A critical flaw in Fortinet's FortiMail email security product is being actively exploited by attackers, and the official fixes are not yet available. If your business runs FortiMail, this needs attention today.
- What it is: A vulnerability (CVE-2026-104286, rated 9.8 out of 10) that lets an attacker with no login write files onto the appliance by sending specially crafted web requests.
- Who is affected: FortiMail versions 7.2, 7.4, 7.6 and 8.0 (up to 8.0.1). Businesses using Fortinet email filtering, or whose IT provider manages it for them, should check.
- The risk: Attackers are already using it, and the US cyber agency CISA added it to its Known Exploited Vulnerabilities list on 1 October 2026. A compromised email gateway can expose mail and give attackers a foothold in your network.
- What to do: Make sure the FortiMail management interface is not reachable from the internet, restrict it to trusted internal networks, and apply Fortinet's workaround of disabling identity-based encryption until patched versions (7.4.9, 7.6.7 and 8.0.2) are released. Version 7.2 users should plan an upgrade to 7.4 or later.
We recommend checking your FortiMail exposure now and contacting OzComm if you would like us to review it for you. Source: Help Net Security.