RC RANDOM CHAOS

Fortinet Warns of Zero-Day Attacks Exploiting Critical FortiMail Flaw

· via BleepingComputer

Original source

Fortinet warns of critical FortiMail flaw exploited in zero-day attacks

BleepingComputer →

Fortinet has disclosed a critical vulnerability (CVE-2026-104286) in its FortiMail email security system that is being actively exploited in zero-day attacks. The flaw, rated 9.8 on the CVSS scale, allows unauthenticated attackers to execute arbitrary code or commands by writing files to the system via crafted HTTP/HTTPS requests. The vulnerability affects multiple versions of FortiMail, and Fortinet has urged customers to apply workarounds until patches are available. Mitigation steps include disabling the IBE feature or restricting access to the management interface. Fortinet has also shared indicators of compromise, including IP addresses and log entries, to help administrators identify compromised systems.

Read the full article

Continue reading at BleepingComputer →

This is an AI-generated summary. Read the original for the full story.