{
  "id": 11430041,
  "title": "Fortinet sounds the alarm over actively exploited FortiMail zero-day",
  "url": "https://urgent.news/2026/10/02/fortinet-sounds-the-alarm-over-actively-exploited-fortimail-zero-day",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-02T10:53:49.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/security/2026/10/02/fortinet-sounds-the-alarm-over-actively-exploited-fortimail-zero-day/5300803"
  },
  "original_language": "en",
  "account": "Fortinet has issued a warning to its customers regarding FortiMail, urging them to bolster security measures following the discovery of a critical flaw that is already being exploited by attackers. The vulnerability, designated as CVE-2026-104286, carries a high CVSS score of 9.8 and impacts various versions of the email security platform. This flaw, a combination of path traversal and improper null character handling in FortiMail's web interface, enables unauthenticated attackers to write arbitrary files to the system via specially crafted HTTP or HTTPS requests. This could allow the attacker to execute arbitrary code or commands on the appliance. Fortinet has identified multiple affected versions, ranging from 7.2.0 to 8.0.1. While the source material does not specify when the attacks commenced or the perpetrators behind them, the vendor has published indicators to assist administrators in detecting suspicious activity on their systems. These indicators include unusual files and configuration changes, along with specific IP addresses linked to the attacks. The Computer Security Incident Response Team (CISA) has further escalated the matter by incorporating CVE-2026-104286 into its Known Exploited Vulnerabilities catalog, mandating US federal civilian agencies to conduct forensic triage and implement mitigations by October 4. Fortinet has stated that patches for several affected branches are forthcoming, but customers on those versions will need to rely on temporary workarounds until the official updates are released. In the interim, Fortinet suggests disabling Identity Based Encryption, if not essential, and preventing the FortiMail management interface from being accessible from the internet. Instead, it advises restricting access to trusted private networks. Administrators are advised to scrutinize their systems for signs of compromise, as the application of a workaround will not eliminate any files or persistence mechanisms that attackers may have already established. This incident is not Fortinet's first encounter with malicious actors infiltrating its network appliances; in June, credentials belonging to approximately 75,000 FortiGate firewalls were unearthed by cybercriminals. However, Fortinet clarified that the data originated from earlier incidents and brute-force attacks rather than a recent breach.",
  "summary": "No login required, exploitation underway, and some admins are still waiting for patches",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 3,
    "also_reported_by": [
      {
        "outlet": "SecurityWeek",
        "title": "Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action",
        "url": "https://urgent.news/2026/10/02/exploited-fortinet-fortimail-zero-day-calls-for-urgent-action",
        "published": "2026-10-02T08:07:33.000Z"
      },
      {
        "outlet": "The Register",
        "title": "Fortinet sounds the alarm over actively exploited FortiMail zero-day",
        "url": "https://urgent.news/2026/10/02/fortinet-sounds-the-alarm-over-actively-exploited-fortimail-zero-day-11432085",
        "published": "2026-10-02T10:53:49.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}