Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [ACTIVE] · [TECHNOLOGY]
2 clusters · 8 sources · 14 days · First seen · Last updated
Fortinet software security vulnerabilities
Overview
Security vulnerabilities have been identified in Fortinet software products. Initial reports highlighted critical flaws in FortiOS and FortiProxy, including CVE-2024-21762 and CVE-2024-23113, which were noted for being exploited in the wild.
Subsequently, a critical zero-day vulnerability, CVE-2026-104286, was discovered in Fortinet’s FortiMail email security appliances. This flaw allows unauthenticated attackers to write arbitrary files to the operating system via the Identity-Based Encryption GUI component. While Fortinet announced upcoming fixes, immediate mitigations such as disabling the affected feature or blocking management interface access were recommended.
Entities
Fortinet · CISA · SolarWinds · FortiMail
Timeline
-
[TECHNOLOGY] 4 sourcesFortinet FortiMail zero-day vulnerability actively exploited
A critical zero-day vulnerability (CVE-2026-104286) in Fortinet FortiMail is being actively exploited, allowing unauthenticated attackers to write arbitrary files to affected systems.
-
[TECHNOLOGY] 4 sourcesFortinet and SolarWinds issue patches for critical security vulnerabilities
Fortinet and SolarWinds have issued patches for critical vulnerabilities, including an actively exploited FortiOS flaw and a high-severity remote code execution bug in SolarWinds Access Rights Manager.
Sources
borncity.com · cybernoz.com · forkast.news · sempreupdate.com.br · tecnoandroid.it · thehackernews.com · theregister.co.uk · venceremos.it