The Register

Fortinet sounds the alarm over actively exploited FortiMail zero-day

VulnerabilityCriticalCVE-2026-104286email security

Fortinet disclosed a critical zero-day vulnerability in FortiMail email security platform being actively exploited. The CVE-2026-104286 flaw allows unauthenticated attackers to write files to vulnerable systems via path traversal and improper null character handling, affecting multiple FortiMail versions.

AI summary · generated with Claude

https://www.theregister.com/security/2026/10/02/fortinet-sounds-the-alarm-over-actively-exploited-fortimail-zero-day/5300803