chiprook
← Security
SecurityOctober 4, 2026, 14:32

Fortinet confirms FortiMail zero-day: patching does not remove the backdoor

CVE-2026-104286 (CVSS 9.8) in the FortiMail web management interface lets unauthenticated attackers write arbitrary files and plant a Linux backdoor via ld.so.preload. CISA added it to the KEV catalog on October 1 with an October 4 deadline for federal agencies; fixed branches are 8.0.2+, 7.6.7+ and 7.4.9+, with no fix for 7.2.

Fortinet confirms FortiMail zero-day: patching does not remove the backdoor
#Fortinet#FortiMail#CISA
Read next
Security

Fortinet warns of critical FortiMail flaw exploited in zero-day attacks

Security

Cisco Patches Exploited Catalyst SD-WAN Zero-Day

Security

F5 patches exploited BIG-IP APM zero-day enabling RCE

Security

CISA Gives Agencies 3 Days to Patch Exploited Pixel Zero-Day