Posts tagged with “fortinet”

FortiMail CVE-2026-104286 zero-day exploited in attacks

Fortinet has disclosed a critical vulnerability in FortiMail, its email security appliance. Attackers are already exploiting it in the wild to run unauthorized code or commands on exposed devices. The flaw is tracked as CVE-2026-104286, carries a CVSS score of 9.8, and sits in the product's management interface.

Patches are not yet out for most affected branches. For now, many administrators can only rely on workarounds.

How the flaw works

In its advisory, published Thursday, Fortinet describes the bug as a combination of two weaknesses. The first is a path traversal issue (CWE-22). The second is improper handling of NULL bytes or NULL characters (CWE-158). Together, they may let an attacker with no credentials write arbitrary files to the underlying system by sending specially crafted HTTP or HTTPS requests.

Read More