Security · October 8, 2026
Also published in हिन्दी, Svenska, Türkçe, Español, Português (Brasil), Italiano, Nederlands, Русский
Fortinet begins update for FortiMail to address zero-day vulnerability
Fortinet has initiated the provision of updates for its email security product, FortiMail, in response to the zero-day vulnerability identified as CVE-2026-104286. The vulnerability allows unauthorized file writing on systems via crafted HTTP requests, posing significant security risks.
On October 1, 2026, Fortinet published a security advisory noting the reports of exploitation and outlining mitigation strategies while preparing for the update. The zero-day vulnerability had already been confirmed to have been exploited, prompting the company to provide Indicators of Compromise (IoC) information for user awareness.
On October 5, 2026, the company updated its advisory and announced the release of the anticipated patches, including FortiMail versions 8.0.2, 7.6.7, and 7.4.9, urging users to update their systems promptly. Additionally, users on the 7.2 branch are advised to migrate to versions from the 7.4 branch onward to mitigate the vulnerability's impact.
The U.S. authorities have added this vulnerability to their list of exploited vulnerabilities, emphasizing the need for early response. Other vulnerabilities affecting various software have also been reported, underscoring the importance of timely updates and security measures across multiple platforms.