negativeSYS.SOURCE: The Hacker News• 2026-10-02T11:19:50+05:30
Critical FortiMail Zero-Day Vulnerability (CVE-2026-104286) Enables Unauthenticated Arbitrary File Writes
A critical zero-day vulnerability in Fortinet FortiMail (CVE-2026-104286) allows unauthenticated attackers to write arbitrary files, leading to potential system compromise. CISA has added it to the KEV catalog, with patches and workarounds recommended for affected versions.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation.
The vulnerability, tracked as CVE-2026-104286 (CVSS score: 9.8), allows unauthenticated attackers to write arbitrary files on the underlying system.
"An improper
*** END OF TRANSMISSION ***