Ethical Hacking News
A critical vulnerability has been discovered in Fortinet's FortiMail, allowing unauthenticated attackers to write arbitrary files on the underlying system. The vulnerability has been rated at a CVSS score of 9.8 and has been actively exploited in the wild. Enterprises must apply workarounds and patches as soon as possible to prevent potential damage. Stay informed and up-to-date on the latest security threats and vulnerabilities to ensure the protection of your organization's assets.
The cybersecurity landscape has been hit with a critical vulnerability in Fortinet's FortiMail, rated at a CVSS score of 9.8. The vulnerability is related to improper pathname limitations and neutralization of NULL bytes, allowing unauthenticated attackers to write arbitrary files. The vulnerability is present in various versions of FortiMail, including 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9. The exploitation of this vulnerability has already been observed in the wild, with Fortinet acknowledging active exploitation. Fortinet has urged customers to apply workarounds until patches are available, including disabling IBE feature support and restricting access to the FortiMail management interface. The discovery of this vulnerability is attributed to Gwendal Guégniaud, a member of Fortinet's Product Security team. Various government agencies have issued alerts and advisories in response to the active exploitation of this vulnerability. This vulnerability highlights the importance of regular vulnerability assessments and patch management, as well as robust security controls.
The cybersecurity landscape has recently been hit with a critical vulnerability in Fortinet's FortiMail, leaving enterprises vulnerable to unauthenticated arbitrary file writes. The vulnerability, identified as CVE-2026-104286, has been rated at a CVSS score of 9.8, indicating a high level of severity and impact.
According to a recent advisory issued by Fortinet, the vulnerability is related to improper pathname limitations and neutralization of NULL bytes. This allows unauthenticated attackers to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. The vulnerability is present in various versions of FortiMail, including 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9.
The exploitation of this vulnerability has already been observed in the wild, with Fortinet acknowledging that the vulnerability has been actively exploited by attackers. In light of this, Fortinet has urged customers to apply workarounds until patches are available. These workarounds include disabling the IBE feature support using a CLI command and restricting access to the FortiMail management interface from the internet or from trusted private networks.
The discovery of this vulnerability is attributed to Gwendal Guégniaud, a member of Fortinet's Product Security team. Guégniaud's team has shared indicators of compromise, including IP addresses, files, and modified configuration files, which can help organizations identify potential vulnerabilities.
In response to the active exploitation of this vulnerability, various government agencies have issued alerts and advisories. For example, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, urging Federal Civilian Executive Branch (FCEB) agencies to apply the patch or workarounds by October 4, 2026.
This vulnerability highlights the importance of regular vulnerability assessments and patch management. It also underscores the need for enterprises to maintain robust security controls, including access restrictions, monitoring, and incident response. As more security flaws are discovered, it is essential for organizations to stay vigilant and proactive in addressing potential vulnerabilities.
In recent weeks, several other high-profile vulnerabilities have been disclosed, including those in Check Point, Arista VeloCloud Orchestrator, F5 BIG-IP Access Policy Manager, Cisco Catalyst SD-WAN Manager, and Citrix NetScaler ADC and NetScaler Gateway. These vulnerabilities have also been actively exploited in the wild, highlighting the ongoing threat landscape and the need for enterprises to prioritize security.
The discovery of this vulnerability serves as a reminder of the importance of staying informed and up-to-date on the latest security threats and vulnerabilities. Organizations must remain vigilant and proactive in addressing potential vulnerabilities, and ensure that their security controls are robust and effective.
Related Information:
https://www.ethicalhackingnews.com/articles/Critical-Fortinet-Vulnerability-Exposed-Leaving-Enterprises-Vulnerable-to-Unauthenticated-File-Writes-ehn.shtml
https://thehackernews.com/2026/10/critical-fortimail-zero-day-flaw.html
https://nvd.nist.gov/vuln/detail/CVE-2026-104286
https://www.cvedetails.com/cve/CVE-2026-104286/
Published: Fri Oct 2 01:37:11 2026 by llama3.2 3B Q4_K_M