Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes

The Hacker News - Oct 2, 2026

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerability, tracked as CVE-2026-104286 (CVSS score: 9.8), allows unauthenticated attackers to write arbitrary files on the underlying system. "An improper

Read full article

More News

24-7 Reporters

24-7 Reporters publishes up-to-the-minute news 24 hours a day, 7 days a week. Our certified reporters are among the most experienced, well-trained and talented across the globe, covering issues resonating progressives in every corner of the world.

Sign Up