Fortinet published FG-IR-26-175 for a critical FortiMail bug, CVE-2026-104286. Unauthenticated attackers can write files over HTTP or HTTPS to the management interface. Affected trains include 8.0.0 to 8.0.1, 7.6.0 to 7.6.6, 7.4.0 to 7.4.8, and 7.2.0 to 7.2.9. Some branches still wait on 7.4.9, 7.6.7, and 8.0.2.
Fortinet says this is exploited in the wild and told BleepingComputer it is coordinating with CISA. CISA put the CVE in the Known Exploited Vulnerabilities catalog and gave federal agencies until October 4.
A write-file bug on the admin interface is a full-box problem. Until every branch has a numbered build, Fortinet's own guidance is to keep that management path off the public internet. If I ran FortiMail, I would read FG-IR-26-175 first, then patch when the numbered build lands.