Vulnerabilities
Fortinet confirms attacks on FortiMail through a critical flaw that requires no password
Fortinet has warned that a critical vulnerability in FortiMail, its email security system, is being exploited. CISA and INCIBE have flagged it. If your company filters its email through a FortiMail, this is the week to ask whether it's up to date or protected with the temporary workaround.
Fortinet — Vendor of the affected product (FortiMail)

In 30 seconds
- On 1 October Fortinet warned that a critical FortiMail vulnerability (CVE-2026-104286, CVSS 9.8) "has been reported to be exploited".
- The flaw lets an attacker with no credentials write files on the device and, according to the vendor, execute unauthorised code or commands.
- CISA added it to its catalogue of exploited vulnerabilities that same day, and INCIBE-CERT flagged it as critical on 2 October.
- The fixed versions are FortiMail 8.0.2, 7.6.7 and 7.4.9; the 7.2 branch has no fix and must move to 7.4 or later.
Does this affect me?
It affects you if your company's email goes through a FortiMail that isn't on a fixed version and doesn't have the temporary workaround applied. It's more common in medium-sized companies or with an IT provider that works with Fortinet. It doesn't affect you if you only use Microsoft 365 or Google Workspace filtering, or if you have a FortiGate without FortiMail. No Spanish victims have been confirmed.
What happened
On 1 October 2026, Fortinet published advisory FG-IR-26-175 about a critical vulnerability in FortiMail, its security system that filters a company's email before it reaches the mailboxes. The flaw, tracked as CVE-2026-104286, has a CVSS score of 9.8 out of 10.
According to Fortinet, the vulnerability "may allow an unauthenticated attacker to write arbitrary files on the underlying system" via crafted web requests, with the impact to "execute unauthorized code or commands". The vendor itself states that the flaw "has been reported to be exploited in the wild" and urges customers to apply the workaround described in the advisory.
That same day, the US cybersecurity agency (CISA) added it to its catalogue of actively exploited vulnerabilities. On 2 October, INCIBE-CERT published its own advisory (INCIBE-2026-692) rated critical, the highest level on its scale. On 5 October, Fortinet updated the advisory with the versions that fix the flaw.
What we know
- Affected versions (according to Fortinet): FortiMail 8.0.0 to 8.0.1, 7.6.0 to 7.6.6, 7.4.0 to 7.4.8 and 7.2.0 to 7.2.9.
- Fixed versions: FortiMail 8.0.2, 7.6.7 or 7.4.9 (or later). The 7.2 branch has no fix of its own: you need to move to 7.4 or later.
- Temporary workaround: Fortinet advises disabling FortiMail's IBE encryption feature or, alternatively, blocking internet access to the webmail interface (or limiting it to a trusted private network).
- Indicators of compromise: Fortinet's advisory includes IP addresses and log entries that can be used to check whether a device has been attacked.

What we don't know yet
- Who is behind the attacks or how many devices have been attacked. Neither Fortinet, CISA nor INCIBE gives details.
- Whether there are victims in Spain. None have been confirmed.
- Whether FortiMail Cloud, the version of the service that Fortinet runs in the cloud, is affected. The advisory doesn't mention it.
- Whether the fixed versions are already available for every device. On 1 October they weren't yet; Fortinet added them to the advisory on 5 October, but still urges customers to apply the workaround.
Why it matters
An email filtering system sees the company's messages pass through it: invoices, contracts, customer data. Whoever controls that device sits at a very sensitive point without anyone inside having fallen for any trick.
And it repeats a pattern we've already seen with firewalls and VPNs: attackers go after security devices exposed to the internet, because they tend to fall outside routine updates.
What it means for an SME
Most small companies don't have a FortiMail. But in companies of a certain size, or when the IT provider works with Fortinet, it's common for email to go through one. And that's where the usual gaps show up:
- the device was installed and is maintained by the provider, and nobody in the company knows it exists;
- it isn't clear who should apply an urgent update outside the usual maintenance;
- the webmail is open to the internet because "it's more convenient that way".
None of this takes technical knowledge, just asking the questions this week.
What your company should do this week
- Ask your IT provider whether your email goes through a FortiMail and which version it runs. If it isn't one of the fixed versions, ask for the update.
- If it can't be updated straight away, ask for Fortinet's temporary workaround to be applied: disable the IBE feature or close access to the webmail from the internet.
- If it's on the 7.2 branch, there's no patch: ask for a plan to move to 7.4 or later.
- Ask them to check the indicators of compromise published by Fortinet. The flaw was already being exploited when Fortinet published the advisory: updating closes the door, but it doesn't remove anyone who already got in.
If you're not sure which of your company's devices are exposed to the internet or who is responsible for updating them, that's exactly what a cybersecurity audit reviews.
Sources
- Fortinet PSIRT — advisory FG-IR-26-175 (CVE-2026-104286), published 1 October 2026 and updated 5 October 2026Primary source
- CISA — «CISA Adds One Known Exploited Vulnerability to Catalog» (1 October 2026)Primary source
- INCIBE-CERT — «Path Traversal en FortiMail de Fortinet», advisory INCIBE-2026-692 (2 October 2026)Primary source
- The Hacker News — «Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes» (Ravie Lakshmanan, 2 October 2026)
Defentria editorial team. The Defentria team selects cybersecurity news from primary sources (CERTs, official bodies and vendors) and explains what it means for a Spanish SME and what to do about it.


