← Back to the feed

~/article/critical-fortimail-zero-day-flaw-exploited-in-attacks-allows-unauthentic-1uz8eo
criticalSource: The Hacker News

Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerability, tracked as CVE-2026-104286 (CVSS score: 9.8), allows unauthenticated attackers to write arbitrary files on the underlying system. "An improper

Read at the source

Summary written for cymesh.dev. The full article lives at The Hacker News.

Referenced CVEs

~/cymesh.net

This is what cymesh.net is for

Certificate and hostname problems are the ones you find out about from your users. cymesh.net finds them first.

monitorsTLS/SSL expiry, chain and hostnamealertsemail, ahead of the expiry datescopenon-intrusive, read-only checks

Related

~/related/critical-fortimail-zero-day-flaw-exploited-in-attacks-allows-unauthentic-1uz8eo