VDB
CVE-2026-104286
CVE-2026-104286
PUBLISHED
KEV
As of October 1, 2026, Fortinet is affected by vulnerabilities in the following products: FortiMail 8.0 Versions prior to 8.0.2 FortiMail 7.6 Versions prior to 7.6.7 FortiMail 7.4 Versions prior to 7.4.9 FortiMail 7.2 Upgrade to branch 7.4 or above Fortinet indicates that CVE-2026-104286 is exploited in the wild. On October 1, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-104286 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates.
EPSS 2.20% · 81.9th percentile
Risk Scores
EPSS Score
2.20%
81.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Versions | Versions prior to 7.4.9 | |
| Versions | Versions prior to 7.6.7 | |
| Versions | Versions prior to 8.0.2 | |
| Upgrade | Upgrade to branch 7.4 or above |
Timeline
- Oct 1, 2026 CISA KEV Added
- Oct 1, 2026 VulnCheck KEV Exploitation
- Oct 1, 2026 Coalition ESS Score
- Oct 1, 2026 CVE Published
- Oct 2, 2026 EPSS Score
- Oct 3, 2026 EPSS Score
- Oct 3, 2026 Security Advisory
References
- https://cyber.gc.ca/en/alerts-advisories/fortinet-security-advisory-av26-989 advisory
- https://www.fortiguard.com/psirt/FG-IR-26-175 vendor
- https://www.fortiguard.com/psirt?filter=1&version=&severity=5&severity=4&severity=3&severity=2 vendor
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-104286 advisory