Fortinet FortiMail CVE-2026-104286 Path Traversal Flaw Actively Exploited
A critical path traversal vulnerability in Fortinet FortiMail, tracked as CVE-2026-104286 with a CVSS v3.1 score of 9.8, is being actively exploited to compromise email security appliances. The flaw combines path traversal (CWE-22) with improper neutralization of NULL bytes (CWE-158) within the FortiMail GUI, enabling unauthenticated remote attackers to write arbitrary files and execute unauthorized code via crafted HTTP or HTTPS requests. Affected products include FortiMail versions 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9. While upcoming security updates will address the flaw in versions 8.0.2, 7.6.7, and 7.4.9, administrators should immediately apply workarounds by disabling Identity-Based Encryption (IBE) via the CLI (`config system encryption ibe`, `set status disable`, `end`) or restricting management interface access to trusted networks. Observed malicious activity is linked to IP addresses 79.141.169.187 and 45.129.0.192, with key indicators of compromise including suspicious files such as `/data/lib/liblog.so`, `/data/bin/webconsole`, and `/data/etc/ld.so.preload`, as well as anomalous log entries involving unexpected `/migadmin` commands and IBE Base64 parsing errors.
Severity: Critical
Threat Details and IOCs
| Malware: | PivotC2 |
|---|---|
| CVEs: | CVE-2025-25249, CVE-2026-104286, CVE-2026-76504, CVE-2026-85102, CVE-2026-88771, CVE-2026-88772, CVE-2026-93616, CVE-2026-93952, CVE-2026-94127 |
| Technologies: | Apache httpd, Fortinet FortiMail, Linux |
| Attacker Countries: | Russia |
| Attacker IPs: | 45[.]129[.]0[.]192, 79[.]141[.]169[.]187 |
| Attacker Hashes: | 4000276a150a165d3c2537d1e19fb393c4de8333076a16655e28059cae82157b, 49a7156a7d043cc8f9f680579db22f86, 5241738a3e9988404239e12243f6d35b, 61af1c4bce1c2eebc8ff689ca5337791, 64c90a00c7fda4d5c7973ed64c25783a, 703e97c64e61e41dc3aaba580d82bb2aa7b6a11b54ee6fb467ed5d5a3bffdef5, 77324ac428bde86d351fc5fc06f6d64a6bfe737dfb2743df1d4c5ac2418a5b6a, 7a6cea9f5c9e2e9994d4e3c4da73f86cf5acd05ea5d312c066c9d1dafd69ee38, 8015f34dc84922b03688399d7f9fe7a00361789f7e420c7e2a2cdb23e75cef84, 8953ec7960b09f544a880b072ad4e6cfda7a8303f486251d3478dcfdfbac23b6, 8eb64f25d2a8e18e05aae058629473cf, ae0ea6502d3fa5f0664bceb73189eb54, d6fe51c22b91776f4c961ea58bcac5917f15d560a619d7ce726d3d51795609d3, f90fa81a5f521d785f2b2f765e3ab897 |
| Victim Industries: | Education, Financial Services, Government, Healthcare, Manufacturing, Retail, Technology Hardware, Telecommunications |
| Victim Countries: | Hong Kong, United States |
Mitigation Advice
- Identify all FortiMail appliances in your environment and upgrade them to a patched version (8.0.2, 7.6.7, 7.4.9, or later) as soon as possible.
- If patching cannot be immediately applied, use the FortiMail CLI to disable the Identity-Based Encryption (IBE) feature with the commands 'config system encryption ibe', 'set status disable', and 'end'.
- Validate that no FortiMail management interfaces are exposed to the public internet. If they are, immediately apply firewall rules to restrict access to only trusted, internal IP addresses.
- Add the IP addresses 79.141.169.187 and 45.129.0.192 to your firewall blocklist to prevent inbound and outbound communication.
- Scan all FortiMail appliances for the existence of the following files and investigate any findings: /data/lib/liblog.so, /data/bin/webconsole, /data/bin/mailservice, /data/etc/ld.so.preload, /bin/smit, /data/etc/httpd.conf, and /data/migadmin.tar.gz.
