If your Midtown professional firm, Staten Island healthcare affiliate, Brooklyn agency, or Queens warehouse runs Fortinet FortiMail for inbound/outbound filtering or Identity-Based Encryption (IBE), treat CVE-2026-104286 as a same-week priority — not a “we will catch the next maintenance window” item. On October 1, 2026, Fortinet published PSIRT advisory FG-IR-26-175 for a critical path-traversal / NULL-byte issue that can let an unauthenticated attacker write arbitrary files via crafted HTTP or HTTPS requests. The same day, CISA added the CVE to its Known Exploited Vulnerabilities (KEV) catalog with a federal remediation due date of October 4, 2026 and forensic triage required per BOD 26-04. Private NYC shops are not under Binding Operational Directive the same way federal agencies are, but a KEV listing plus Fortinet’s own “exploited in the wild” language should jump the queue ahead of cosmetic change tickets.
This post is a practical checklist for NYC SMBs and the MSPs who support FortiMail appliances and VMs. Named sources only: Fortinet FortiGuard PSIRT FG-IR-26-175 (published October 1, 2026; CVSS 9.8; Known Exploited: Yes); CISA’s “CISA Adds One Known Exploited Vulnerability to Catalog” alert (October 1, 2026); CISA’s KEV catalog entry for CVE-2026-104286 (dateAdded 2026-10-01; dueDate 2026-10-04; forensic triage: Yes); and SecurityAffairs’ secondary summary of the KEV addition. No invented percentages. No exploit recipes.
What Fortinet FortiMail CVE-2026-104286 actually is
Per Fortinet’s FG-IR-26-175 advisory, CVE-2026-104286 combines CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — path traversal) with CWE-158 (Improper Neutralization of NULL Byte or NULL Character). Impact language is blunt: an unauthenticated attacker may write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. Fortinet rates severity Critical, CVSSv3 9.8, attack type Unauthenticated, component GUI, and marks Known Exploited: Yes. The advisory states the issue has been reported exploited in the wild and urges customers to apply the workaround below while fixed builds ship.
CISA’s October 1 alert names the addition as CVE-2026-104286 Fortinet FortiMail Path Traversal Vulnerability and points readers to BOD 26-04 risk-based prioritization. The KEV catalog entry restates the path-traversal / NULL-byte description, lists due date 2026-10-04, known ransomware campaign use as Unknown, and forensic triage per BOD 26-04 as Yes. SecurityAffairs’ secondary write-up of the KEV addition restates the CVSS 9.8 score and the unauthenticated file-write impact. Treat Fortinet and CISA as primary; treat secondary press as confirmation, not a substitute for the vendor page.
What this is not: a claim that every FortiMail on the internet is already ransomed, or a walkthrough of how to craft the HTTP request. Fortinet’s language is operational — exploited in the wild, patch or workaround now — and CISA’s KEV designation means exploitation evidence met catalog criteria. The takeaway for an MSP ticket queue is still blunt: when an unauthenticated path can write files on a mail security appliance and the CVE is on KEV, you inventory, mitigate, and plan the upgrade before the federal outer bound becomes yesterday’s news.
Affected versions and workarounds (from Fortinet — not a substitute for the advisory)
Per FG-IR-26-175 (October 1, 2026):
- FortiMail 8.0 — 8.0.0 through 8.0.1 affected; upgrade to upcoming 8.0.2 or above.
- FortiMail 7.6 — 7.6.0 through 7.6.6 affected; upgrade to upcoming 7.6.7 or above.
- FortiMail 7.4 — 7.4.0 through 7.4.8 affected; upgrade to upcoming 7.4.9 or above.
- FortiMail 7.2 — 7.2.0 through 7.2.9 affected; upgrade to branch 7.4 or above.
Fixed builds are listed as “upcoming” on several trains in the initial publication. Until those packages are installed in your change window, Fortinet documents two temporary controls:
- Disable IBE feature support via the GUI (Encryption → IBE → IBE Service set to off) or the CLI sequence Fortinet publishes in FG-IR-26-175 (
config system encryption ibe/set status disable/end). - Alternatively: disable access to the FortiMail management interface from the internet, or limit management access to trusted private networks only.
Those are vendor-stated workarounds, not permanent architecture advice. If IBE is a production requirement for your legal or healthcare clients, you still need a named owner for the upgrade path — and you should assume internet-exposed management GUI is a separate debt item even after the CVE closes.
Why NYC SMBs with FortiMail should care this week
FortiMail shows up in New York professional services as the appliance or VM that sits in front of Microsoft 365 or on-prem Exchange: spam/malware filtering, DLP hooks, and IBE for regulated mail. It is not a “set and forget” toaster. It is an internet-facing or DMZ-adjacent mail security control plane. An unauthenticated arbitrary file write on that class of device is how quiet persistence starts — especially when the management GUI is reachable from the public internet “just for the vendor” or “just for the MSP.”
CISA’s BOD 26-04 framing in the October 1 KEV notice applies to Federal Civilian Executive Branch agencies. CISA still encourages all organizations to prioritize KEV remediation. The federal due date of October 4, 2026 is a useful outer bound for private-sector urgency: if agencies must remediate by Saturday, an exposed FortiMail in a Midtown or Staten Island stack should not still be “waiting for the next quarterly firmware night.”
