DKDKCISSPSearch
VulnerabilitiesDEVELOPING

Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities ( KEV ) catalog, following reports of active exploitation.

DKCISSP News DeskThe Hacker News2 Oct 2026, 11:19 am
Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes
Image courtesy of The Hacker News. Original report
DKCISSP REPORT

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities ( KEV ) catalog, following reports of active exploitation.

The vulnerability, tracked as CVE-2026-104286 (CVSS score: 9.8), allows unauthenticated attackers to write arbitrary files on the underlying system.

Fortinet has acknowledged that the vulnerability has been exploited in the wild, urging customers to apply the following workarounds until fixes are available for certain versions - Fortinet credited Gwendal Guégniaud of the Fortinet Product Security team with discovering and reporting the flaw.

It has shared the following indicators of compromise - In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies are recommended to apply the patch or workarounds by October 4, 2026.

The Cybersecurity and Infrastructure Security Agency (CISA) added a critical CVSS 9.8 authentication bypass flaw in Cisco Catalyst SD-WAN Manager to its known exploited vulnerabilities (KEV) catalog on Sept. 30.

It is the eighth new Catalyst SD-WAN Manager bug added to the KEV this year alone, according to watchTowr , which has been tracking the activity around Cisco’s SD-WAN products closely.

The bug — CVE-2026-76504 — could let an unauthenticated, remote attacker access an affected system with the privileges of the admin user because of an improper handling of URI encoding in an HTTP request.

As a single-pane-of-glass used by enterprises to manage, configure, and monitor large networks, it’s naturally an attractive target.” Roman Sannikov, global research coordinator at iCounter, said because Cisco’s SD-WAN Manager controls how traffic moves between every branch on the network, teams need to patch quickly.

The development comes as number of security flaws in Check Point (CVE-2026-85102 and CVE-2026-93616), Arista VeloCloud Orchestrator (CVE-2026-93952), F5 BIG-IP Access Policy Manager (CVE-2026-94127), Cisco Catalyst SD-WAN Manager (CVE-2026-76504), and Citrix NetScaler ADC and NetScaler Gateway (CVE-2026-88771 and CVE-2026-88772) have come under in-the-wild exploitation.

What should actually change is treating internet-facing management interfaces as the crown jewels they are: restrict access to known, trusted sources, put them behind a layer that can detect and block anomalous API requests in real time, and assume a patch will always be late to at least some of your fleet.” Jason Soroko, senior fellow at Sectigo, added that this bypass grants administrator access to the central manager’s API, creating a risk of unauthorized configuration changes across the branches it manages.

Randolph Barr, chief Information security officer at Cequence Security, pointed out that watchTowr's count of eight CVEs this year shows attackers (and researchers) are actively hunting this surface.

In a security advisory published on September 30, Cisco issued a warning about CVE-2026-76504, a vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager which could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user.

With a CVSS score of 9.8 the vulnerability is classed as critical.

Soroko said Cisco teams should patch and investigate possible compromise, also preserve logs before upgrading, check for unexpected access, and review configuration changes.

What happened

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities ( KEV ) catalog, following reports of active exploitation.

The vulnerability, tracked as CVE-2026-104286 (CVSS score: 9.8), allows unauthenticated attackers to write arbitrary files on the underlying system.

Fortinet has acknowledged that the vulnerability has been exploited in the wild, urging customers to apply the following workarounds until fixes are available for certain versions - Fortinet credited Gwendal Guégniaud of the Fortinet Product Security team with discovering and reporting the flaw.

What changed

It has shared the following indicators of compromise - In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies are recommended to apply the patch or workarounds by October 4, 2026.

The Cybersecurity and Infrastructure Security Agency (CISA) added a critical CVSS 9.8 authentication bypass flaw in Cisco Catalyst SD-WAN Manager to its known exploited vulnerabilities (KEV) catalog on Sept. 30.

It is the eighth new Catalyst SD-WAN Manager bug added to the KEV this year alone, according to watchTowr , which has been tracking the activity around Cisco’s SD-WAN products closely.

