News with an accent.

Front of a FortiMail 400F appliance, a white rack-mounted chassis with network ports, USB ports and the Fortinet logo.
Internet

FortiMail 7.6.7 is out, the release Fortinet lists as the fix

The release notes are dated Oct. 2. Fortinet does not name the exploited flaw in them, and there is no trace of the other two fixed versions.

Fortinet has published version 7.6.7 of FortiMail, the release its security advisory names as the fix for the vulnerability tracked as CVE-2026-104286. The release notes are dated Oct. 2, the same day our first report described the fix as pending.

The flaw, rated 9.8 out of 10 by Fortinet, lets someone with no credentials write files to the appliance using crafted web requests. The company and the U.S. cybersecurity agency CISA report that it is already being used in real attacks.

What is and is not confirmed

Fortinet's advisory, updated Oct. 5, lists three fixed versions: 7.4.9, 7.6.7 and 8.0.2. For the 7.2 branch, the last affected release is 7.2.9, and Fortinet says to move to 7.4 or later.

What has been checked so far:

  • FortiMail 7.6.7: it exists, as build 858. Its notes include path traversal fixes, the type of defect Fortinet describes in the advisory, but they do not name the CVE or the FG-IR-26-175 identifier.
  • FortiMail 8.0.2 and 7.4.9: this outlet found no release notes or confirmed download.
  • Attacks: neither Fortinet nor CISA has said who is behind them or how many appliances are exposed.

That 7.6.7 is the fix is what Fortinet states in its advisory. Checking that it closes this CVE is up to whoever runs the appliance. Until an upgrade is possible, Fortinet recommends turning off the IBE feature, identity-based email encryption, and limiting web access to trusted networks.

There are no figures on affected organizations in Mexico. Still pending: Fortinet publishing the notes for 8.0.2 and 7.4.9 and clarifying whether 7.6.7 fully closes the CVE.

Keep reading

El Mediático uses cookies to measure its audience and, where advertising is active, to show ads. You can accept all, reject all, or choose what to allow. The cookie policy is available in Spanish only. More about cookies (Spanish)