Desert Forge IT — Arizona IT · Field-tested tools & guidesFree consult →

Fortinet Exploited CVEs 2026: FortiMail CVE-2026-104286, FortiOS, FortiSandbox

Critical CVE-2026-104286, CVE-2025-25249, CVE-2025-68686, CVE-2026-25089, CVE-2026-39808 — Five Fortinet vulnerabilities joined CISA's exploited list between July and October 2026, led by an unauthenticated FortiMail file-write bug (CVSS 9.8). Affected versions and what FortiGate, FortiMail and FortiSandbox owners should do.

Published 2026-10-08 · Last updated 2026-10-08

TL;DR: FortiGate firewalls are everywhere in small and mid-size businesses, and Fortinet gear keeps landing on CISA's exploited list. The newest, CVE-2026-104286 (Oct 1), lets an unauthenticated attacker write files on FortiMail. FortiOS has a heap overflow (CVE-2025-25249) and a bypass that keeps earlier attackers' backdoors alive (CVE-2025-68686). Upgrade to the current release on your branch and check for persistence.

CVE-2026-104286FortiMail path traversal → unauthenticated arbitrary file write. CVSS 9.8. KEV 2026-10-01
CVE-2025-25249FortiOS / FortiSwitchManager heap overflow via crafted packets → code execution. CVSS 7.4. KEV 2026-09-09
CVE-2025-68686FortiOS info exposure that bypasses the fix for the symlink backdoor. CVSS 5.3. KEV 2026-07-27
CVE-2026-25089 / 39808FortiSandbox OS command injection. CVSS 9.1. KEV 2026-07-16
FixUpgrade to a release newer than the affected ranges below (see each FortiGuard advisory)

What’s affected

CVEProductAffected versions (per Fortinet)
CVE-2026-104286FortiMail8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8, 7.2.0–7.2.9
CVE-2025-25249FortiOS, FortiSwitchManagerFortiOS 7.6.0–7.6.3, 7.4.0–7.4.8, 7.2.0–7.2.11, 7.0.0–7.0.17, all 6.4; FortiSwitchManager 7.2.0–7.2.6, 7.0.0–7.0.5
CVE-2025-68686FortiOS7.6.0–7.6.1, 7.4.0–7.4.6, all 7.2, all 7.0, all 6.4
CVE-2026-25089FortiSandbox5.0.0–5.0.5, 4.4.0–4.4.8, all 4.2; Cloud/PaaS 5.0.4–5.0.5
CVE-2026-39808FortiSandbox4.4.0–4.4.8

CVE-2025-68686 needs a closer look. In earlier Fortinet incidents, attackers who got in planted a symbolic link that kept read access to the device’s files even after it was patched. Fortinet removed that backdoor in an update; this CVE is a way around that fix. It only helps an attacker who has already compromised the device, so if your FortiGate was ever exposed on an old version, assume the backdoor may still be there until you’re on a fixed release.

Note that FortiOS 7.2, 7.0 and 6.4 are listed as affected in all versions for CVE-2025-68686. Upgrading to a supported branch is the fix.

Am I affected?

get system status        # FortiOS / FortiMail / FortiSandbox CLI: shows the version

Compare against the table. If you manage multiple devices through FortiManager or FortiCloud, the firmware column there gives you the whole fleet at once.

How to patch

  1. Check the FortiGuard advisory for your product (linked below) for the exact fixed build on your branch, and use Fortinet’s upgrade path tool. FortiOS often requires stepping through intermediate versions.
  2. Back up the config (execute backup config), upgrade, and confirm with get system status.
  3. On FortiOS, confirm the symlink cleanup ran: after upgrading to a fixed version, the device removes known malicious symlinks from the SSL-VPN language-file area automatically.

Reduce exposure

  • Never expose the management interface (HTTPS/SSH admin) to the internet. Restrict it with trusted hosts on each admin account and with local-in policies.
  • FortiMail’s web interface should only be reachable from where admins and webmail users actually are.
  • If you don’t use SSL-VPN, disable it. Fortinet has moved many customers to IPsec for this reason.

Check for compromise

  • Review admin accounts, local users and recent config changes (diagnose sys config-log / the event logs).
  • On FortiMail, look for unfamiliar files in the web root and unexpected mail rules or forwarding addresses.
  • If a device was exposed on a vulnerable version, Fortinet’s guidance for confirmed compromise is a clean firmware reinstall, a reviewed config restore, and rotation of all credentials and VPN secrets.

Sources

← Back to Knowledge Base

Want this handled for you?

Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.

Get a free security check →  ·  More security advisories