Fortinet warns of critical FortiMail flaw exploited in zero-day attacks
12 Articles
12 Articles
Fortinet warns of critical FortiMail flaw exploited in zero-day attacks
Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices. [...]
Fortinet alerts to critical day zero failure in FortiMail, with active exploitation. See affected versions, mitigation and signs of engagement.
Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware - National Cyber Security Consulting
Ravie LakshmananOct 02, 2026Vulnerability / Enterprise Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerability, tracked as CVE-2026-104286 (CVSS score: 9.8), allows unauthenticated attackers to write arbitrary files on the underlying […] Tha…
FortiMail’s Encryption Feature Was Supposed to Protect Email. It Became the Attack Vector.
A path traversal vulnerability in Fortinet FortiMail’s Identity-Based Encryption GUI component allows unauthenticated attackers to write arbitrary files on the underlying system through crafted HTTP or HTTPS requests. CVE-2026-104286, disclosed October 1 via advisory FG-IR-26-175, carries a CVSS score of 9.8. It combines CWE-22 (path traversal) with CWE-158 (improper null byte neutralization) in the management […]
Critical FortiMail zero-day exploited in the wild (CVE-2026-104286)
Fortinet is warning customers that attackers are exploiting a zero-day vulnerability (CVE-2026-104286) in FortiMail, its email security gateway. Fortinet says the flaw has been reported to be exploited in the wild, and urges customers to apply the workaround it shared until fixes are available. About CVE-2026-104286 “An Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) [CWE-22] and Improper Neutralization of NULL Byt…
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium










