Critical CVE-2026-104286, CVE-2025-25249, CVE-2025-68686, CVE-2026-25089, CVE-2026-39808 — Five Fortinet vulnerabilities joined CISA's exploited list between July and October 2026, led by an unauthenticated FortiMail file-write bug (CVSS 9.8). Affected versions and what FortiGate, FortiMail and FortiSandbox owners should do.
Published 2026-10-08 · Last updated 2026-10-08
TL;DR: FortiGate firewalls are everywhere in small and mid-size businesses, and Fortinet gear keeps landing on CISA's exploited list. The newest, CVE-2026-104286 (Oct 1), lets an unauthenticated attacker write files on FortiMail. FortiOS has a heap overflow (CVE-2025-25249) and a bypass that keeps earlier attackers' backdoors alive (CVE-2025-68686). Upgrade to the current release on your branch and check for persistence.
| CVE-2026-104286 | FortiMail path traversal → unauthenticated arbitrary file write. CVSS 9.8. KEV 2026-10-01 |
|---|---|
| CVE-2025-25249 | FortiOS / FortiSwitchManager heap overflow via crafted packets → code execution. CVSS 7.4. KEV 2026-09-09 |
| CVE-2025-68686 | FortiOS info exposure that bypasses the fix for the symlink backdoor. CVSS 5.3. KEV 2026-07-27 |
| CVE-2026-25089 / 39808 | FortiSandbox OS command injection. CVSS 9.1. KEV 2026-07-16 |
| Fix | Upgrade to a release newer than the affected ranges below (see each FortiGuard advisory) |
| CVE | Product | Affected versions (per Fortinet) |
|---|---|---|
| CVE-2026-104286 | FortiMail | 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8, 7.2.0–7.2.9 |
| CVE-2025-25249 | FortiOS, FortiSwitchManager | FortiOS 7.6.0–7.6.3, 7.4.0–7.4.8, 7.2.0–7.2.11, 7.0.0–7.0.17, all 6.4; FortiSwitchManager 7.2.0–7.2.6, 7.0.0–7.0.5 |
| CVE-2025-68686 | FortiOS | 7.6.0–7.6.1, 7.4.0–7.4.6, all 7.2, all 7.0, all 6.4 |
| CVE-2026-25089 | FortiSandbox | 5.0.0–5.0.5, 4.4.0–4.4.8, all 4.2; Cloud/PaaS 5.0.4–5.0.5 |
| CVE-2026-39808 | FortiSandbox | 4.4.0–4.4.8 |
CVE-2025-68686 needs a closer look. In earlier Fortinet incidents, attackers who got in planted a symbolic link that kept read access to the device’s files even after it was patched. Fortinet removed that backdoor in an update; this CVE is a way around that fix. It only helps an attacker who has already compromised the device, so if your FortiGate was ever exposed on an old version, assume the backdoor may still be there until you’re on a fixed release.
Note that FortiOS 7.2, 7.0 and 6.4 are listed as affected in all versions for CVE-2025-68686. Upgrading to a supported branch is the fix.
get system status # FortiOS / FortiMail / FortiSandbox CLI: shows the version
Compare against the table. If you manage multiple devices through FortiManager or FortiCloud, the firmware column there gives you the whole fleet at once.
execute backup config), upgrade, and confirm with get system status.diagnose sys config-log / the event logs).Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.