Fortinet is warning customers to lock down FortiMail after attackers started exploiting a critical bug that lets them write files to vulnerable systems without logging in. The flaw, tracked as CVE-2026-104286, carries a CVSS score of 9.8 and affects multiple versions of Fortinet's email security platform. Fortinet describes the vulnerability as a combination of path traversal and improper handling of null characters in FortiMail's web interface.
Fortinet sounds the alarm over actively exploited FortiMail zero-day
About this summary. This is a short, independently written summary of an article first published by The Register. Cyber Security News did not report or verify the underlying story. Read the original: https://www.theregister.com/security/2026/10/02/fortinet-sounds-the-alarm-over-actively-exploited-fortimail-zero-day/5300803

Source attribution: headline and facts are from The Register (theregister.com). Summary method: excerpt of the source description. See our source attribution policy.





