Home / Oct 03, 2026 / Story
0
#1 The Hacker News general October 02, 2026 at 05:49 UTC

Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes

By [email protected] (The Hacker News)

AI Summary

CISA added CVE-2026-104286 (CVSS 9.8) in Fortinet FortiMail to its Known Exploited Vulnerabilities catalog following confirmed active exploitation. The critical path traversal flaw allows unauthenticated attackers to write arbitrary files to the underlying system, making immediate patching essential for all FortiMail deployments.

Relevance score: 92.0/100

# More from October 03