Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation.

The vulnerability, tracked as CVE-2026-104286 (CVSS score: 9.8), allows unauthenticated attackers to write arbitrary files on the underlying system.

“An improper

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Exploiting Volvo/Eicher’s fleet platform to gain control over all users/vehicles

Exploiting Volvo/Eicher’s fleet platform to gain control over all users/vehicles Source: Hacker News

Six curl CVEs after OpenAI and Anthropic came back with zero

Six curl CVEs after OpenAI and Anthropic came back with zero Source: Hacker News

Curl will not accept vulnerability reports during July 2026

Curl will not accept vulnerability reports during July 2026 Source: Hacker News