Over 3,900 FortiMail gateways exposed online amid active exploitation
A security flaw tracked as CVE-2026-104286 in Fortinet's FortiMail email gateway is under active exploitation, prompting CISA to add it to its Known Exploited Vulnerabilities catalog. Internet scans conducted on October 4, 2026, found 3,911 instances identifiable by application fingerprint and 5,322 by page title. The exposed devices represent a subset of all deployments, as many may be hidden behind firewalls or proxies. The high-value, internet-facing nature of these mail security appliances makes them a prime target for attackers. Security experts advise administrators to verify if their own FortiMail systems are publicly reachable and to restrict administrative interfaces.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in