Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    Sony WH-1000XM5 remain some of our favourite headphones, especially at this low price

    October 4, 2026

    Plex just added 4 new free live TV channels to its streaming lineup

    October 4, 2026

    Trump Names National Intelligence Director Jay Clayton to Lead a New Federal AI Task Force

    October 4, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action
    Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action
    Cybersecurity

    Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action

    The Tech GuyBy The Tech GuyOctober 4, 2026No Comments2 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    The US Cybersecurity and Infrastructure Security Agency (CISA) and Fortinet on Thursday sounded the alarm on a critical FortiMail vulnerability that has been exploited in the wild. Patches have yet to be released.

    Advertisement

    Tracked as CVE-2026-104286 (CVSS score of 9.8), the zero-day is a path traversal and an improper neutralization of NULL byte or NULL character flaw that could allow attackers to write arbitrary files to the underlying system.

    Threat actors could exploit the issue via crafted HTTP or HTTPS requests, potentially gaining arbitrary code or command execution.

    Fortinet has published an advisory describing the security defect, urging organizations to disable the IBE feature support or disable access to the FortiMail management interface from the web and limit access to trusted sources. 

    “This has been reported to be exploited in the wild; customers are urged to apply the workaround,” the company said.

    Fortinet also published indicators of compromise (IoCs) to help security teams hunt for potential intrusions.

    Advertisement. Scroll to continue reading.

    On Thursday, CISA added CVE-2026-104286 to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to address it within three days, as mandated by BOD 26-04.

    According to Fortinet, the security bug was discovered internally and affects FortiMail versions 7.2.0 through 7.2.9, 7.4.0 through 7.4.8, 7.6.0 through 7.6.6, and 8.0.0 through 8.0.1.

    The company says fixes will be included in the upcoming FortiMail versions 7.4.9, 7.6.7, and 8.0.2, but has not provided a release timeline.

    Neither Fortinet nor CISA has provided details on the observed attacks.

    Related: Zimbra Vulnerability Exploited in the Wild Prior to Public Disclosure

    Related: Zammad Zero-Days Exploited in AI-Powered DIVD Hack

    Related: Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability

    Related: Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    Trump Names National Intelligence Director Jay Clayton to Lead a New Federal AI Task Force

    October 4, 2026

    AI Agents Aimed SQL Injection at US and Canadian Government Sites

    October 4, 2026

    Fortra Patches Critical Vulnerabilities in BoKS

    October 3, 2026

    doxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet Misadventures

    October 3, 2026

    In Rare Move, Alleged Iranian State Hacker Extradited to US

    October 3, 2026

    Crypto Scammers Hijack Microsoft’s Official X Account

    October 3, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 2026392 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 2026211 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202517 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    Sony WH-1000XM5 remain some of our favourite headphones, especially at this low price

    October 4, 2026

    Plex just added 4 new free live TV channels to its streaming lineup

    October 4, 2026

    Trump Names National Intelligence Director Jay Clayton to Lead a New Federal AI Task Force

    October 4, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.