Fortinet warns of critical FortiMail zero-day under active attack
Fortinet has disclosed a critical vulnerability in its FortiMail appliances, identified as CVE-2026-104286, which attackers are actively exploiting in zero-day attacks. The flaw, affecting multiple FortiMail versions, allows unauthenticated attackers to write files on compromised systems through crafted web requests. Fortinet recommends immediate workarounds, as fixes for many versions are not yet available. Customers are urged to restrict management interface access and disable specific features to reduce risk.
- Critical flaw lets attackers write arbitrary files
- Actively exploited in attacks, CISA added to KEV catalog
- Affects FortiMail versions 7.2 to 8.0.1
- No patches for most versions yet, workarounds issued
Sources covering this
How it unfolded
- BleepingComputer Fortinet warns of critical FortiMail flaw exploited in zero-day attacks
- The Hacker News Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes
- SecurityWeek Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action
- The Register Fortinet sounds the alarm over actively exploited FortiMail zero-day
More in Cybersecurity
Police arrest alleged 16-year-old leader of KillSec ransomware group
An international law enforcement operation has arrested a 16-year-old suspected of leading the KillSec ransomware gang, seized its leak…
Microsoft's X account compromised to promote crypto scam
Unknown attackers took control of Microsoft's official X account, which has over 13 million followers, to promote a fraudulent…
New device claims to freeze iPhones to bypass Apple security
A leaked video shows Magnet Forensics, seller of the popular GrayKey hacking tool, claiming its new device can bypass Apple's 72-hour…
Sapphire issues security firmware update for Radeon RX 7000 GPUs
Sapphire has released a security-focused firmware update for all its AMD Radeon RX 7000 series desktop graphics cards.