You bought FortiMail so inbound junk would die in a box that isn’t your mailbox cluster. Fortinet published the punchline anyway. CVE-2026-104286 is a critical path traversal, stacked with a NULL-byte neutralization failure, and the company says unauthenticated attackers are already writing files onto the appliance. Help Net Security and SecurityWeek both have Fortinet urging a workaround until a real fix ships. That is cybersecurity with a SKU, a public listener, and a file write. If your threat-protection story is “the gateway handles mail,” you just inherited a host that already sees every message you care about.

That box was always a write surface

Email security gateways have to answer the internet. That is the product. SMTP on 25, maybe submission, a web admin on 443, and parsers that unpack MIME like it is a polite document format. Path traversal plus a NULL byte is how those parsers get talked into writing outside the directory they were supposed to jail. The check and the write disagree about where the string ends. Unauthenticated arbitrary file write is how you get a planted config, a web shell, a dropped binary, or a cron job on a box sitting in the inspection path.

Defense in depth diagrams love this appliance. It sits in front of the mail servers, so the rest of the stack can pretend inbound is clean. The firewall rule that “protects” FortiMail is usually an allow from the world on the ports the SKU requires. You published it. They needed a path the daemon would honor.

File write on the gateway is a foothold with a view. They can read mail, alter mail, or pivot into the management VLAN you never segmented because it was “just the spam filter.” Incident response gets worse from there. The logs you trust are the logs the appliance writes. If they can write files, they can write those logs too. Your first question is which files changed on the box, not which spam rule fired last Tuesday.

Nobody files a ticket named “check the filter’s disk.”

Fortinet security appliance warning related to an exploited FortiMail vulnerability
Fortinet is shipping a workaround for an in-the-wild FortiMail file write. Your rebuild plan should assume the disk is untrusted until you prove otherwise.

Google is nailing the helper API shut

Google is doing the grown-up version of the same admission on phones. Android 17’s Advanced Protection limits accessibility services to verified apps classified as Accessibility Tools. The Hacker News writeup is blunt: malicious apps have been using that API as the main conduit for malware and financial fraud. Accessibility was built so people who need it can use the device. It became a privileged remote-control surface because the OS treated “this app helps the user” as a reason to hand over taps, screens, and keystrokes.

Steal that framing for FortiMail. Privileged helpers are high-value because they already sit above the thing you wanted protected. An accessibility service sees the UI. An email gateway sees the mail. A verified badge is a vendor timeline. Your job is to shrink who can talk to the helper and what it is allowed to write.

You will hear that mobile malware is a different universe from appliance bugs. The operator lesson is identical. If a component has extra privilege because it is “helpful,” assume someone is already driving it. Then cut the drive path. Waiting for Fortinet to invent an Android-style “verified tools only” posture for every listener you exposed is how this class of bug keeps landing in production.

Android 17 Advanced Protection restricting accessibility services to verified tools
Android 17’s Advanced Protection finally treats accessibility as a privileged API, the same class of helper your mail gateway has been for years.

Do the ugly work before the patch lands

Fortinet says apply the workaround. Do that today. Then treat every FortiMail instance as a host that might already have extra files on disk, including HA pairs and that lab unit still on a public NAT because someone needed to test DLP.

Immediate moves, in the order that actually reduces risk:

  • Apply the vendor workaround for CVE-2026-104286 on every appliance, then confirm it actually stuck after failover.
  • Pull the management GUI off the internet. Admin only from a jump host you control.
  • Snapshot running config, and capture hashes of web roots, plugin dirs, and scheduled-task paths before you “clean” anything.
  • Hunt unexpected files, recently touched binaries, new local admins, and mystery services on the box.
  • Restrict who can hit the listener. You may not be able to hide SMTP, but you can hide 443 from the world.

After the bleeding stops, keep going. Put the appliance in the same inventory as Windows servers: owner, patch SLA, last firmware, threat detection coverage that is more than “syslog exists.” Security hardening here is boring and overdue. Disable unused services. Rotate admin credentials. Require MFA on the GUI. Dump leftover debug accounts from the last audit that nobody closed. Alert on config exports, new local users, and file changes in application directories.

The admin plane still eats password guesses. If that GUI is reachable, brute-force is free reconnaissance while someone else is busy with the path traversal. Put an autoban in front of it. ipban on a Linux jump host, or IPBan Pro if those jump boxes are Windows, is the control that kills the noise so your people can see the file-write event.

Tabletop the rebuild. Incident response for this class of bug ends with known-good firmware and a config you pulled from a backup you trust, not a reboot of the mail queue. If you cannot rebuild without tribal knowledge, that is the next ticket. Write down which certificates, TLS profiles, and routing rules live only on the box. Those are the files you will miss at 2 a.m.

Your cybersecurity tickets still skip the appliance

Most programs watch endpoints, identity, and maybe the firewall hit counters. The mail gateway is furniture. It has been there since 2018, it “just works,” and the only ticket it generates is a full queue. That is how you miss an unauthenticated write.

If threat detection never looks at file integrity on the gateway, you will learn about CVE-2026-104286 from a second advisory, a ransom note, or a partner who stopped receiving mail. Cyber security spend that paid for the SKU should pay for watching the SKU like a server: integrity, auth, egress from a device that was never supposed to browse the web.

The Android change is a hint about where vendors slowly move once the abuse is undeniable. Privileged APIs get locked to a verified class. You already know which boxes sit on the internet with parsers and admin GUIs. Those are this week’s work. Firmware later. Isolation now.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.