Who is affected

The bug — CVE-2026-76504 — could let an unauthenticated, remote attacker access an affected system with the privileges of the admin user because of an improper handling of URI encoding in an HTTP request.

As a single-pane-of-glass used by enterprises to manage, configure, and monitor large networks, it’s naturally an attractive target.” Roman Sannikov, global research coordinator at iCounter, said because Cisco’s SD-WAN Manager controls how traffic moves between every branch on the network, teams need to patch quickly.

Why it matters

The development comes as number of security flaws in Check Point (CVE-2026-85102 and CVE-2026-93616), Arista VeloCloud Orchestrator (CVE-2026-93952), F5 BIG-IP Access Policy Manager (CVE-2026-94127), Cisco Catalyst SD-WAN Manager (CVE-2026-76504), and Citrix NetScaler ADC and NetScaler Gateway (CVE-2026-88771 and CVE-2026-88772) have come under in-the-wild exploitation.

What should actually change is treating internet-facing management interfaces as the crown jewels they are: restrict access to known, trusted sources, put them behind a layer that can detect and block anomalous API requests in real time, and assume a patch will always be late to at least some of your fleet.” Jason Soroko, senior fellow at Sectigo, added that this bypass grants administrator access to the central manager’s API, creating a risk of unauthorized configuration changes across the branches it manages.

Technical details

Randolph Barr, chief Information security officer at Cequence Security, pointed out that watchTowr's count of eight CVEs this year shows attackers (and researchers) are actively hunting this surface.

In a security advisory published on September 30, Cisco issued a warning about CVE-2026-76504, a vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager which could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user.

With a CVSS score of 9.8 the vulnerability is classed as critical.

Response

Soroko said Cisco teams should patch and investigate possible compromise, also preserve logs before upgrading, check for unexpected access, and review configuration changes.

These steps follow the investigation guidance and Cisco’s hardening recommendations.

What security teams should do

Soroko said teams should also keep management interfaces off the public internet, restrict access to approved administration systems, and send logs to a separate server.

Cisco also issued SD-WAN security-hardening releases in August following an internal review.

What remains unknown

Cisco recommends reviewing the following logs for requests related to j_security_check from unknown or unauthorized IP addresses: /var/log/nms/containers/service-proxy/serviceproxy-access.log : Requests with an encoded character in the j_security_check path, such as POST /%6a_security_check HTTP/1.1 .

It also advised security teams investigating potentially compromised SD-WAN systems to check the serviceproxy-access.log file located under /var/log/nms/containers/service-proxy and the vmanage-server.log file under /var/log/nms/ for entries related to j_security_check from unknown or unauthorized IP addresses.

Attribution

The Hacker News: The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities ( KEV ) catalog, following reports of active exploitation.

SC Media: The Cybersecurity and Infrastructure Security Agency (CISA) added a critical CVSS 9.8 authentication bypass flaw in Cisco Catalyst SD-WAN Manager to its known exploited vulnerabilities (KEV) catalog on Sept. 30.

Infosecurity Magazine: In a security advisory published on September 30, Cisco issued a warning about CVE-2026-76504, a vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager which could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user.

Rapid7: Critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in the wild (CVE-2026-76504) Critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in the wild (CVE-2026-76504) On September 30, 2026, Cisco published a security advisory for CVE-2026-76504 , a critical API authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Manager.

What to watch next

Watch for additional victim details, indicators of compromise and follow-on exploitation reports.

Watch for revised vendor guidance, fixed versions and mitigation updates.

MORE IN VULNERABILITIES

More cybersecurity reporting

Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCEThe Hacker News · 5 Oct 2026, 8:48 pmOut-of-band Exchange Server update fixes high-severity mailbox access bug (CVE-2026-96940) - Help Net SecurityHelp Net Security · 5 Oct 2026, 4:08 pmAttackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOTThe Hacker News · 5 Oct 2026, 1:00 pmCVE-2023-36025 (SmartScreen Bypass) Vulnerability: Analysis & Detection | HuntressHuntress · 4 Oct 2026, 5:30 am