Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes
thehackernews.com Oct 2, 2026

Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes

AI-summarised brief · reviewed before publication

The U.S. Cybersecurity and Infrastructure Security Agency added a critical flaw in Fortinet FortiMail (CVE‑2026‑104286, CVSS 9.8) to its Known Exploited Vulnerabilities catalog after reports of active attacks. The vulnerability permits unauthenticated attackers to write arbitrary files via crafted HTTP/HTTPS requests, exploiting path traversal and NULL‑byte issues. Fortinet confirmed wild exploitation and urged affected customers to apply workarounds or patches by October 4, 2026. The incident follows similar in‑the‑wild exploits on Check Point, Arista, F5, Cisco, and Citrix products.

💡 Why It Matters

  • · The flaw exposes a broad class of enterprise mail gateways to remote code execution, underscoring the urgency of patching legacy security products before attackers can deploy automated, AI‑driven intrusion tools.