Fortinet security advisory (AV26-989)
Canada's Cyber Centre warns FortiMail path-traversal CVE-2026-104286 is exploited in the wild and listed in CISA KEV.
On October 1, 2026, the Canadian Centre for Cyber Security issued advisory AV26-989 on FortiMail vulnerabilities. Affected versions are FortiMail 8.0 before 8.0.2, 7.6 before 7.6.7, and 7.4 before 7.4.9; 7.2 users are directed to upgrade to 7.4 or later. Fortinet says CVE-2026-104286, an improper pathname limitation, is exploited in the wild, and CISA added it to the Known Exploited Vulnerabilities catalog the same day.
- CVE-2026-104286 in FortiMail is confirmed exploited in the wild.
- CISA added the vulnerability to the KEV catalog on October 1, 2026.
- Update FortiMail 8.0 to 8.0.2, 7.6 to 7.6.7, and 7.4 to 7.4.9.
- FortiMail 7.2 has no fix listed; move to branch 7.4 or newer.
- The flaw is improper limitation of a pathname to a restricted directory.
Vulnerabilities mentionedAll →
- CVE-2026-1042869.82%Unauthenticated path traversal file write in Fortinet FortiMailpublished · Fortinet FortiMail KEV PoC
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-104286 |
Full article110 words · extracted from cyber.gc.ca · click to collapse
Serial number: AV26-989
Date: October 1, 2026
As of October 1, 2026, Fortinet is affected by vulnerabilities in the following products:
- FortiMail 8.0
- Versions prior to 8.0.2
- FortiMail 7.6
- Versions prior to 7.6.7
- FortiMail 7.4
- Versions prior to 7.4.9
- FortiMail 7.2
- Upgrade to branch 7.4 or above
Fortinet indicates that CVE-2026-104286 is exploited in the wild.
On October 1, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-104286 to their Known Exploited Vulnerabilities (KEV) Database.
The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyber.gc.ca/en/alerts-advisories/fortinet-security-advisory-av26-989