Fortinet has disclosed a critical vulnerability in FortiMail, its email security gateway, and attackers are already using it. The flaw is tracked as CVE-2026-104286 and carries a severity score of 9.8 out of 10. On 2 October it was added to the US CISA catalogue of known exploited vulnerabilities, which is the clearest signal there is that this is not a theoretical risk.
If your business uses FortiMail, or an IT provider runs it for you, this needs attention today rather than next week.
What the flaw allows
The bug lets an attacker with no login write files of their choosing onto the underlying system. It comes from weak handling of file paths and special characters, and it can be triggered remotely. Writing arbitrary files to a mail gateway is a serious problem. It can let an attacker plant tools, change how the device behaves, or build a foothold from which to reach the rest of your network.
Email gateways are attractive targets because they sit at the edge of your network, see all of your mail, and are often left alone once installed. Many small businesses do not even know which version they run.
The affected versions are FortiMail 8.0.0 to 8.0.1, 7.6.0 to 7.6.6 and 7.4.0 to 7.4.8. Fortinet has released fixed versions: 8.0.2, 7.6.7 and 7.4.9 or later.
What to do today
Find out whether you use FortiMail. Ask your IT provider directly: “Do we run FortiMail, which version, and has CVE-2026-104286 been patched?” If you use Microsoft 365 or Google Workspace filtering only, this particular flaw does not affect you, but it is worth confirming rather than assuming.
Patch to a fixed version. Updating is the only complete fix. If you cannot update immediately, restrict who can reach the management interface so it is not exposed to the internet, and follow Fortinet’s published guidance.
Look for signs of compromise. Because exploitation has already started, patching alone may not be enough. Ask for the device logs to be reviewed for unexpected file changes, new administrator accounts or unusual outbound connections, particularly around the period before you applied the update.
Review who can log in. Check administrator accounts on the appliance, remove any you do not recognise, and rotate credentials if there is any doubt.
The wider lesson
This is the second Fortinet-related warning in recent weeks, and it follows a pattern: edge devices such as firewalls, VPNs and mail gateways are patched late because they feel like infrastructure rather than software. Attackers know this and move fast once a flaw is public.
Keeping a simple list of every internet-facing device you own, with its version and the person responsible for updating it, closes much of that gap. If an outsourced provider manages your systems, make sure patching these devices is written into the agreement. A monitoring service such as KeepSafe can also help you spot exposed or out-of-date systems and track fresh incidents that affect UK businesses, so you hear about problems like this on the day they appear.
The takeaway
A critical, actively exploited flaw in an email gateway is a same-day job. Confirm whether you run FortiMail, update to 8.0.2, 7.6.7 or 7.4.9 or later, and have someone check the device for signs it was reached before you patched.