#1
The Hacker News
general
October 02, 2026 at 05:49 UTC
Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes
By [email protected] (The Hacker News)
AI Summary
CISA added CVE-2026-104286 (CVSS 9.8) in Fortinet FortiMail to its Known Exploited Vulnerabilities catalog following confirmed active exploitation. The critical path traversal flaw allows unauthenticated attackers to write arbitrary files to the underlying system, making immediate patching essential for all FortiMail deployments.
Relevance score: 92.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →