Fortinet Says Attackers Are Exploiting a FortiMail Flaw and the Fix Is Not out Yet

Fortinet says attackers are already exploiting a flaw in FortiMail, its email security gateway, and the company has not yet released a version that fixes it.
The advisory, published Oct. 1 as FG-IR-26-175, records the flaw as known exploited and lists the fixed builds 8.0.2, 7.6.7 and 7.4.9 as upcoming rather than available. Until one arrives, the company's advice is to turn off FortiMail's identity-based encryption feature or restrict who can reach its web interface.
Fortinet describes the problem, tracked as CVE-2026-104286, as a path-traversal flaw that lets an attacker with no account on the system write files to it over the network. The advisory lists FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8 and 7.2.0 through 7.2.9 as affected, and tells administrators still on the 7.2 branch to move to 7.4 or above. Fortinet rates the flaw Critical, 9.8 out of 10.
CISA added the same identifier to its Known Exploited Vulnerabilities catalog on Oct. 1, saying it did so on evidence of active exploitation. Under Binding Operational Directive 26-04, federal civilian agencies must prioritize rapid remediation of catalog entries on publicly exposed assets that would give an attacker total control of the asset, and must check whether the system was already compromised before applying the patch. CISA says the directive binds only those agencies, though it encourages every other organization to prioritize catalog entries the same way.
Neither Fortinet nor CISA named who is exploiting the flaw, or how many systems have been affected.
