ConciseSignal
Following

Fortinet warns of critical FortiMail zero-day under active attack

Fortinet has disclosed a critical vulnerability in its FortiMail appliances, identified as CVE-2026-104286, which attackers are actively exploiting in zero-day attacks. The flaw, affecting multiple FortiMail versions, allows unauthenticated attackers to write files on compromised systems through crafted web requests. Fortinet recommends immediate workarounds, as fixes for many versions are not yet available. Customers are urged to restrict management interface access and disable specific features to reduce risk.

Why it mattersThe vulnerability exposes enterprise mail systems to remote attacks without authentication, posing a risk of further system compromise and data theft. Organizations using affected FortiMail versions may be vulnerable until full patches are released.

Sources covering this

BleepingComputerFortinet warns of critical FortiMail flaw exploited in zero-day attacks10:42 PM →The Hacker NewsCritical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes5:49 AM →SecurityWeekHeadline onlyExploited Fortinet FortiMail Zero-Day Calls for Urgent Action8:07 AM →The RegisterHeadline onlyFortinet sounds the alarm over actively exploited FortiMail zero-day10:53 AM →

How it unfolded

  • BleepingComputer Fortinet warns of critical FortiMail flaw exploited in zero-day attacks
  • The Hacker News Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes
  • SecurityWeek Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action
  • The Register Fortinet sounds the alarm over actively exploited FortiMail zero-day
Concise Signal DailyEnterprise AI, security & business tech.Weekdays, 7am Eastern · Sample issue

More in Cybersecurity