LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingCVE-2026-7273 · Zyxel GS1900 Switch Flaw Exploited, Now in EU CatalogueCVE-2026-102489 · Zammad Session Fixation Vulnerability Exploited Same Day as DisclosureCVE-2026-102490 · Zammad GmbH Zammad Vulnerability Exploited Same Day as Publication
CVE-2026-104286critical

Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action

A critical-severity zero-day vulnerability, tracked as CVE-2026-104286, has been reported in Fortinet's FortiMail email security gateway. The flaw is described as a path traversal vulnerability that permits attackers to write arbitrary files to the underlying system. Organizations leveraging FortiMail deployments are advised to take immediate mitigation steps due to the active exploitation of…

ZeroDay News ·

Source: SecurityWeek

A critical-severity zero-day vulnerability, tracked as CVE-2026-104286, has been reported in Fortinet's FortiMail email security gateway. The flaw is described as a path traversal vulnerability that permits attackers to write arbitrary files to the underlying system. Organizations leveraging FortiMail deployments are advised to take immediate mitigation steps due to the active exploitation of this vulnerability.

The reported path traversal vulnerability allows an attacker to manipulate file paths in a way that causes the application to write files to unintended locations on the server. By supplying specially crafted input, an attacker can bypass directory restrictions and place malicious files, such as web shells or configuration files, in sensitive directories. This capability to write arbitrary files can lead to remote code execution, data exfiltration, or complete system compromise, depending on the attacker's objectives and the privileges of the affected process.

FortiMail is an email security platform designed to protect organizations from various email-borne threats, including spam, phishing, and malware. As an internet-facing appliance, it often processes untrusted input, making it a frequent target for attackers seeking initial access to corporate networks. The compromise of such a gateway can provide a pivot point for broader network intrusion.

The scope of this vulnerability affects Fortinet FortiMail installations. While specific versions were not detailed in the report, it is common for zero-day exploits to target a range of unpatched versions across a product line. Given the critical severity and active exploitation, all organizations utilizing FortiMail should assume their systems are at risk until specific patch information or mitigation guidance is released by the vendor.

Typical mitigation for path traversal vulnerabilities often involves input validation and sanitization, ensuring that file paths do not contain malicious characters or sequences that could lead to directory traversal. For actively exploited zero-days, immediate actions commonly include applying vendor-supplied patches, implementing intrusion detection/prevention system (IDS/IPS) rules to block known exploit patterns, or, in some cases, temporarily restricting access to the affected service until a permanent fix is available. Organizations should also review logs for any indicators of compromise.

This incident underscores the persistent threat posed by zero-day vulnerabilities in critical network infrastructure devices. Email security gateways, firewalls, and VPN appliances are prime targets due to their perimeter placement and direct exposure to the internet. The rapid disclosure and call for urgent action highlight the severe implications of such flaws, emphasizing the need for robust patch management, continuous monitoring, and incident response capabilities within organizations.

vulnerabilities in this storyCVE-2026-104286
fortinetfortimailzero-dayvulnerabilitypath traversal
ShareXLinkedInWhatsAppFacebook

More News

view all →
patch

Three questions a hospital CISO should ask a healthcare fintech vendor

A cybersecurity expert has outlined key questions hospital CISOs should pose to healthcare fintech vendors to assess their security posture, particularly concerning patient data and financial transactions. Drew McCombs, who holds both CTO and CISO roles at Cylerity, emphasizes that security should be an integral part of development processes, not an afterthought, especially when patient data…

CVE-2026-88779

Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

Citrix has confirmed the active exploitation of a new zero-day vulnerability, identified as CVE-2026-88779, affecting its NetScaler appliances. This new flaw reportedly emerged and was exploited just days after the company released patches for two other previously exploited vulnerabilities in the same product line.

cloud

Keyorix: Open-source secrets management for teams that can’t use SaaS

Keyorix, an open-source secrets management solution, has been released, offering an on-premises alternative for organizations unable to utilize cloud-based services for credential storage. The system is designed to run entirely on a company's own infrastructure, with its core functionality requiring no internet connection.

security

How RMM abuse gives attackers a way in that looks like business as usual

Attackers are increasingly leveraging legitimate remote monitoring and management (RMM) software to gain persistent access to victim systems, a tactic observed in 45% of endpoint-related incidents recorded by security firm Huntress in the first quarter of 2026. This method allows attackers to execute commands remotely and maintain access in a way that often appears to be normal administrative…

nation-state

TTY Logs and the Data it Captures, (Sun, Oct 4th)

A recent report details an experiment involving the collection and analysis of TTY logs from DShield sensors. The experiment focused on capturing activity from actors or bots that successfully logged into these sensors, specifically recording the various commands executed post-login. These collected TTY logs are then parsed and transmitted daily to the DShield SIEM for correlation with other…

CVE-2026-88779high

Citrix NetScaler Flaw Exploited Before CVE Publication

The CVE-2026-88779 vulnerability in Citrix NetScaler was exploited before its official publication date. A second independent catalogue now confirms exploitation.