Skip to main content
See every side of every news story
Published • loading... • Updated

Fortinet warns of critical FortiMail flaw exploited in zero-day attacks

Fortinet said the 9.8-rated flaw lets unauthenticated attackers write files on affected FortiMail appliances and could enable code execution.

  • Fortinet warned customers of a critical vulnerability, CVE-2026-104286, currently being exploited in the wild with a CVSS score of 9.8 that allows unauthenticated attackers to write arbitrary files via HTTP or HTTPS requests.
  • The vulnerability stems from path traversal and improper null character handling in FortiMail's web interface, affecting versions 8.0, 7.6, 7.4, and 7.2 and potentially enabling code execution on affected appliances.
  • CISA added CVE-2026-104286 to its Known Exploited Vulnerabilities catalog, directing US federal civilian agencies to apply mitigations by October 4; Fortinet lists fixes as "upcoming," leaving customers reliant on workarounds.
  • Administrators must check for signs of compromise, including suspicious files and configuration changes, because applying workarounds will not remove existing persistence mechanisms attackers may have planted.
  • This incident follows other security challenges for Fortinet this year; in June, credentials linked to around 75,000 FortiGate firewalls surfaced, though Fortinet attributed the data to brute-force attacks rather than a fresh breach.
Insights by Ground AI

17 Articles

The INCIBE-CERT has warned of a critical vulnerability in FortiMail de Fortinet that the attackers are actively exploiting. The alert, published on Friday, October 2, 2026 with the INCIBE-2026-692 identifier, affects one of the most widely used email gateways by companies and public administrations. The bug allows an unauthenticated remote attacker to write arbitrary files on the affected system and, from there, execute unauthorized code or comm…

Read Full Article
Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 80% of the sources are Center
80% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

BleepingComputer broke the news in Melville, United States on Thursday, October 1, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal