
Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes
What Happened?
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerability, tracked as CVE-2026-104286 (CVSS score: 9.8), allows unauthenticated attackers to write arbitrary files on the underlying system. "An improper...
Why It Matters
The implications of this cybersecurity update are significant for digital infrastructure in Tier-1 nations. Experts suggest that such developments could influence both consumer behavior and enterprise-level security protocols in the US, UK, CA, and AU markets.
Key Takeaways
- 1A critical security flaw in Fortinet FortiMail has been added to CISA's Known Exploited Vulnerabilities catalog. The vulnerability allows unauthenticated attackers to write arbitrary files to the system. This flaw is being actively exploited.
Summary written with AI from the story's source text.
Get the News Era newsletter
The most important tech and cybersecurity stories, delivered to your inbox. Free, and you can unsubscribe at any time.