Security

Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes

CISA adds a critical Fortinet FortiMail vulnerability to its Known Exploited Vulnerabilities catalog after reports of active attacks. Tracked as CVE-2026-104286 with a CVSS score of 9.8, the flaw lets unauthenticated attackers write arbitrary files on the system.

Image: The Hacker News

Why it matters

Organizations using FortiMail face an actively exploited flaw that permits unauthenticated file writes. Its inclusion in CISA’s KEV catalog makes it a high-priority issue for security teams.

Coverage 1 publisher

  1. The Hacker News

    Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes

Articles stay on their publishers’ sites; each link opens the original.