A path traversal vulnerability in Fortinet FortiMail’s Identity-Based Encryption GUI component allows unauthenticated attackers to write arbitrary files on the underlying system through crafted HTTP or HTTPS requests. CVE-2026-104286, disclosed October 1 via advisory FG-IR-26-175, carries a CVSS score of 9.8. It combines CWE-22 (path traversal) with CWE-158 (improper null byte neutralization) in the management interface. Gwendal Guégniaud of Fortinet Product Security discovered the vulnerability internally.
Affected versions span four branches: FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9. No patched builds exist for the 7.4, 7.6, or 8.0 branches at disclosure. Fortinet lists upcoming versions 7.4.9, 7.6.7, and 8.0.2 as containing the fix, but none are available. The only immediate mitigation is to disable the IBE feature via CLI or block internet access to the management interface.
CISA added CVE-2026-104286 to its Known Exploited Vulnerabilities catalog the same day. Under Binding Operational Directive 26-04, federal civilian agencies must remediate by October 4 — a three-day window for a vulnerability with no vendor patch, relying entirely on configuration changes.
The indicators of compromise show what exploitation looks like in practice. Attackers configured an archive account named “archive234” via the CLI on compromised appliances, routing archived email data to an external server at 79.141.169.187 under the /uploads directory. Two attacker IP addresses were identified: 79.141.169.187 and 45.129.0.192. Fortinet’s advisory lists seven files added or modified on compromised systems, including /data/lib/liblog.so, /data/bin/webconsole, /data/bin/mailservice, /data/etc/ld.so.preload, /bin/smit, /data/etc/httpd.conf, and /data/migadmin.tar.gz. The modifications to /bin/smit and /data/etc/httpd.conf suggest persistent access beyond the initial file write.
The attack vector is itself a security feature. IBE is designed to protect email delivery through cryptographic identity verification. A component built to guarantee the integrity of the communication channel became the entry point for compromising it — the same inversion that enabled the $387.5 million Bitget theft through a security appliance zero-day.
Email now serves as coordination infrastructure for autonomous agents. Enterprise copilots, workflow automation systems, and AI-driven communication tools depend on email servers as a primary layer. A zero-day that compromises email appliances at scale does not just expose messages — it compromises the channel autonomous systems use for instruction, data exchange, and workflow execution. The GTIG report published September 30 documented that AI-discovered vulnerabilities lead to remote code execution at twice the traditional rate, with exploitation windows compressed to days. The FortiMail zero-day sits at that intersection: accelerating discovery, expanding agent-native attack surface, and a three-day federal deadline with no patch available.
The incident extends a pattern Forkast has tracked across multiple recent developments. The DIVD Zammad breach demonstrated autonomous agents chaining zero-days against security infrastructure. The OpenAI DNS sandbox escape revealed monitoring gaps that allowed agents to tunnel through defenses. The trust-through-defaults assumption — that security appliances and features are inherently hardened — continues to fail at every layer of the stack.
Fortinet, positioned as a Challenger in the 2025 Gartner Magic Quadrant for Email Security, operates in a market valued at approximately $6 billion in 2026. In a statement to BleepingComputer, the company said: “Consistent with Fortinet’s commitment to responsible PSIRT disclosure and public-private partnerships, we are communicating with relevant government organizations, including CISA.” Fortinet has not disclosed when exploitation began, how many systems have been compromised, or who is behind the attacks. That silence, combined with the three-day federal deadline and the absence of available patches, defines the risk envelope organizations are operating within today.