sources and telemetry it touches: Fortinet CommonSecurityLog, Web Proxy, Firewall. The queries below are rated critical severity at medium confidence, and ship for 7 SIEM platforms — KQL, SPL, Elastic, QRadar, Sumo, YARA-L, LogScale.
MITRE ATT&CK
let traversalPatterns = dynamic(["../","..%2f","..%5c","%2e%2e%2f","%252e%252e","..\\","%00","%2500","....//"]);
CommonSecurityLog
| where DeviceVendor == "Fortinet" and DeviceProduct has "FortiMail"
| where RequestURL has_any (traversalPatterns) or AdditionalExtensions has_any (traversalPatterns)
| where RequestURL has_any ("/admin", "/api", "/webmail", "/cgi-bin", "/download")
| extend TraversalHit = tostring(RequestURL)
| project TimeGenerated, SourceIP, DestinationIP, DeviceName, RequestURL, RequestMethod, Activity, DeviceAction
| summarize Attempts = count(), URLs = make_set(RequestURL, 20), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated) by SourceIP, DestinationIP, DeviceName
| where Attempts >= 1
| order by Attempts desc Flags HTTP requests to FortiMail management/webmail/API endpoints containing path-traversal or null-byte sequences in CommonSecurityLog firewall/proxy telemetry.
Data Sources
Required Tables
False Positives
- Authorized vulnerability scanners (Nessus, Qualys, Rapid7) probing the appliance
- Security penetration testing engagements against FortiMail
- Legitimate webmail attachment downloads whose URLs coincidentally contain encoded sequences
Sigma rule & cross-platform mapping
The detection logic for Fortinet FortiMail Path Traversal Exploitation (CVE-2026-104286) (CVE-2026-104286) above is provided in a vendor-neutral
form so you can deploy it on any SIEM. The same logic is shipped here as native
KQL (Microsoft Sentinel / Defender), SPL (Splunk), Elastic (Elastic Security (EQL)), QRadar (IBM QRadar (AQL)), Sumo (Sumo Logic CSE), YARA-L (Google Chronicle / SecOps), LogScale (CrowdStrike LogScale (CQL)) queries. In Sigma terms, this detection targets the
following logsource:
logsource:
category: network_connection
product: windows Browse the community-maintained Sigma rules for this technique:
Platform-specific guides for CVE-2026-104286
References (5)
- https://fortiguard.fortinet.com/psirt/FG-IR-26-175
- https://nvd.nist.gov/vuln/detail/CVE-2026-104286
- https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk
- https://www.bleepingcomputer.com/news/security/fortinet-warns-of-critical-fortimail-flaw-exploited-in-zero-day-attacks/
Testing Methodology
Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.
- Test 1Basic path traversal against FortiMail download endpoint
Expected signal: FortiMail HTTP access log entry with RequestURL containing '../../../../etc/passwd' to /download.
- Test 2URL-encoded traversal against admin API
Expected signal: FortiMail/web proxy log with encoded %2e%2e%2f sequence against /api path.
- Test 3Null-byte truncation traversal (CWE-158)
Expected signal: Web/proxy log capturing %00 null-byte plus traversal sequence to /webmail.
Response Playbook
Triage
- Confirm the targeted appliance is FortiMail and identify its firmware version against FG-IR-26-175 to determine exploitability.
- Extract the full request URL(s) and decode traversal/null-byte sequences to determine which file paths the attacker attempted to access (e.g. /etc/passwd, FortiMail config, session files).
- Determine whether the request received a 200/successful response versus being blocked (4xx) to distinguish successful reads from blocked attempts.
- Check the source IP reputation and cross-reference against CISA KEV / threat-intel feeds for known CVE-2026-104286 exploitation infrastructure.
Containment
- Block the attacker source IP(s) at the perimeter firewall and on the FortiMail trusted-host/admin access list.
- Restrict FortiMail administrative and API interface exposure to management networks only; remove any internet-facing exposure of the admin GUI.
- Apply the Fortinet FG-IR-26-175 patched firmware or vendor-provided workaround immediately given active KEV exploitation.
Evidence Collection
- Export FortiMail HTTP/admin access logs, system event logs, and any available full packet captures covering the attack window.
- Capture the current FortiMail configuration backup and hashes of system binaries to detect tampering or implanted webshells.
Escalation Criteria
- ! Escalate to incident response if any traversal request returned a successful (2xx) response indicating confirmed file disclosure.
- ! Escalate immediately if post-exploitation indicators are present (new admin accounts, config changes, outbound C2, modified system files).
Investigation Guide
Forensic Artifacts
- >
FortiMail HTTP/admin access logs showing traversal request URLs and response codes - >
FortiMail configuration backup diffs and system event logs - >
Network flow / PCAP records of connections from the source IP to the appliance management port
Tuning Guidance
Baseline and allowlist authorized vulnerability scanners and penetration-testing source IPs. Tighten the path filter to the specific vulnerable FortiMail endpoints identified in FG-IR-26-175 once published to reduce benign webmail download noise. Where available, correlate with HTTP response codes and only alert on 2xx responses to confirmed traversal to cut false positives, while keeping a lower-severity rule for blocked attempts.
Hunting Queries
Surfaces source IPs issuing repeated traversal/null-byte requests against FortiMail over time to spot scanning and exploitation bursts.
CommonSecurityLog | where DeviceVendor == "Fortinet" and DeviceProduct has "FortiMail" | where RequestURL has_any ("%00","../","..%2f","....//") | summarize count() by SourceIP, bin(TimeGenerated, 1h) index=fortinet sourcetype="fortinet:fortimail" (uri="*../*" OR uri="*%00*" OR uri="*....//*") | stats count by src_ip, uri Atomic Red Team Tests
Simulates a directory traversal attempt to read /etc/passwd via the FortiMail web interface in a lab.
Command
curl -ks "https://fortimail.lab.local/download?file=../../../../etc/passwd" -o /tmp/cve_2026_104286_test.out Cleanup
rm -f /tmp/cve_2026_104286_test.out Expected Telemetry
FortiMail HTTP access log entry with RequestURL containing '../../../../etc/passwd' to /download.
Expected Detection
Detection fires on the '../' traversal sequence targeting the /download path.
Sends a URL-encoded traversal payload to the FortiMail admin API endpoint.
Command
curl -ks "https://fortimail.lab.local/api/v1/file?path=%2e%2e%2f%2e%2e%2f%2e%2e%2fconfig" -o /dev/null Cleanup
echo 'no cleanup required' Expected Telemetry
FortiMail/web proxy log with encoded %2e%2e%2f sequence against /api path.
Expected Detection
Detection matches the %2e%2e%2f encoded traversal pattern on the /api endpoint.
Tests null-byte injection combined with traversal against the webmail endpoint.
Command
powershell -Command "Invoke-WebRequest -Uri 'https://fortimail.lab.local/webmail?attach=..%2f..%2fetc%2fpasswd%00.png' -SkipCertificateCheck -OutFile $env:TEMP\cve104286.out" Cleanup
powershell -Command "Remove-Item $env:TEMP\cve104286.out -ErrorAction SilentlyContinue" Expected Telemetry
Web/proxy log capturing %00 null-byte plus traversal sequence to /webmail.
Expected Detection
Detection fires on the %00 null-byte and traversal pattern on the /webmail path.