Trusence Every claim has a source
Last updated 4 October 2026 Search Türkçe
← All stories
Security

Fortinet warns of exploited FortiMail flaw with no fixes yet for key releases

CISA has added the bug to its exploited-vulnerability list, putting exposed FortiMail systems on a tight mitigation clock.

Updated 4 October 2026

Fortinet has disclosed and is now seeing active exploitation of a critical FortiMail bug, CVE-2026-104286, that can let an unauthenticated attacker write files and run code on exposed appliances. The issue affects FortiMail 7.2.0 through 7.2.9, 7.4.0 through 7.4.8, 7.6.0 through 7.6.6, and 8.0.0 through 8.0.1, and Fortinet says fixes are not yet out for 7.4, 7.6, or 8.0 builds, with patched versions planned for 7.4.9, 7.6.7, and 8.0.2. It has published workarounds, compromise indicators, and attacker IPs, and CISA has added the flaw to its Known Exploited Vulnerability list with a federal mitigation deadline of October 4. In a separate disclosure, Cisco said a critical zero-day in Catalyst SD-WAN Manager, CVE-2026-76504, is being used to reach admin privileges, affecting all deployments and prompting fixed releases across multiple branches. Cisco also said this is the fifth actively exploited SD-WAN zero-day this year and pointed defenders to log files and IOCs that include %6a-encoded requests.

Why it matters

Organizations running affected FortiMail releases need to assume exposure now, because the flaw is already being used in zero-day attacks and Fortinet has not yet shipped fixes for 7.4, 7.6, or 8.0. With CISA setting an October 4 deadline for federal mitigation, the focus shifts to workarounds and incident checks until patched versions arrive.

Sources

  • BleepingComputer
  • Ars Technica