- Using your SIEM or log management platform, search FortiMail logs for evidence of anomalous activity, including unexpected '/migadmin' commands, IBE Base64 parsing errors, or unusual archive account configurations.
Compliance Best Practices
- Implement and enforce a network security policy that prohibits exposing administrative interfaces of any appliance or server to the public internet. Use jump boxes or VPNs for administrative access.
- Establish a formal vulnerability management program that includes regular, authenticated scanning of all assets, risk-based prioritization of findings, and defined SLAs for remediation.
- Deploy a File Integrity Monitoring (FIM) solution on critical infrastructure, including security appliances like FortiMail, to alert on unauthorized file creation or modification in sensitive directories.
- Enhance SIEM detection capabilities by establishing baselines for normal system and user behavior on critical appliances and creating correlation rules to alert on significant deviations from that baseline.
- Implement and maintain a comprehensive hardware and software asset inventory to ensure you can quickly identify all affected systems in response to vulnerability disclosures.
https://buaq.net/go-445919.html
https://cyberpress.org/critical-fortimail-flaw-lets-unauthenticated-attackers/
https://exploit-intel.com/vuln/CVE-2026-104286
https://gbhackers.com/fortinet-fortimail-path-traversal-flaw/
https://securityonline.info/fortimail-vulnerability-cve-2026-104286/
https://thehackernews.com/2026/10/critical-fortimail-zero-day-flaw.html
https://www.securityweek.com/exploited-fortinet-fortimail-zero-day-calls-for-urgent-action/
Citrix NetScaler CVE-2026-88779 Zero-Day Actively Exploited via SAML
Citrix has issued emergency security updates to address a zero-day vulnerability, tracked as CVE-2026-88779 with a CVSS score of 8.7, which affects NetScaler ADC and NetScaler Gateway appliances utilizing SAML authentication with Gateway or AAA functionality. Although officially designated as a memory buffer flaw causing denial-of-service conditions through the repeated crashing of the `nsaaad` and `Pitboss` processes, active exploitation indicates the vulnerability can be leveraged for remote code execution. Security researchers have observed threat actors targeting SAML authentication factors with crafted usernames containing shell commands designed to download malware payloads from the IP address 213.209.159.55, save them to `/v`, and execute them. In response to these active attacks, which prompted the Cybersecurity and Infrastructure Security Agency (CISA) to add the flaw to its Known Exploited Vulnerabilities catalog, administrators must immediately upgrade vulnerable deployments to NetScaler versions 14.1-73.41, 13.1-64.28, or their corresponding FIPS-compliant releases.
Severity: Critical
Threat Details and IOCs
| CVEs: | CVE-2023-6549, CVE-2025-6543, CVE-2026-88771, CVE-2026-88772, CVE-2026-88778, CVE-2026-88779 |
|---|---|
| Technologies: | Citrix NetScaler ADC, Citrix NetScaler Gateway |
| Attacker IPs: | 213[.]209[.]159[.]55 |
| Victim Industries: | Cloud Infrastructure, Education, Energy, Financial Services, Government, Healthcare, Legal & Compliance, Manufacturing, Multimedia, Professional Services, Retail, Technology Hardware, Telecommunications |
| Victim Countries: | Canada, Germany, Netherlands, Switzerland, United Kingdom, United States |
Mitigation Advice
- Run configuration checks on all NetScaler appliances to determine if they are configured as a SAML Service Provider (SP) or Identity Provider (IdP).
- Upgrade all vulnerable NetScaler ADC and Gateway appliances to the patched versions (14.1-73.41, 13.1-64.28, or the appropriate FIPS/NDcPP version) immediately.
- Add the IP address 213.209.159.55 to the network firewall blocklist.
- Review NetScaler appliance logs for evidence of compromise, such as unexpected reboots, repeated crashes of the 'nsaaad' process, and suspicious command strings in authentication usernames.
- Scan the filesystem of all potentially vulnerable NetScaler appliances for a malicious payload file named '/v'.
- Apply the latest 'Global Deny Lists' provided by Citrix to your NetScaler deployments to block known malicious actors.
Compliance Best Practices
- Review and improve the vulnerability management program to shorten the time required to test and deploy emergency patches for critical, internet-facing systems.
