thehackernews.com
Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes
The U.S. Cybersecurity and Infrastructure Security Agency added a critical flaw in Fortinet FortiMail (CVE‑2026‑104286, CVSS 9.8) to its Known Exploited Vulnerabilities catalog after reports of active attacks. The vulnerability permits unauthenticated attackers to write arbitrary files via crafted HTTP/HTTPS requests, exploiting path traversal and NULL‑byte issues. Fortinet confirmed wild exploitation and urged affected customers to apply workarounds or patches by October 4, 2026. The incident follows similar in‑the‑wild exploits on Check Point, Arista, F5, Cisco, and Citrix products. [...]