Today in tech

Breaking news, reviews, guides and deals on all that’s cutting-edge

Advertisement
Advertisement
Advertisement
Advertisement
Advertisement
Advertisement
Advertisement
Advertisement
FortiMail’s Encryption Feature Was Supposed to Protect Email. It Became the Attack Vector.

FortiMail’s Encryption Feature Was Supposed to Protect Email. It Became the Attack Vector.

A path traversal vulnerability in Fortinet FortiMail’s Identity-Based Encryption GUI component allows unauthenticated attackers to write arbitrary files on the underlying system through crafted HTTP or HTTPS requests. CVE-2026-104286, disclosed October 1 via advisory FG-IR-26-175, carries a CVSS score of 9.8. It combines CWE-22 (path traversal) with CWE-158 (improper null byte neutralization) in the management […]

Forkast News
Advertisement
Advertisement
Advertisement
Advertisement

More from Yahoo Tech