7IT · News

The alarm went off at CISA on Thursday. If you run FortiMail, the clock is running.

By Lior AharonovFounder, 7IT Solutions ·

What happened

On Thursday, 1 October 2026, CISA added CVE-2026-104286, a path traversal flaw in Fortinet FortiMail, to its catalog of vulnerabilities attackers are already using. SecurityWeek reports a CVSS score of 9.8: crafted web requests can write files onto the appliance. As of 2 October the fixes (7.4.9, 7.6.7 and 8.0.2) were planned, with no release date.

Why it matters

Your mail gateway reads every message coming in: the invoice, the password reset, the 'please wire the money today'. Whoever owns it is already inside. Affected: 7.2.0 to 7.2.9, 7.4.0 to 7.4.8, 7.6.0 to 7.6.6 and 8.0.0 to 8.0.1.

What to do

If you run FortiMail, apply Fortinet's workaround right now: turn off IBE support, or cut web access to the management interface and limit it to trusted sources. The patch? Not out as of 2 October, so the workaround is the plan.

The scariest breach isn't the one in the headlines. It's the one happening in your mail server while you read this.

Lior Aharonov · my take

Sources

securityactively exploitedcisa kevfortinet

Researched with AI tools; every fact is checked against the linked sources.

All 7IT news · Atom feed

Need a hand with something like this? Talk to 7IT.