Fortinet on Oct. 1 warned that a path traversal vulnerability in Fortinet FortiMail was being exploited in the wild and urged customers to patch right away.
In its advisory, Fortinet said the bug lets an unauthenticated attacker write arbitrary files onto the underlying system through crafted web requests.
The CVSS 9.8 bug — CVE-2026-104286 — was also added to the known exploited vulnerabilities (KEV) catalog yesterday by the Cybersecurity and Infrastructure Security Agency (CISA), which gave federal agencies until Oct. 4 to make the patch.
Security pros were concerned about this one because the Fortinet FortiMail management interface operates as the admin console for the appliance that filters an organization's email and decides what gets delivered, quarantined or blocked.
Roman Y. Sannikov, global research coordinator at iCounter, said the indicators of compromise Fortinet published show attackers are using it to dig into the enterprise.
Sannikov explained that the list includes changes to ld.so.preload, a Linux mechanism that loads a library into every process on the system, along with an added liblog.so file and a modified web server configuration. Sannikov said that combination points to attackers setting up persistent access, so they can stay on the device after the initial intrusion. This essentially gives threat actors control of part of an organization's security infrastructure, letting the attackers decide what’s allowed in, said Sannikov.
“That goes a long way toward giving them persistence on top of access,” said Sannikov. “They didn't just break into the factory, they are manning the guard house, controlling who or what gets to enter. An attacker who controls the email gateway can see the mail flowing through it, collect credentials and password reset links, and change the filtering so their own phishing gets through. Initial access brokers look for exactly this kind of foothold: a trusted device at the network edge that a ransomware affiliate or fraud crew can pick up later.”
Seemant Sehgal, chief executive officer at BreachLock, said an unauthenticated path traversal allowing arbitrary file writes gives an attacker effective control of the appliance, which means they can plant a web shell, route email through attacker-controlled infrastructure, intercept administrator credentials, and use the gateway as a foothold into the broader network.
“Exposed management interfaces on perimeter appliances are a frequent finding the team comes across in penetration testing engagements, which is why removing public access to the interface should be the immediate step, alongside applying the vendor's IBE workaround and hunting for the indicators of compromise in the advisory before trusting the device going forward,” said Sehgal.
John Bambenek, president at Bambenek Consulting, added that he's concerned about the likely ability of an attacker to redirect or blindcopy inbound email for BEC-style attacks.
“Almost every BEC case I’ve looked at involved mail forwarding rules and as long as mail flows to the user, no one ever looks there, so attackers can last months and years,” said Bambenek.