Filter email through FortiMail? Patch it today
Businesses running Fortinet FortiMail (versions 7.2 through 8.0.1) as their email security gateway, usually set up and maintained by an IT provider rather than run in-house. If your IT provider manages a different email filtering product (Microsoft 365, Mimecast, or similar), this isn't your equipment.
Fortinet FortiMail is an email security gateway many small and mid-sized businesses use to filter spam, phishing and malware out of email before it reaches staff inboxes. Fortinet has confirmed a critical flaw, rated 9.8 out of 10, that lets an attacker who hasn't logged in at all plant files on the device over an ordinary web request. Criminals are already using it to drop their own software onto affected systems. CISA (the US Cybersecurity and Infrastructure Security Agency, which tracks vulnerabilities under active attack) gave US federal agencies only three days to fix it, a sign of how urgent this is. A fix is available, and a quick workaround exists if patching takes longer.
Do this
Ask your IT provider: "Is our FortiMail updated to 7.4.9, 7.6.7, 8.0.2 or later, and if not, has the IBE feature been disabled as a stopgap?"
Sources: CISA KEV: FortiMail path traversal flaw ↗ · Fortinet security advisory ↗CVE-2026-104286 · CWE-22 · CWE-158