Fortinet News Articles
Recent news articles refferecing the vendors vulnerabilities.
CISA Adds Fortinet FortiMail 0-day Vulnerability to KEV Following Active Exploitation
CISA added critical Fortinet FortiMail flaw CVE-2026-104286 to its KEV catalog following evidence of active exploitation.
6 days ago

FortiMail Zero-Day CVE-2026-104286 Is Under Attack With No Patch Yet
Fortinet's critical FortiMail zero-day CVE-2026-104286 is being exploited, but fixed builds are still pending. Here's what administrators should do now.
1 week ago
Hackers Backdoor Fortinet FortiMail Email Gateways With No Password; Patches Unavailable
Fortinet FortiMail zero-day CVE-2026-104286 lets unauthenticated attackers write arbitrary files to email gateways and plant persistent backdoors. CISA added the CVSS 9.8 path traversal flaw to its
1 week ago
Fortinet sounds the alarm over actively exploited FortiMail zero-day
No login required, exploitation underway, and some admins are still waiting for patches
1 week ago
Fortinet sounds the alarm over actively exploited FortiMail zero-day
No login required, exploitation underway, and some admins are still waiting for patches
1 week ago
Critical FortiMail zero-day exploited in the wild (CVE-2026-104286) - IT Security News
2026-10-02 11:10 Fortinet is warning customers that attackers are exploiting a zero-day vulnerability (CVE-2026-104286) in FortiMail, its email security gateway. Fortinet says the flaw has...
1 week ago
Critical FortiMail zero-day exploited in the wild (CVE-2026-104286) - Help Net Security
Fortinet is warning customers that attackers are exploiting a zero-day vulnerability (CVE-2026-104286) in FortiMail.
1 week ago
Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action
A critical vulnerability in FortiMail (CVE-2026-104286) exploited as a zero-day calls for urgent action, Fortinet and CISA warn.
1 week ago
Attackers target critical FortiSandbox flaws as CISA issues patch order
Command injection vulns land on exploited list after researchers spot abuse attempts
Attackers target critical FortiSandbox flaws as CISA issues patch order
Command injection vulns land on exploited list after researchers spot abuse attempts
US Cybersecurity Agency Sounds Alarm, Orders Immediate Action on Actively Exploited Fortinet Flaws
CISA has ordered US agencies to urgently patch actively exploited Fortinet vulnerabilities, warning the critical flaws could enable remote code execution...
3 Recently Patched Fortinet FortiSandbox Vulnerabilities in Hacker Crosshairs
Fortinet FortiSandbox vulnerabilities tracked as CVE-2026-39808, CVE-2026-39813, and CVE-2026-25089 are being targeted in the wild.
Three critical Fortinet sandbox bugs splattered by unknown attackers
All have patches, so make sure you upgrade to a fixed version
Three critical Fortinet sandbox bugs splattered by unknown attackers
All have patches, so make sure you upgrade to a fixed version
Attackers are exploiting FortiSandbox vulnerabilities - IT Security News
Attackers have been spotted exploiting three vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) in FortiSandbox, a platform that other Fortinet security products depend on for threat verdicts to enforce blocking decisions and trigger automated responses. The warning came on Monday from...
Attackers are exploiting FortiSandbox vulnerabilities - Help Net Security
Attackers have been spotted exploiting three vulnerabilities (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089) in FortiSandbox.
Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week
Attackers are exploiting three Fortinet FortiSandbox flaws, including one patched last week, risking auth bypass and command execution.
Critical Fortinet FortiSandbox flaws now exploited in attacks
Attackers are now exploiting several critical vulnerabilities in Fortinet's FortiSandbox cyber threat detection platform, according to threat intelligence company Defused.
New infostealer reaches enterprise devices through FortiClient EMS vulnerability - IT Security News
Attackers are delivering a broad-spectrum infostealer to enterprise computers by exploiting a known vulnerability (CVE-2026-35616) in FortiClient Enterprise Management Server (EMS). “The [malicious] payload was presented as a Fortinet endpoint update and executed through FortiClient-managed VPN scri...
New infostealer reaches enterprise devices through FortiClient EMS vulnerability - Help Net Security
Attackers are delivering an infostealer to enterprise computers by exploiting a known vulnerability (CVE-2026-35616) in FortiClient EMS.
Fortinet Flaw Opens Door to Mass Credential Theft via Managed Endpoints
Threat actors are exploiting CVE-2026-35616 in FortiClient EMS to push disguised credential stealers to all managed endpoints at scale. Arctic Wolf and WatchTowr detail how attackers abuse management infrastructure for silent deployment and browser data theft. Organizations must patch immediately.
Hackers exploit FortiClient EMS flaw to push infostealer malware
Hackers are exploiting an authentication bypass vulnerability (CVE-2026-35616) in FortiClient Enterprise Management Server (EMS) to deliver an undocumented credential stealer called EKZ.
Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer
FortiClient EMS flaw CVE-2026-35616 enabled malware delivery via fake updates, risking credential theft across endpoints.
Critical FortiClient EMS Vulnerability Exploited in Fresh Attacks
CVE-2026-35616, a FortiClient EMS zero-day vulnerability patched in April, has been exploited in fresh infostealer attacks.
PoC Exploit Released for FortiSandbox Vulnerability that Allows Attacker to Execute Commands - IT Security News
A proof-of-concept (PoC) exploit has been publicly released for a critical vulnerability in Fortinet’s FortiSandbox product, tracked as CVE-2026-39808. The flaw allows an unauthenticated attacker to execute arbitrary operating system commands as root, the highest privilege level, without requiring a...