- Configure NetScaler appliances to forward all relevant logs, including authentication and system process logs, to a centralized SIEM to enable automated monitoring and alerting.
- Implement and enforce network segmentation policies that isolate internet-facing appliances like NetScaler from the internal corporate network, restricting their access to only essential systems.
- Develop and regularly test an incident response playbook specifically for compromises of network edge devices like NetScaler.
https://cyberpress.org/cisa-warns-of-citrix-netscaler-flaw/
https://securityonline.info/citrix-netscaler-cve-2026-88779-exploited/
https://thehackernews.com/2026/10/new-netscaler-zero-day-exploited-in.html
https://www.hkcert.org/security-bulletin/citrix-products-denial-of-service-vulnerability_20261005
AWS Patches Loom AI Agent Authentication Bypass (CVE-2026-103956) and SageMaker Command Injection
Amazon Web Services (AWS) has released security updates addressing three vulnerabilities in its open-source Loom platform for AI agent orchestration, alongside an OS command-injection vulnerability in Amazon SageMaker Unified Studio. Tracked as CVE-2026-103956, the most severe Loom flaw is an authentication-bypass vulnerability (CWE-306/CWE-1188) affecting versions prior to 1.6.1; it allows unauthenticated network clients to gain administrative control over the agent control plane, register malicious tool servers, and modify IAM policies when no identity provider is configured. CVE-2026-103957 is an OAuth2 discovery-handling flaw (CWE-918/CWE-201) in Loom versions prior to 1.7.0 that permits authenticated users with `mcp:write` or `a2a:write` scopes to exfiltrate client secrets and access tokens via malicious discovery URLs. CVE-2026-103958, also affecting Loom versions prior to 1.7.0, is a server-side request forgery (SSRF) vulnerability in Model Context Protocol (MCP) and agent-to-agent (A2A) connection handling that allows scoped users to redirect backend requests to internal endpoints, potentially exposing temporary cloud credentials. AWS resolved these Loom issues in version 1.7.0 and recommends immediate upgrades or configuring Amazon Cognito/external identity providers as a workaround. Additionally, AWS patched CVE-2026-104019, an OS command-injection vulnerability in the SageMaker Unified Studio Space startup script that could allow contributors to execute arbitrary commands in other members' Spaces and hijack temporary execution-role credentials; this has been addressed via a global fix requiring administrators to restart affected Studio Spaces.
Severity: Critical
Threat Details and IOCs
| CVEs: | CVE-2026-103956, CVE-2026-103957, CVE-2026-103958, CVE-2026-104019 |
|---|---|
| Technologies: | Amazon Cognito, Amazon Identity and Access Management, Amazon Loom, Amazon SageMaker, Amazon SageMaker Python SDK, Amazon SageMaker Unified Studio, Amazon Web Services |
| Victim Industries: | Artificial Intelligence, Automotive, Cloud Infrastructure, Education, Financial Services, Government, Healthcare, Information Technology, Manufacturing |
| Victim Countries: | United States |
Mitigation Advice
- Identify all AWS Loom deployments and upgrade them to version 1.7.0 or later.
- Identify all Amazon SageMaker Unified Studio Spaces and restart them to apply the patched images that mitigate CVE-2026-104019.
- For any AWS Loom deployments that cannot be immediately upgraded, configure an Amazon Cognito user pool or an active external identity provider to prevent unauthenticated access.
- Scan all AWS Loom deployments to ensure the environment variable `LOOM_ALLOW_UNAUTHENTICATED_LOCAL_DEV` is not set in any non-development environment.
- Rotate all OAuth2 client secrets used by AWS Loom integrations as a precaution against potential exposure from CVE-2026-103957.
- Force rotation of temporary IAM role credentials associated with AWS Loom and Amazon SageMaker Studio, and review CloudTrail logs for any anomalous activity originating from these services.
Compliance Best Practices
- Review and restrict user permissions within AWS Loom, specifically limiting who has `mcp:write` or `a2a:write` scopes to the minimum necessary personnel.
