Serial number: AV26-989
Date: October 1, 2026
As of October 1, 2026, Fortinet is affected by vulnerabilities in the following products:
- FortiMail 8.0
- Versions prior to 8.0.2
- FortiMail 7.6
- Versions prior to 7.6.7
- FortiMail 7.4
- Versions prior to 7.4.9
- FortiMail 7.2
- Upgrade to branch 7.4 or above
Fortinet indicates that CVE-2026-104286 is exploited in the wild.
On October 1, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-104286 to their Known Exploited Vulnerabilities (KEV) Database.
The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.