HackerFeeds

CyberSecurity News

Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes

The Hacker News
· October 2, 2026

AI summary

A critical security flaw in Fortinet FortiMail is being actively exploited in attacks, prompting the US Cybersecurity and Infrastructure Security Agency to add it to its Known Exploited Vulnerabilities catalog. The vulnerability allows unauthenticated attackers to write arbitrary files on the underlying system. It has a high CVSS score of 9.8, indicating a severe impact. The issue is related to improper handling of certain operations. The vulnerability is identified as CVE-2026-104286. Active exploitation of this flaw has been reported, posing a significant risk to affected systems.

Vulnerabilities mentioned

Read the full article at The Hacker Newsthehackernews.com/2026/10/critical-fortimail-zero-day-flaw.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.