Urgent.News

What's breaking now, across thousands of outlets.

Tech

Fortinet sounds the alarm over actively exploited FortiMail zero-day

No login required, exploitation underway, and some admins are still waiting for patches

Fortinet sounds the alarm over actively exploited FortiMail zero-day

Fortinet has alerted customers to urgently secure their FortiMail systems after hackers began exploiting a serious vulnerability. This flaw, known as CVE-2026-104286, allows an attacker to write files to vulnerable systems without needing to log in. The vulnerability, rated a high 9.8 on the CVSS scale, impacts various versions of Fortinet's email security platform.

An unauthenticated attacker can exploit it by sending specially designed HTTP or HTTPS requests to the system, resulting in the creation of arbitrary files that could potentially lead to the execution of malicious code or commands.

Affected versions range from 7.2.0 to 7.2.9, 7.4.0 to 7.4.8, 7.6.0 to 7.6.6, and 8.0.0 to 8.0.1. While Fortinet has not disclosed the exact timeline of when the attacks began, they have shared indicators that administrators can use to detect potential compromises, such as suspicious files, configuration changes, and specific IP addresses linked to the attacks.

The Cybersecurity and Infrastructure Security Agency (CISA) has included CVE-2026-104286 in its Known Exploited Vulnerabilities catalog, advising US federal civilian agencies to conduct forensic triage and apply mitigations by October 4. Fortinet is currently working on fixes for the different affected branches, but as of now, customers on those versions must rely on workarounds until the updates are available.

In the meantime, Fortinet suggests disabling Identity Based Encryption if it's not necessary, or alternatively, preventing the FortiMail management interface from being accessible from the internet and limiting access to trusted private networks.

This isn't the first time Fortinet has faced issues with attackers infiltrating its network appliances this year. In June, login credentials for approximately 75,000 FortiGate firewalls were discovered in the hands of cybercriminals, though Fortinet clarified that these credentials stemmed from previous incidents and brute-force attacks rather than a new breach.

Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at theregister.com →

More in Tech

More from Friday 2 October →