← Back to feed
Vulnerabilities & PatchesEmerging1 sourceOct 2, 2026 · 11:55via Malware.news

Fortinet security advisory (AV26-989)

Brief

Serial number: AV26-989 Date: October 1, 2026

As of October 1, 2026, Fortinet is affected by vulnerabilities in the following products:

  • FortiMail 8.0
  • Versions prior to 8.0.2
  • FortiMail 7.6
  • Versions prior to 7.6.7
  • FortiMail 7.4
  • Versions prior to 7.4.9
  • FortiMail 7.2
  • Upgrade to branch 7.4 or above

Fortinet indicates that CVE-2026-104286 is exploited in the wild.

On October 1, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-104286 to their Known Exploited Vulnerabilities (KEV) Database.

The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.

  • Fortinet - Improper limitation of a pathname to a restricted directory
  • Fortinet PSIRT Advisories
  • CISA KEV: CVE-2026-104286

cyber.gc.ca/en/alerts-advisories/fortinet-sec…

Read more on Malware.news→