Also separate this from last week’s Apple and Citrix KEV stories. Apple CVE-2026-86950 (CoreGraphics) and Citrix NetScaler CVE-2026-88771 / CVE-2026-88772 already had their own checklists. Different product class, different owners, different change windows. Do not let a Mac fleet push crowd out mail-security firmware — and do not let FortiMail become the excuse to ignore edge appliances or phones. Run the queues in parallel.
Indicators Fortinet published (high level — for your SIEM / EDR owners)
FG-IR-26-175 includes Indicators of Compromise: filesystem paths and hashes for added or modified binaries and config artifacts, two related IP addresses presented in the advisory’s IoC section, and example system / encryption log lines. We will not reproduce a hunting cookbook here. Your job is to hand the advisory URL to whoever owns FortiMail forensics and ask for a before/after statement: “Did we see these artifacts or log patterns before we applied the workaround?” KEV marks forensic triage per BOD 26-04 as Yes for the federal audience; private firms should still treat “exploited in the wild” as a reason to look before you assume a clean slate — without turning the week into malware theater.
NYC MSP / SMB checklist (inventory, mitigate, then upgrade)
- Inventory every FortiMail — physical appliances, VMs, and cloud/hosted instances that touch business mail. Record exact version strings (8.0.x / 7.6.x / 7.4.x / 7.2.x), HA peers, and whether management GUI or IBE is enabled.
- Map exposure — is HTTPS management reachable from the public internet, a vendor jump host, or only a private admin VLAN? Screenshot firewall rules before you change them.
- Apply Fortinet’s temporary control now — disable IBE per FG-IR-26-175 if you can live without it for a few days, or lock management access to trusted networks. Document which control you chose and who approved it.
- Schedule the fixed build — track Fortinet’s “upcoming” 8.0.2 / 7.6.7 / 7.4.9 (and 7.2 → 7.4+) packages; put a named change window on the calendar before October 4 if the build is available, or the next business day after it ships.
- Triage for compromise signals — compare Fortinet’s published IoCs and log examples against your SIEM / FortiMail event history. If something looks wrong, preserve evidence per your playbook before you wipe or rebuild.
- Close the ticket with evidence — version report, workaround claim, management-exposure screenshot, and upgrade completion — not a Slack message that “mail filtering is fine.”
Do not spend the week chasing PoCs from random repos. Fortinet and CISA already told you what matters: unauthenticated file write on FortiMail, workaround and upgrade path published, KEV due October 4 for federal systems, triage flag set for the directive audience.
What “good” looks like for an MSP-run New York mail-security stack
Good looks like a living inventory of FortiMail versions with owners and HA roles — not a sticky note from the last hardware refresh. Good looks like management interfaces that are not casually internet-exposed. Good looks like clients hearing a clear message: “Your FortiMail train is X.Y.Z; IBE is off (or management is locked down) until we land the fixed build; here is the compliance count as of this morning.” Vague reassurance (“Fortinet auto-updates”) is not the same as a completed change with version evidence.
If you are an internal IT lead without an MSP, the same checklist applies — assign a named owner for the workaround and a named owner for the firmware upgrade. User-initiated “we will check the GUI later” is fine for a household NAS. It is a weak control for a 40-person Brooklyn agency when CISA’s clock is measured in days.
For New York privacy and breach-notification context that does apply to many SMBs — a different conversation from BOD 26-04 — keep your SHIELD and incident playbooks nearby if triage turns into confirmed compromise. Do not confuse “federal due date” with “NYS lawsuit deadline.” Do confuse “KEV + Fortinet exploitation language” with “mitigate this week.”
Sources (named, primary)
- Fortinet FortiGuard Labs — PSIRT FG-IR-26-175 (published October 1, 2026): CVE-2026-104286; path traversal + NULL-byte neutralization; unauthenticated arbitrary file write via crafted HTTP/HTTPS; CVSSv3 9.8; Known Exploited Yes; affected FortiMail 8.0 / 7.6 / 7.4 / 7.2 ranges; IBE-disable and management-exposure workarounds; IoCs. https://fortiguard.fortinet.com/psirt/FG-IR-26-175
- CISA — “CISA Adds One Known Exploited Vulnerability to Catalog” (October 1, 2026): CVE-2026-104286 Fortinet FortiMail Path Traversal added to KEV; BOD 26-04 context. https://www.cisa.gov/news-events/alerts/2026/10/01/cisa-adds-one-known-exploited-vulnerability-catalog
- CISA — Known Exploited Vulnerabilities Catalog entry for CVE-2026-104286: dateAdded 2026-10-01; dueDate 2026-10-04; forensic triage Yes; CWE-22, CWE-158. https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- SecurityAffairs — secondary summary of the CISA KEV addition (CVSS 9.8; restates Fortinet impact and workaround guidance).
If your organization needs hands-on help inventorying FortiMail, locking down management exposure, applying Fortinet’s workaround, and clearing CVE-2026-104286 before the October 4 federal KEV outer bound becomes yesterday’s news, MicroSky Managed Services can help. Call (718) 672-2177 or visit https://microskyms.com.


