The alarm went off at CISA on Thursday. If you run FortiMail, the clock is running.
By Lior AharonovFounder, 7IT Solutions ·
On Thursday, 1 October 2026, CISA added CVE-2026-104286, a path traversal flaw in Fortinet FortiMail, to its catalog of vulnerabilities attackers are already using. SecurityWeek reports a CVSS score of 9.8: crafted web requests can write files onto the appliance. As of 2 October the fixes (7.4.9, 7.6.7 and 8.0.2) were planned, with no release date.
Your mail gateway reads every message coming in: the invoice, the password reset, the 'please wire the money today'. Whoever owns it is already inside. Affected: 7.2.0 to 7.2.9, 7.4.0 to 7.4.8, 7.6.0 to 7.6.6 and 8.0.0 to 8.0.1.
If you run FortiMail, apply Fortinet's workaround right now: turn off IBE support, or cut web access to the management interface and limit it to trusted sources. The patch? Not out as of 2 October, so the workaround is the plan.
The scariest breach isn't the one in the headlines. It's the one happening in your mail server while you read this.
Lior Aharonov · my takeSources
Researched with AI tools; every fact is checked against the linked sources.