Fortinet FortiOS and FortiProxy Vulnerable to Critical Path Traversal Exploit
Fortinet has issued a critical advisory for a path traversal vulnerability in FortiOS and FortiProxy, actively exploited in the wild, allowing unauthenticated attackers to write arbitrary files.

Fortinet has disclosed a critical vulnerability, designated CVE-2026-31803, affecting its FortiOS and FortiProxy products. This flaw, characterized by an "Improper limitation of a pathname to a restricted directory" (CWE-22) and "Improper Neutralization of NULL Byte or NULL Character" (CWE-158), carries a severe CVSS score of 9.8. The vulnerability allows unauthenticated attackers to write arbitrary files to the system by crafting specific HTTP or HTTPS requests.
The exploit mechanism leverages the path traversal weakness to navigate the file system and the NULL byte neutralization issue to bypass security checks, enabling the attacker to place malicious files anywhere on the affected system. This could lead to a complete system compromise, including the installation of backdoors, modification of critical system files, or data exfiltration.
Fortinet has confirmed that this vulnerability is actively being exploited in the wild, highlighting the immediate risk to organizations using vulnerable versions of FortiOS and FortiProxy. While specific threat actors are not named, the active exploitation suggests that attackers are actively seeking out and compromising susceptible devices.
The advisory lists specific affected versions for FortiMail, including 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9. Fortinet recommends upgrading to upcoming versions such as 8.0.2, 7.6.7, or 7.4.9 for the respective product lines. For FortiMail 7.2, users are advised to upgrade to branch 7.4 or above.
As a workaround, Fortinet suggests disabling the IBE (Integrated Business Email) feature support via the CLI command config system encryption ibe set status disable. Alternatively, administrators can restrict access to the FortiMail management interface from the internet or limit it to trusted private networks. These measures aim to mitigate the risk until patches can be applied.
Indicators of Compromise (IoCs) provided include modified and added files such as /data/lib/liblog.so, /bin/smit, /data/bin/webconsole, /data/bin/mailservice, /data/etc/httpd.conf, /data/etc/ld.so.preload, and /data/migadmin.tar.gz, along with associated MD5 and SHA256 hashes. Several IP addresses, including 79[.]141.169.187 and 45[.]129.0.192, are also listed as potentially malicious.
This vulnerability underscores the persistent threat posed by path traversal flaws, especially when combined with other weaknesses like improper NULL byte handling. Organizations are strongly urged to review their Fortinet deployments, apply the recommended workarounds immediately, and plan for timely upgrades to secure their systems against active exploitation.
CISA has now added CVE-2026-104286, a path traversal vulnerability specifically affecting Fortinet FortiMail, to its Known Exploited Vulnerabilities (KEV) Catalog. This new entry is based on evidence of active exploitation and reinforces the urgency for federal agencies to address such high-risk vulnerabilities on publicly exposed assets as mandated by Binding Operational Directive 26-04.