Skip to content
See the World Through ScienceA project of ALLATRA

Fortinet Says Attackers Are Exploiting a FortiMail Flaw and the Fix Is Not out Yet

AI & Technology

Republish this story

Our work is licensed under Creative Commons BY-NC 4.0. You may republish this piece for free — with credit to ALLATRA Media and a link to the original, unedited beyond length trims, and not for commercial use.

Read the full license

A white Fortinet FortiGate 100D network appliance mounted in a rack above a Dell PowerConnect switch, with yellow and green patch cables running to its ports.
A Fortinet security appliance running in a network cabinet, above a Dell switch. The advisory of October 1, 2026 concerns FortiMail, a separate product in the same vendor's range (illustrative)."Fortinet FortiGate 100D" by webernetz, via flickr, CC-BY-2.0

Fortinet says attackers are already exploiting a flaw in FortiMail, its email security gateway, and the company has not yet released a version that fixes it.

The advisory, published Oct. 1 as FG-IR-26-175, records the flaw as known exploited and lists the fixed builds 8.0.2, 7.6.7 and 7.4.9 as upcoming rather than available. Until one arrives, the company's advice is to turn off FortiMail's identity-based encryption feature or restrict who can reach its web interface.

Fortinet describes the problem, tracked as CVE-2026-104286, as a path-traversal flaw that lets an attacker with no account on the system write files to it over the network. The advisory lists FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8 and 7.2.0 through 7.2.9 as affected, and tells administrators still on the 7.2 branch to move to 7.4 or above. Fortinet rates the flaw Critical, 9.8 out of 10.

CISA added the same identifier to its Known Exploited Vulnerabilities catalog on Oct. 1, saying it did so on evidence of active exploitation. Under Binding Operational Directive 26-04, federal civilian agencies must prioritize rapid remediation of catalog entries on publicly exposed assets that would give an attacker total control of the asset, and must check whether the system was already compromised before applying the patch. CISA says the directive binds only those agencies, though it encourages every other organization to prioritize catalog entries the same way.

Neither Fortinet nor CISA named who is exploiting the flaw, or how many systems have been affected.

Sources

Spot an error?

Spot an error?

Report an error

Spotted a mistake on this page? Tell us what's wrong and our editors will take a look.

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We correct mistakes openly. Select any text to flag it. Fixes are logged under our Corrections Policy.

Report an error

Reporting on

Fortinet Says Attackers Are Exploiting a FortiMail Flaw and the Fix Is Not out Yet

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We read every report. Corrections are logged publicly.