Yesterday Fortinet published an advisory for FortiMail, and CISA added it to the known-exploited catalog the same day. Fortinet’s sentence: an unauthenticated attacker can write files onto the system. Fortinet says this has been reported exploited and does not name an attacker or how many customers were hit. The flaw is CVE-2026-104286. Fortinet scores it 9.8. CISA lists ransomware use as unknown. Federal civilian agencies are due Sunday, October 4. That date is in the catalog, not on CISA’s alert page.
If that email gateway is yours, there is no fixed release to install yet. Fortinet labels the fixes upcoming: 8.0.2, 7.6.7, and 7.4.9. On Fortinet’s table, 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, and 7.4.0 through 7.4.8 are still affected. Do not treat a current 7.4 install as the fix, and do not treat a move from 7.2 onto today’s 7.4 build as done. Until a fixed release exists, do one of the two things on the advisory: turn IBE off under Encryption, IBE, IBE Service, or stop the management page from being reachable on the internet and allow only a trusted private network. Those are alternatives, not a suggestion to do neither. Turning the workaround on does not tell you whether someone already wrote files. Fortinet says to look for an archive account named archive234, remote IP 79.141.169.187, remote directory /uploads, and a second IP, 45.129.0.192. People who do not run FortiMail have nothing to change.
A separate note, not a work-login reset. Yesterday Microsoft’s account on X followed a Clippy cryptocurrency account, reposted it, and changed its picture to Clippy. Spokesperson Brent Colburn said the access was unauthorized, those posts did not come from Microsoft, and the account has been secured. Nothing reported here says a Microsoft 365 or work login was involved. Do not buy the token, do not connect a wallet, and do not reset a work password because of this.