Fortinet security advisory (AV26-989)
Canada's Cyber Centre warns FortiMail path-traversal CVE-2026-104286 is exploited in the wild and listed in CISA KEV.
On October 1, 2026, the Canadian Centre for Cyber Security issued advisory AV26-989 on FortiMail vulnerabilities. Affected versions are FortiMail 8.0 before 8.0.2, 7.6 before 7.6.7, and 7.4 before 7.4.9; 7.2 users are directed to upgrade to 7.4 or later. Fortinet says CVE-2026-104286, an improper pathname limitation, is exploited in the wild, and CISA added it to the Known Exploited Vulnerabilities catalog the same day.