Organizations that operate Fortinet FortiMail should check the installed version. Fortinet lists affected ranges, upgrade targets, and temporary workarounds.
In 60 seconds
- Organizations running Fortinet FortiMail should check the installed version against Fortinet’s affected ranges.
- Ask the email or network administrator whether FortiMail is in use and whether this issue has been reviewed.
- Use Fortinet’s current upgrade target or listed workaround through the organization’s normal change process.
- Do not run commands or install files supplied by an unexpected caller or message claiming to offer a fix.
Who should care and what to do today
This alert concerns organizations that operate Fortinet FortiMail. Ask the person who manages the organization’s email or network systems whether FortiMail is in use and which version is installed.
Fortinet lists these affected ranges: FortiMail 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9. Compare the installed version with Fortinet’s official security guidance.
If the version is affected, review Fortinet’s current upgrade target or another listed step through the organization’s normal change process. The October 1 guidance described the upgrade targets as upcoming, so administrators should check Fortinet’s page for current availability before changing the system. Do not run commands or install files from an unexpected message or caller claiming to provide a fix.
What CISA and Fortinet reported
CISA added the FortiMail issue to its Known Exploited Vulnerabilities Catalog on October 1, 2026. The catalog records security flaws for which CISA says it has evidence of active exploitation, meaning attackers are using them.
The issue is a path traversal flaw. In plain terms, a specially made web request may reach a file or location outside the area the system should allow. Fortinet says an attacker who does not need to sign in may be able to write files to the underlying system through crafted web requests.
Fortinet says the issue has been exploited in the wild. Its guidance lists upgrade targets of 8.0.2 or later, 7.6.7 or later, and 7.4.9 or later for the first three affected branches. For version 7.2, it directs customers to move to the 7.4 branch or later. The guidance published October 1 called those targets upcoming, so the current vendor page matters.
Options if the system cannot be updated immediately
Fortinet lists disabling IBE feature support as a workaround. Fortinet also says administrators can disable access to the FortiMail management interface from the internet or limit access to a trusted private network.
These steps can affect how the system is managed or configured. An administrator should review the effect before applying one and use the organization’s normal change process.
Fortinet’s guidance lists possible signs of compromise, including specific files, internet addresses, and log entries. If the system was exposed and an administrator finds one of those signs, the organization should use its existing incident-review process. An upgrade by itself does not show what happened on that system.
What the federal requirement means
CISA says Binding Operational Directive 26-04 sets vulnerability-management requirements for federal civilian executive-branch agencies.
The directive tells those agencies to prioritize certain catalog-listed flaws on publicly exposed systems when exploitation would give an attacker total control. It also sets expectations for checking whether a system was compromised before a fix was applied.
The directive applies to the federal agencies covered by it. CISA encourages other organizations to use the catalog when deciding which security work to handle first.
General guidance: avoid improvised fixes
Do not download a file, run a command, or give someone access because an unexpected message or caller claims to offer a FortiMail fix. Use the official Fortinet guidance and the organization’s established administrator or security contact instead.
CISA’s catalog entry and Fortinet’s notice concern active exploitation of this FortiMail issue. They do not report what happened on every FortiMail system. The version check and any review for signs of access should be handled by the organization’s administrator or security team.
Does this affect me?
- Who may be affected
- The alert concerns organizations that operate Fortinet FortiMail. Fortinet lists affected ranges for versions 8.0, 7.6, 7.4, and 7.2.
- How to check
- Ask the email or network administrator whether FortiMail is in use, which version is installed, and whether it matches Fortinet’s listed ranges.
- What to do
- If an affected version is running, review Fortinet’s current upgrade target or listed workaround through the organization’s normal change process.
- What to avoid
- Do not run commands or install files supplied by unsolicited contacts claiming to provide a FortiMail fix.
Common questions
Which FortiMail versions does Fortinet list as affected?
Fortinet lists 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9. Administrators should check Fortinet’s current page because the October 1 guidance described the listed upgrade targets as upcoming.
What does active exploitation mean in this alert?
CISA says it has evidence that attackers are using the flaw. Fortinet also says the issue has been exploited in the wild. The alert concerns the vulnerability and does not report what happened on every FortiMail system.
What upgrade targets does Fortinet list?
For affected 8.0, 7.6, and 7.4 systems, Fortinet lists 8.0.2 or later, 7.6.7 or later, and 7.4.9 or later. For version 7.2, it directs customers to move to the 7.4 branch or later. The October 1 guidance described these targets as upcoming, so administrators should verify current availability.
What workarounds does Fortinet list?
Fortinet lists disabling IBE feature support or restricting access to the FortiMail management interface by removing internet access or allowing only trusted private-network access. Administrators should review the effect of either step before applying it.
Does the federal requirement apply to every organization?
No. CISA says Binding Operational Directive 26-04 applies to federal civilian executive-branch agencies. CISA encourages other organizations to use the catalog to help prioritize security work.
Primary source
This article is based on CISA’s October 1, 2026 alert and Fortinet’s official security guidance: https://www.cisa.gov/news-events/alerts/2026/10/01/cisa-adds-one-known-exploited-vulnerability-catalog and https://fortiguard.fortinet.com/psirt/FG-IR-26-175 Read the complete original source.
More reporting on this event
Concerned this may affect your computer or account?
Bring the exact alert, device, product, and timeline. Leon will help separate urgent action from noise.
Article history: Published Oct 1, 2026 at 9:12 pm EDT. Updates and corrections are noted here when material facts change.
