Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation.

The vulnerability, tracked as CVE-2026-104286 (CVSS score: 9.8), allows unauthenticated attackers to write arbitrary files on the underlying system.

“An improper

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Why older tech is sometimes safer from hackers

Why older tech is sometimes safer from hackers Source: Hacker News

Greg Kroah-Hartman – Security in the LLM Age [video]

Greg Kroah-Hartman – Security in the LLM Age Source: Hacker News

Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers’ Data It Said Was Deleted

Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers’ Data It Said Was Deleted Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted