FortiMail Encryption Function Becomes an Attack Vector, CVE-2026-104286 Vulnerability Exposed
2026-10-02 16:53:46
CoinMeta data: The FortiMail encryption feature of Fortinet was originally intended to protect emails, but it has become a vector for attacks. The CVE-2026-104286 vulnerability allows unauthorized attackers to write any file on the system through specially crafted HTTP or HTTPS requests, with a severity score of 9.8. Affected versions include FortiMail 8.0.0 to 8.0.1, 7.6.0 to 7.6.6, 7.4.0 to 7.4.8, and 7.2.0 to 7.2.9. There are currently no patch versions available for the 7.4, 7.6, or 8.0 branches. CISA has added this vulnerability to the list of known exploited vulnerabilities, and federal agencies must fix it by October 4th. The existence of this vulnerability enables attackers to route archived email data to external servers through configured accounts, highlighting the vulnerability of email as an autonomous proxy coordination infrastructure.
Bullish 0
Bearish 0
Source:Forkast
This content is for market information only and does not constitute investment advice.