Fortinet security advisory (AV26-989)

Canadian Centre for Cyber Security Version 1 original current

Imported from official source

Serial number: AV26-989Date: October 1, 2026 As of October 1, 2026, Fortinet is affected by vulnerabilities in the following products: FortiMail 8.0 Versions prior to 8.0.2 FortiMail 7.6 Versions prior to 7.6.7 FortiMail 7.4 Versions prior to 7.4.9 FortiMail 7.2 Upgrade to branch 7.4 or above Fortinet indicates that CVE-2026-104286 is exploited in the wild. On October 1, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-104286 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates. Fortinet - Improper limitation of a pathname to a restricted directory Fortinet PSIRT Advisories CISA KEV: CVE-2026-104286

This version

Version
1 of 1
Recorded
October 02, 2026 12:00
Change
Initial
Content hash
03abfc6743037999b00525f17f9edf44
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.