- Implement a formal review process for assigning 'project contributor' or higher permissions within Amazon SageMaker projects to enforce the principle of least privilege.
- Implement strict network egress filtering for services like AWS Loom to prevent them from making outbound connections to arbitrary internal or external endpoints.
- Develop and implement a formal process to track open-source software components, like AWS Loom, used in our environment and subscribe to their security bulletins.
- Establish and enforce secure configuration baselines for all deployed cloud services, ensuring that services like AWS Loom are never deployed in production with default, unauthenticated access enabled.
China-Nexus Longlegs Uses Microsoft SharePoint Vulnerabilities to Deploy Warlock Ransomware
The China-nexus threat actor Longlegs, also tracked as Storm-2603, is actively targeting critical infrastructure, government, and academic institutions across Portuguese- and Spanish-speaking regions in Europe, Africa, and Latin America, recently compromising a water utility and a telecommunications provider. Initial access is gained by exploiting Microsoft SharePoint Server vulnerabilities to deploy a webshell in the LAYOUTS directory, followed by harvesting ASP.NET machine keys to forge signed payloads. To maintain persistence and move laterally, the group utilizes DLL side-loading, abuses Visual Studio Code's remote tunneling feature, and creates a masqueraded domain account named `SPSEPRDSetup`. Defenses are systematically disabled using the vulnerable signed driver `K7RKScan` to terminate security processes at the kernel level. Ultimately, the threat actor leverages Active Directory SYSVOL replication to distribute and execute the Warlock ransomware domain-wide, recently compromising at least 40 hosts with defense-evasion tools and deploying ransomware on at least 33 hosts.
Severity: Critical
Threat Details and IOCs
| Malware: | ABCD ransomware, LockBit, LockBit 2.0, LockBit 3.0, LockBit Black, Warlock, WarLock, Water Manaul, X2anylock |
|---|---|
| CVEs: | CVE-2025-1055, CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, CVE-2025-53771 |
| Technologies: | K7 Ultimate Security, Microsoft Active Directory, Microsoft SharePoint Server, Microsoft Visual Studio Code, Microsoft Windows, Microsoft Windows Server |
| Threat Actors: | APT27, APT31, BronzeUnion, CamoFei, ChamelGang, ClCRI1040, EmissaryPanda, GOLDSALEM, LinenTyphoon, Longlegs, Play, Storm-2603, Storm2603, VioletTyphoon, Warlock, Zirconium |
| Attacker Countries: | China, Russia |
| Attacker IPs: | 104[.]238[.]159[.]149, 131[.]226[.]2[.]6, 134[.]199[.]202[.]205, 188[.]130[.]206[.]168, 65[.]38[.]121[.]198 |
| Attacker Domains: | catbox[.]moe, litter[.]catbox[.]moe, msupdate[.]updatemicfosoft[.]com, oastify[.]com, s3[.]wasabisys[.]com, update[.]updatemicfosoft[.]com, wasabisys[.]com, xn8xyt-drop[.]s3[.]wasabisys[.]com |
| Attacker URLs: | c34718cbb4c6[.]ngrok-free[.]app/file.ps1, hxxps[://]litter[.]catbox[.]moe/6f5tdt.msi, hxxps[://]s3[.]wasabisys[.]com/fortifs/vamd64.msi, hxxps[://]xn8xyt-drop[.]s3[.]wasabisys[.]com/xn8xyt.msi, hxxp[://]www[.]TARGET_DOMAIN[.]{RANDOM[.]oastify[.]com |
