InfoSec News Nuggets – 10/02/2026
Brief
Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes
CISA has added a critical Fortinet FortiMail vulnerability, CVE-2026-104286 (CVSS 9. 8), to its Known Exploited Vulnerabilities catalog after Fortinet confirmed in-the-wild attacks. The path traversal and NULL byte handling flaw lets an unauthenticated attacker write arbitrary files to the underlying system using crafted HTTP or HTTPS requests, and it affects FortiMail 7. 2 through 8.
- With fixes still pending for some branches, Fortinet is urging customers to disable the IBE feature and cut off internet access to the management interface, and it has published attacker IP addresses and file-based indicators of compromise. Federal civilian agencies have until October 4 to apply patches or workarounds.
