Search
Find merged stories by title or summary.
FortiMail zero-day exploited in attacks as CISA urges immediate patching
A critical zero-day vulnerability in Fortinet FortiMail is being actively exploited in the wild, prompting the US Cybersecurity and Infrastructure Security Agency (CISA) to add the flaw to its Known Exploited Vulnerabilities (KEV) catalog. Tracked as CVE-2026-104286 and rated 9. 8 (Critical) on the CVSS scale, the vulnerability allows unauthenticated attackers to write arbitrary files to … The post FortiMail zero-day exploited in attacks as CISA urges immediate patching appeared first on CyberInsider .
InfoSec News Nuggets – 10/02/2026
Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes CISA has added a critical Fortinet FortiMail vulnerability, CVE-2026-104286 (CVSS 9. 8), to its Known Exploited Vulnerabilities catalog after Fortinet confirmed in-the-wild attacks. The path traversal and NULL byte handling flaw lets an unauthenticated attacker write arbitrary files to the underlying system using crafted HTTP or HTTPS requests, and it affects FortiMail 7. 2 through 8. 0. With fixes still pending for some branches, Fortinet is urging customers to disable the IBE feature and cut off internet access to the management interface, and it has published attacker IP addresses and file-based indicators of compromise. Federal civilian agencies have until October 4 to apply patches or workarounds.
Fortinet security advisory (AV26-989)
Serial number: AV26-989 Date: October 1, 2026 As of October 1, 2026, Fortinet is affected by vulnerabilities in the following products: • FortiMail 8.0 • Versions prior to 8.0.2 • FortiMail 7.6 • Versions prior to 7.6.7 • FortiMail 7.4 • Versions prior to 7.4.9 • FortiMail 7.2 • Upgrade to branch 7.4 or above Fortinet indicates that CVE-2026-104286 is exploited in the wild. On October 1, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-104286 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply the necessary updates. • Fortinet - Improper limitation of a pathname to a restricted directory • Fortinet PSIRT Advisories • CISA KEV: CVE-2026-104286 https://cyber.gc.ca/en/alerts-advisories/fortinet-security-advisory-av26-9891post-1participantReadfulltopic
CVE-2026-104286: FortiMail Path Traversal Vulnerability Actively Exploited
Successful exploitation may let an unauthenticated attacker send a crafted request that tricks FortiMail into writing a file outside its intended folder. By placing a file onto the underlying system, the attacker gains a way to run commands on the device itself. This can lead to full control of the mail gateway, exposing stored mail, credentials, and other systems it connects to. CVE CVE-2026-104286 Affected Products FortiMail 8. 0 through 8. 0. 1 FortiMail 7. 6 through 7. 6. 6 FortiMail 7. 4 through 7. 4. 8 FortiMail 7. 2 through 7. 2. 9 Exploitation The vulnerability has been exploited in the wild[1].
Critical FortiMail zero-day exploited in the wild (CVE-2026-104286)
Fortinet is warning customers that attackers are exploiting a zero-day vulnerability (CVE-2026-104286) in FortiMail, its email security gateway. Fortinet says the flaw has been reported to be exploited in the wild, and urges customers to apply the workaround it shared until fixes are available. About CVE-2026-104286 “An Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) [CWE-22] and Improper Neutralization of NULL Byte or NULL Character [CWE-158] vulnerability may allow an unauthenticated attacker … More → The post Critical FortiMail zero-day exploited in the wild (CVE-2026-104286) appeared first on Help Net Security .
Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action
CVE-2026-104286 is a critical-severity path traversal vulnerability that could allow attackers to write arbitrary files to the system. The post Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action appeared first on SecurityWeek .
FortiMail Zero-Day CVE-2026-104286 Actively Exploited in Attacks
Fortinet is warning of active exploitation of CVE-2026-104286, a critical FortiMail zero-day that can allow unauthenticated attackers to write arbitrary files to vulnerable systems. The post FortiMail Zero-Day CVE-2026-104286 Actively Exploited in Attacks appeared first on CyberUpdates365 • Latest Cybersecurity News & Vulnerabilities .
U.S. CISA adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog
U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog. The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added a Fortinet FortiMail flaw, tracked as CVE-2026-104286 (CVSS score of 9. 8), to its Known Exploited Vulnerabilities (KEV) catalog . The flaw is a path traversal vulnerability that can be triggered through specially crafted HTTP or HTTPS requests. An unauthenticated attacker can exploit the issue to bypass restrictions on file paths and write arbitrary files to the underlying system. The vulnerability also involves improper handling of NULL characters, which can help the attacker bypass security checks. The flaw is reportedly being exploited in the wild, so affected customers are urged to apply the recommended workaround.
Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes
The U. S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerability, tracked as CVE-2026-104286 (CVSS score: 9.8), allows unauthenticated attackers to write arbitrary files on the underlying system. "An improper
Fortinet warns of critical FortiMail flaw exploited in zero-day attacks
Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices. [... ]
[Previdian] CVE-2026-104286 - Confirmed Exploitation
CVE-2026-104286 Previdian Catalog: Confirmed Status: Yes Exploited: 2026-10-01 19:38 UTC Status Updated: 1 Evidence Sources: 2026-10-01 First Seen: 2026-10-01 Asserted:
You've reached the end of current stories for this search.