| Attacker Hashes: | 116ca4e88a1bcebb6c0da7fb431c8eca7b8ef3f9767194820c56091972ccac2c, 155fb1cbdaea12c83ba92d18c88cf38bbc42bb684f913ca0bc26fcf115426a55, 1eb914c09c873f0a7bcf81475ab0f6bdfaccc6b63bf7e5f2dbf19295106af192, 1edb2c0b537cd95bbd5fc16321b4c38a6adf325ccc7b588ad6acc980b0463b60, 206f27ae820783b7755bca89f83a0fe096dbb510018dd65b63fc80bd20c03261, 24480dbe306597da1ba393b6e30d542673066f98826cc07ac4b9033137f37dbf, 27b7591cf9e1283010ca98fa5dbe970a73fee0d8cde277639924c144718db7c0, 37f94fe1b4a106f02b6f74a69cbc05e69c17406f688beef4c9a045ffcbd2e65e, 445a37279d3a229ed18513e85f0c8d861c6f560e0f914a5869df14a74b679b86, 4c1750a14915bf2c0b093c2cb59063912dfa039a2adfe6d26d6914804e2ae928, 567cb8e8c8bd0d909870c656b292b57bcb24eb55a8582b884e0a228e298e7443, 62881359e75c9e8899c4bc9f452ef9743e68ce467f8b3e4398bebacde9550dea, 6753b840cec65dfba0d7d326ec768bff2495784c60db6a139f51c5e83349ac4d, 6b273c2179518dacb1218201fd37ee2492a5e1713be907e69bf7ea56ceca53a5, 6d07f1232dc59b84038fd0b2e75fdd3d5b825882bb0dba9e6724b7b0823fa3ad, 6f6db63ece791c6dc1054f1e1231b5bbcf6c051a49bad0784569271753e24619, 73c5268256c9da5488cd9e2b79013060ac321c7e54129344dc7b51e268af36ea, 7ae971e40528d364fa52f3bb5e0660ac25ef63e082e3bbd54f153e27b31eae68, 83705c75731e1d590b08f9357bc3b0f04741e92a033618736387512b40dab060, 8b58f7811a2a2f2a5024220490473774f02759dd2dd904b5b9fabfbaae37125f, 8ce8d8270ee9de02644530b8dd7fa78973b4a3b80f121e2c5f45ae68cce196f9, 92bb4ddb98eeaf11fc15bb32e71d0a63256a0ed826a03ba293ce3a8bf057a514, 9ceb01f8bf7d6dba2ae07f5bd6070de3ec67b5eb01f969b0ba85e74564fb83a7, aaff04d84ef85353966aa4af186ff1254b72c068f33f802417b29dc23fb9f192, ae9f7fce57c7b928e659dccf0e00fa79cd9cd61a106f18d4e03f92dc3a03c295, b180ab0a5845ed619939154f67526d2b04d28713fcc1904fbd666275538f431d, b5a78616f709859a0d9f830d28ff2f9dbbb2387df1753739407917e96dadf6b0, c27b725ff66fdfb11dd6487a3815d1d1eba89d61b0e919e4d06ed3ac6a74fe94, c2c1fec7856e8d49f5d49267e69993837575dbbec99cd702c5be134a85b2c139, c46825fcc0d1bf7a8b192facb176d6bf916c9dccfd6fa994be691e3b0e585f4e, d6da885c90a5d1fb88d0a3f0b5d9817a82d5772d5510a0773c80ca581ce2486d, e14240bac8277b0f6dd4d29ab5da20d246bcccae647e5fe8d19cdae7fe471b20, e3204b05e2f3a29bb6e6fcc21dda77d7cd31dfa755c21da0aa8661b5619ee0a1, eea631b5f7125239db0811e4682c2316ead69f9822e02d94fb5d8bf0d2faebed, f54ae00a9bae73da001c4d3d690d26ddf5e8e006b5562f936df472ec5e299441, f7269f80f81e99d06a590d7ab374e12fdf7e5f55a02c2a46c342d670f8519fdf, fb3846c9ac53d1b841ada3a6b1091153fea41a169cb44fe0084097d1f4d45984, ffbc9dfc284b147e07a430fe9471e66c716a84a1f18976474a54bee82605fa9a |
| Victim Industries: | Cloud Infrastructure, Education, Government, Telecommunications, Utilities, Water Supply |
| Victim Countries: | Brazil, Croatia, India, Japan, Portugal, Russia, Spain, Taiwan, Turkey, United States |
Mitigation Advice
- Immediately identify all on-premises Microsoft SharePoint servers and apply the latest security patches to mitigate the 'ToolShell' vulnerabilities.
- Add all file hashes listed in the article's Indicators of Compromise to your Endpoint Detection and Response (EDR) and antivirus blocklists.
