LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingCVE-2026-7273 · Zyxel GS1900 Switch Flaw Exploited, Now in EU CatalogueCVE-2026-102489 · Zammad Session Fixation Vulnerability Exploited Same Day as DisclosureCVE-2026-102490 · Zammad GmbH Zammad Vulnerability Exploited Same Day as Publication
CVE-2026-104286critical

Fortinet warns of critical FortiMail flaw exploited in zero-day attacks

Fortinet has issued a warning regarding a critical vulnerability in its FortiMail email security platform, identified as CVE-2026-104286, which is actively being exploited in zero-day attacks. The flaw, rated with a CVSS score of 9.8, affects the FortiMail management interface and could allow an unauthenticated attacker to execute arbitrary code or commands.

ZeroDay News ·

Source: BleepingComputer

Fortinet has issued a warning regarding a critical vulnerability in its FortiMail email security platform, identified as CVE-2026-104286, which is actively being exploited in zero-day attacks. The flaw, rated with a CVSS score of 9.8, affects the FortiMail management interface and could allow an unauthenticated attacker to execute arbitrary code or commands.

The vulnerability is described as an "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')" (CWE-22) and "Improper Neutralization of NULL Byte or NULL Character" (CWE-158). This combination could enable an attacker to write arbitrary files to the underlying system by crafting specific HTTP or HTTPS requests.

Gwendal Gugniaud of Fortinet's Product Security team discovered the issue internally. Affected FortiMail versions include 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9. Fortinet has confirmed active exploitation and is urging customers to implement temporary mitigations while awaiting security updates.

For FortiMail 7.2 users, upgrading to the 7.4 branch or a later version is recommended. Security updates for FortiMail 7.4, 7.6, and 8.0 installations are not yet available, but Fortinet has indicated that fixes will be included in upcoming versions 7.4.9, 7.6.7, and 8.0.2.

As a workaround, administrators can disable IBE (Identity-Based Encryption) feature support using the command: `config system encryption ibe set status disable end`. Alternatively, access to the FortiMail management interface can be restricted from the internet or limited to trusted private networks.

Fortinet has also provided Indicators of Compromise (IOCs) to help identify potential breaches. These include specific file modifications and additions, along with their SHA-256 hashes: `/data/lib/liblog.so` (added), `/bin/smit` (modified), `/data/bin/webconsole` (added), `/data/bin/mailservice` (added), `/data/etc/httpd.conf` (modified), `/data/etc/ld.so.preload` (added), and `/data/migadmin.tar.gz` (modified).

Two IP addresses, 79.141.169.187 and 45.129.0.192, have been linked to the attacks. Log entries provided by Fortinet as IOCs show activities such as a cron job executing a command related to `/migadmin`, an administrator logout, an IBE decryption error, and failed login attempts. One specific log entry indicates the configuration of an archive account named `archive234` with `79.141.169.187` as the remote server and `/uploads` as the remote directory, suggesting an attempt to exfiltrate archived data.

Fortinet has not publicly disclosed the initial exploitation date, the number of compromised systems, or the identity of the attackers. The company has stated it is coordinating with government agencies, including CISA, on the advisory's content. CISA has added CVE-2026-104286 to its Known Exploited Vulnerability catalog, mandating federal agencies to perform forensic triage and mitigate the flaw by October 4th.

vulnerabilities in this storyCVE-2026-104286
vulnerabilityzero-day
ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2026-88779

Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

Citrix has confirmed the active exploitation of a new zero-day vulnerability, identified as CVE-2026-88779, affecting its NetScaler appliances. This new flaw reportedly emerged and was exploited just days after the company released patches for two other previously exploited vulnerabilities in the same product line.

CVE-2026-88779high

Citrix NetScaler Flaw Exploited Before CVE Publication

The CVE-2026-88779 vulnerability in Citrix NetScaler was exploited before its official publication date. A second independent catalogue now confirms exploitation.

CVE-2026-88779

Citrix patches NetScaler SAML zero-day exploited in attacks

Citrix has issued urgent security updates for a new zero-day vulnerability, identified as CVE-2026-88779, affecting its NetScaler ADC and NetScaler Gateway appliances. The flaw, described as a memory buffer issue, has been actively exploited in targeted attacks, primarily leading to denial-of-service conditions.

patch

Three questions a hospital CISO should ask a healthcare fintech vendor

A cybersecurity expert has outlined key questions hospital CISOs should pose to healthcare fintech vendors to assess their security posture, particularly concerning patient data and financial transactions. Drew McCombs, who holds both CTO and CISO roles at Cylerity, emphasizes that security should be an integral part of development processes, not an afterthought, especially when patient data…

cloud

Keyorix: Open-source secrets management for teams that can’t use SaaS

Keyorix, an open-source secrets management solution, has been released, offering an on-premises alternative for organizations unable to utilize cloud-based services for credential storage. The system is designed to run entirely on a company's own infrastructure, with its core functionality requiring no internet connection.

security

How RMM abuse gives attackers a way in that looks like business as usual

Attackers are increasingly leveraging legitimate remote monitoring and management (RMM) software to gain persistent access to victim systems, a tactic observed in 45% of endpoint-related incidents recorded by security firm Huntress in the first quarter of 2026. This method allows attackers to execute commands remotely and maintain access in a way that often appears to be normal administrative…