# Fortinet warns of exploited FortiMail flaw as CISA sets October 4 deadline

_Published Friday, October 2, 2026 at 5:08 AM EDT · Security · Latest · Tier 1 — Major_

![Fortinet warns of exploited FortiMail flaw as CISA sets October 4 deadline — Primary](https://img.helpnetsecurity.com/wp-content/uploads/2026/01/21163736/fortinet-man-1500.webp)

Fortinet warned on October 1 that attackers are exploiting CVE-2026-104286 in FortiMail, its email security gateway. The flaw allows an unauthenticated attacker to write arbitrary files through crafted HTTP or HTTPS requests. CISA added it to its Known Exploited Vulnerabilities catalog that day and gave federal civilian agencies until October 4 to address it.

The vulnerability affects versions 8.0.0-8.0.1, 7.6.0-7.6.6, 7.4.0-7.4.8 and 7.2.0-7.2.9. Planned fixes in 8.0.2, 7.6.7 and 7.4.9 are not yet released. Administrators can disable identity-based encryption or block internet access to the management interface, including by restricting access to a trusted private network.

## Sources

- [Help Net Security](https://www.helpnetsecurity.com/2026/10/02/fortinet-fortimail-vulnerability-cve-2026-104286/)

---
Canonical: https://techandbusiness.org/newswire/y2vc3lQYSw_J8b8i9gJ0bf
Published: 2026-10-02T09:08:33.720Z
Story chronology: 2026-10-01T00:00:00.000Z
Retrieved: 2026-10-02T13:45:46.392Z
Publisher: Tech & Business (techandbusiness.org)
