• Login
teqpost
  • Home
  • Hardware
  • Gaming
  • Gadgets
  • AI
  • Software
  • Security
  • Policy
No Result
View All Result
teqpost
  • Home
  • Hardware
  • Gaming
  • Gadgets
  • AI
  • Software
  • Security
  • Policy
No Result
View All Result
teqpost
No Result
View All Result

Home / Security / Fortinet warns of critical FortiMail zero-day flaw

Fortinet warns of critical FortiMail zero-day flaw

byLotfi Ben Taleb
October 2, 2026
in Security
Reading Time: 2 mins read
Close-up of a clear RJ45 Ethernet connector on a cable against a cyan background
Share on Facebook
Share on Twitter

Fortinet is warning customers about a critical FortiMail zero-day flaw that lets unauthenticated attackers write arbitrary files to vulnerable systems. The vulnerability, tracked as CVE-2026-104286, carries a CVSS score of 9.8. CISA has added it to its Known Exploited Vulnerabilities catalog after confirming active exploitation.

FortiMail sits at the edge of the mail flow, inspecting inbound and outbound messages for spam, phishing and malware, which usually means its management interface is reachable from outside the network it protects. An attacker who can write files to that interface is one step from running code on a system with visibility into every message crossing the gateway, which is what makes this flaw worth treating as urgent rather than routine patch-cycle work.

How the FortiMail zero-day flaw bypasses authentication

Fortinet describes the bug as a combination of path traversal and improper handling of null characters in FortiMail’s web interface. Path traversal lets a request escape the directory a web application expects to write into, climbing back up the filesystem with sequences like ../. Pairing that with null-character handling is an older trick: file-handling code can treat a null byte as a string terminator, letting an attacker smuggle a different path or extension past a check that only read the string up to that point.

Combined, the two issues give an attacker enough control to place a file exactly where they want it on the appliance, using nothing more than a specially crafted HTTP or HTTPS request and no credentials at all. Writing to the right location is enough to execute code or commands, which is what turns a file-write bug into full device compromise.

The flaw affects FortiMail versions 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9. That spread covers every maintained branch of the product, so version-pinning isn’t a workaround: anyone running FortiMail needs to check their build number against Fortinet’s advisory directly rather than assume an older release is safe.

What CISA’s KEV listing adds, and what’s still missing

CISA’s Known Exploited Vulnerabilities catalog is reserved for flaws with confirmed real-world exploitation, and CVE-2026-104286 was added to it this week. Fortinet’s own advisory states that the vulnerability “is being exploited in the wild,” but stops there: it gives no date for when the attacks started, no attribution, and no count of how many customers have been hit, as The Register noted. For admins deciding how urgently to patch, that gap matters: a flaw exploited by one opportunistic actor against a handful of targets calls for a different response than one already being used at scale.

Another appliance zero-day joins a crowded list

FortiMail joins a run of perimeter and email security appliances that have taken the same path this year: a vendor advisory followed within days by a CISA KEV listing. Citrix confirmed two NetScaler zero-days under active attack earlier this year, and the pattern repeats: an internet-facing management interface, unauthenticated exploitation, and a scramble to patch before a public proof-of-concept arrives.

If a FortiMail instance exposes its web interface to anything beyond a restricted management network, that exposure is the thing to close this week, not just the software version. Patching clears the specific bug; it does nothing about the next one if the interface is still sitting on the open internet.

Tags: vulnerability
Previous Post

Nvidia cuts DGX Spark price with 64GB model at $4,999

Next Post

Samsung launches Galaxy Buds On, its first clip-on earbuds

Related Posts

Tangled colored network patch cables running into a server rack panel
Security

Citrix confirms two NetScaler zero-days under active attack

September 28, 2026
Rows of blue-lit server hard drive caddies in a data center rack
Security

ShinyHunters bypass WAFs to exploit Oracle PeopleSoft flaw

September 27, 2026
Rendered illustration of a data center corridor lined with server racks showing blue status lights
Security

WSO2 and Adobe Commerce flaws land on CISA’s exploited list

September 26, 2026
0 0 votes
Article Rating
Subscribe
Notify of
0 Comments

Popular News

Three Samsung phone backs side by side, green with many cameras, purple and cream with three cameras

Galaxy S27 renders show a design split from the Ultra

October 1, 2026
Close-up of an iPhone's glass back and dual rear camera lenses lit from above

iPhone Duo 3D model lets you open the hinge before launch

September 20, 2026
A Radeon graphics card installed in a PC case, lit by green and blue ambient light

Modders get DLSS 5 running on AMD’s RDNA 4 GPUs

September 7, 2026
Close-up of a GeForce RTX graphics card installed in a PC case with a blurred power cable bundle

DLSS 5 mods expose RTX 5090’s power connector limit

September 27, 2026
Next Post
Black Samsung earbuds charging case with white Samsung logo, closed, on a gray surface

Samsung launches Galaxy Buds On, its first clip-on earbuds

Technology for enthusiasts and gamers. Hardware, gaming and the software in between, with the spec sheets read properly and the marketing taken back out.

Categories

Categories

  • AI
  • Gadgets
  • Gaming
  • Hardware
  • Policy
  • Security
  • Software
Site Links
  • Latest
  • About
  • Contact
About
  • How We Work
  • Privacy Policy

© 2026 teqpost. All rights reserved.

  • Privacy Policy
  • Contact

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Hardware
  • Gaming
  • Gadgets
  • AI
  • Software
  • Security
  • Policy

© 2026 JNews - Premium WordPress news & magazine theme by Jegtheme.

wpDiscuz
0
0
Would love your thoughts, please comment.x
()
x
| Reply