Back to all news
Security

Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes

The Hacker News·October 2, 2026·1 min read
Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes

CISA added Fortinet FortiMail flaw CVE-2026-104286 to its Known Exploited Vulnerabilities catalog on Thursday after reports of active exploitation. The critical vulnerability, rated CVSS 9.8, allows unauthenticated attackers to write arbitrary files on the underlying system. Fortinet has not yet released a patch, and CISA urges organizations to apply mitigations or discontinue use until fixes are available.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store