- Block the domains and URLs listed in the article's Indicators of Compromise, such as 'catbox[.]moe' and 'wasabisys[.]com', at the web proxy, DNS filter, and firewall.
- Scan all endpoints and servers for the presence of malicious file names and paths mentioned in the article, such as 'run.exe', 'rune.exe', and 'layout2sp.aspx'.
- Hunt for suspicious command-line activity in security logs, specifically looking for the execution of 'net user /domain', 'whoami', 'nltest /domain_trusts', and 'nxc.exe'.
- Use endpoint security controls, such as Windows Defender Application Control (WDAC), to create a block rule for the vulnerable 'K7RKScan.sys' driver.
Compliance Best Practices
- Implement file integrity monitoring (FIM) on the SYSVOL share to generate alerts for the creation or modification of executable files and scripts.
- Implement a process to continuously audit and alert on any changes to privileged groups, such as local Administrators on servers and Domain Admins in Active Directory.
- Develop and deploy an application control policy using tools like AppLocker or Windows Defender Application Control (WDAC) to restrict the execution of unauthorized applications, scripts, and DLLs.
- Isolate public-facing servers, such as SharePoint, in a dedicated network segment (DMZ) with strict firewall rules that only allow necessary traffic to and from the internal network.
- Review and enable tamper protection features on all Endpoint Detection and Response (EDR) and antivirus agents to prevent them from being disabled or modified by unauthorized users or processes.
- Establish and enforce a policy to disable or restrict the use of remote tunneling features in developer tools like Visual Studio Code on production servers and standard user workstations.
- Enable PowerShell Script Block Logging and Module Logging on all Windows systems and forward these logs to a central SIEM for monitoring and analysis.
Anthropic's Mythos Model Discovers CVE-2026-61500 in Rejetto HFS Under Active Exploitation
A critical authentication-bypass vulnerability, tracked as CVE-2026-61500, has been discovered in Rejetto HTTP File Server (HFS) and is currently undergoing active exploitation in the wild. Discovered using Anthropic's Mythos AI model, the flaw allows attackers to forge valid session cookies and achieve remote code execution by exploiting cryptographic weaknesses in how HFS signs session cookies. Specifically, HFS relies on V8's insecure `Math.random()` pseudo-random number generator (PRNG) using the xorshift128+ algorithm; because the application leaks these outputs, the algorithm is fully reversible, allowing attackers to use a Satisfiability Modulo Theories (SMT) solver like Z3 to recover the PRNG seed. Active exploitation has been observed targeting hosts in the United States and Japan, initially originating from a China-hosted IP address and subsequently routing through US-based proxy IPs within the same subnet (173.239.211.248 and 173.239.211.249). Users of Rejetto HFS are urged to upgrade to version 3.2.1 or later to mitigate this vulnerability.
Severity: Medium
Threat Details and IOCs
| Malware: | HATVIBE |
|---|---|
| CVEs: | CVE-2024-23692, CVE-2026-61500 |
| Technologies: | Rejetto HTTP File Server |
| Attacker Countries: | China |
| Attacker IPs: | 173[.]239[.]211[.]248, 173[.]239[.]211[.]249 |
| Victim Countries: | Japan, United States |
Mitigation Advice
- Update all instances of Rejetto HTTP File Server (HFS) to version 3.2.1 or later immediately.
- Use a vulnerability scanner to discover all instances of Rejetto HTTP File Server (HFS) on the network and identify any versions older than 3.2.1.
- Add the IP addresses 173.239.211.248 and 173.239.211.249 to your firewall's blocklist.
- Search all firewall, web server, and network traffic logs for any connections to or from the IP addresses 173.239.211.248 and 173.239.211.249.
Compliance Best Practices
- Establish and maintain a comprehensive software asset inventory to ensure all applications, including open-source software, are tracked and managed.
- Implement a formal vulnerability management program that includes regular scanning, risk-based prioritization, and defined service-level agreements (SLAs) for patching.
- Implement network segmentation to isolate internet-facing servers and services from the internal corporate network.
- Incorporate secure coding training for developers, specifically covering the correct use of cryptographic libraries and the dangers of using non-secure random number generators for security-sensitive functions.


