CRITICALZero Day
Global

Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes

·Source: The Hacker News

Updated:

Executive Summary

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerability, tracked as CVE-2026-104286 (CVSS score: 9.8), allows unauthenticated attackers to write arbitrary files on the underlying system. "An improper

Analysis

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerability, tracked as CVE-2026-104286 (CVSS score: 9.8), allows unauthenticated attackers to write arbitrary files on the underlying system. "An improper

Indicators of Compromise (1)

CVE (1)
CVE-2026-104286
Source Attribution

Originally published by The Hacker News on Oct 2, 2026.

Related Threats

CRITICALZero Day

ShinyHunters’ exploitation of a new PeopleSoft zero-day hole threatens to change enterprise risk dynamics

A recent compromise of PeopleSoft by hacking group ShinyHunters is causing new concerns for enterprise users of the Oracle product, with analysts recommending extreme measures in response. Law enforcement has made some progress in its pursuit of the cyber criminals involved. On Saturday, Reuters reported that a suspected member of ShinyHunters had been arrested by the FBI and has been cooperating

CVE-2026-35273
CSO Online
CRITICALZero Day

Citrix discloses third actively exploited NetScaler zero-day in less than a week

The vendor was much quicker and consistent in its response to the latest defect, and researchers consider the impact relatively low compared to the previous pair of zero-days. The post Citrix discloses third actively exploited NetScaler zero-day in less than a week appeared first on CyberScoop .

CyberScoop
CRITICALZero Day

Citrix warns of actively exploited NetScaler flaw days after zero-day patch rush

Citrix has warned customers about another high-severity vulnerability in its NetScaler ADC and NetScaler Gateway products, just days after the company urged them to fix a separate batch of flaws that included two actively exploited zero-days . The new vulnerability, tracked as CVE-2026-88779 , is a memory-overflow issue that can cause a denial-of-service (DoS) condition on affected appliances. Cit

CVE-2026-88779CVE-2026-88772
CSO Online