🚨 CISA just updated its Known Exploited Vulnerabilities (KEV) list on Oct 1, adding a high-risk issue: Fortinet FortiMail path traversal CVE-2026-104286. Because there’s evidence of active exploitation, federal civilian agencies have until Oct 4 to patch—seriously tight timeline. What’s the problem? It’s not just basic “path traversal.” Attackers can craft requests to bypass restricted directories, and the bug also includes improper NULL-byte/NULL character handling. Result: malicious actors can send specially crafted HTTP/HTTPS requests without authentication, potentially writing arbitrary files on the underlying system—opening the door to deeper compromise and persistence. CVE-2026-104286 is already in NVD and MITRE, with a CVSS score of 9.8 (critical). Affected versions include: FortiMail 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8, and 7.2.0–7.2.9. Fortinet’s PSIRT (FG-IR-26-175) provides patch guidance plus two IoCs for hunting. In the meantime, consider temporary mitigations like disabling IBE and restricting FortiMail admin access to private networks only. Check your version now. Prioritize patching + IoC-based log/traffic review. #CISA #Fortinet #FortiMail #KEV #CyberSecurity #VulnerabilityManagement
Want to learn more? Visit Explore the world, stay updated on travel insights and international affairs, and discover authentic stories from real life
评论
发表评论