Today Fortinet updated its FortiMail advisory. The PSIRT page now shows Updated Date October 5, 2026, and a timeline line reading Solution update. The named fixes are no longer labeled upcoming. The flaw is still CVE-2026-104286 — the same one from the October 2 briefing — scored 9.8, marked known exploited, with no virtual patch. Fortinet still says the issue has been reported exploited in the wild and still urges the workaround while you get the build on.

If that email gateway is yours, install the fixed release on your train: 8.0.2 or above, 7.6.7 or above, or 7.4.9 or above. On Fortinet’s table, 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, and 7.4.0 through 7.4.8 are still affected. Do not treat a jump from 7.2 onto an unpatched 7.4 build as done. Keep the workaround until you are sure the fixed build is running: turn IBE off, or keep the FortiMail webmail interface off the open internet and allow only a trusted private network. Installing the build does not tell you whether someone already wrote files. Fortinet’s hunt hints still include an archive account named archive234 and remote IPs 79.141.169.187 and 45.129.0.192. People who do not run FortiMail have nothing to change.

A separate note, not a password reset. Google paused new product-vulnerability submissions to its open-source bug bounty after a flood of AI junk reports, per Monday’s writeups of a Sunday announcement. Supply-chain reports under that program still work, and submissions filed before October 1 are unaffected. Google says it will share an update in Q1 2027. Nothing reported here says Gmail, Android, or Workspace passwords were taken over. Do not reset a Google password because of a bug-bounty process change.