Skip to finding
important · Edge — RCE

Attackers are using FortiMail’s public management interface for credential-free file writes and appliance code execution.

Affects

Fortinet FortiMail, a physical, virtual and cloud-deployed secure email gateway.

A crafted HTTP or HTTPS request combines path traversal with NULL-byte handling to write or replace files outside the intended path.

Detail and 4 sources

Observed compromises included attacker-added binaries, ld.so.preload modification and root cron activity.

A patch was announced, but current release availability could not be resolved from the retrieved vendor material.

Today’s change is the confirmed scope: the arbitrary-file-write primitive is now connected to persistence and command execution using root-level mechanisms.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Monday, October 5, 2026