A CVSS 9.8 zero-day in Fortinet FortiMail is being exploited in the wild, and CISA has added it to the Known Exploited Vulnerabilities catalog. When the vulnerability is an unauthenticated arbitrary file write on an email security gateway, the blast radius extends to every mail flow that appliance touches. Today’s brief also covers a new GlobalProtect buffer overflow, Microsoft losing control of its own X account, and a Pentagon HR breach affecting nearly 3 million people.

In the News

FortiMail Zero-Day Exploited in the Wild - CISA KEV-Listed

CVE-2026-104286 is a critical path traversal vulnerability in Fortinet FortiMail with a CVSS score of 9.8. The flaw allows unauthenticated remote attackers to write arbitrary files to FortiMail systems - no credentials, no user interaction, no preconditions beyond network reachability. CISA confirmed active exploitation and added the CVE to the Known Exploited Vulnerabilities catalog.

FortiMail is deployed inline on email flows, which means a compromise does not just affect the appliance - it gives an attacker a write primitive on the system responsible for scanning, filtering, and routing inbound and outbound mail. The initial exploitation details have not been fully disclosed, but path traversal to arbitrary file write is a well-understood chain: write a webshell, establish persistence, pivot.

Fortinet has released patches. Organizations running FortiMail should treat this as an emergency patch cycle. For environments where immediate patching is not possible, isolating FortiMail management interfaces from untrusted networks and monitoring for unexpected file creation on the appliance are interim compensating controls - but they are not substitutes for patching.

What defenders should do: Patch FortiMail immediately. Audit FortiMail systems for indicators of compromise - unexpected files in web-accessible directories, anomalous outbound connections, and new scheduled tasks or cron entries. Review CISA KEV for binding operational directive timelines.

Palo Alto GlobalProtect Buffer Overflow - CVE-2026-0250

Palo Alto Networks disclosed CVE-2026-0250, a medium-severity buffer overflow in the GlobalProtect App that triggers during Portal or Gateway connection. No exploitation has been reported, and the CVSS score reflects the local attack complexity involved. Patches are available.

The operational risk here is not the current severity - it is the target. GlobalProtect is one of the most widely deployed VPN clients in enterprise environments, and VPN client vulnerabilities have a consistent history of being weaponized quickly once disclosed. The disclosure-to-exploitation window for VPN-class vulnerabilities has compressed to days in recent campaigns.

What defenders should do: Patch GlobalProtect at the next maintenance window. For organizations evaluating long-term VPN alternatives, this is another data point in the ZTNA/SSE migration conversation - replacing the client-side VPN attack surface with a zero-trust access model that does not require a persistent agent with elevated privileges on the endpoint.

Microsoft’s Official X Account Hijacked for Crypto Scam

Attackers compromised Microsoft’s 13-million-follower X account and used it to promote a Clippy-themed cryptocurrency pump-and-dump scheme. The takeover was brief, but the reach was massive - 13 million followers exposed to a fraudulent token promotion under the Microsoft brand.

The incident highlights a control gap that exists in most enterprises: social media accounts for major brands often sit outside the identity governance perimeter. They are managed through third-party tools, delegated to agencies, and protected with platform-native MFA rather than enterprise-grade identity controls. An attacker who compromises the credentials or session tokens for these accounts bypasses every network and endpoint control the organization has deployed.

What defenders should do: Treat high-follower social media accounts as privileged accounts. Enforce phishing-resistant MFA, monitor for anomalous session activity, and ensure that social media management platforms are integrated into the enterprise identity provider - not running on standalone credentials.

Pentagon HR System Breached - Nearly 3 Million Records Stolen

The Defense Manpower Data Center’s human resources management system was compromised in October 2025, exposing personal data for nearly 3 million current and former Department of Defense personnel. The stolen dataset includes names, Social Security numbers, and employment records - a high-value target for both espionage and identity fraud.

The disclosure came nearly a year after the initial compromise. While attribution has not been publicly confirmed, HR systems are a known priority target for nation-state actors because they map organizational structure, identify individuals with security clearances, and provide PII that enables targeted social engineering.

What defenders should do: Microsegment HR and PII-heavy application environments. Implement data loss prevention controls that detect bulk data exfiltration from HR platforms. Enforce identity-based access policies that restrict which users, devices, and network segments can reach HR systems.

Defender Action Items

  • FortiMail (CVE-2026-104286): Emergency patch cycle. Audit for webshells, unexpected file writes, and anomalous outbound connections from FortiMail appliances. If patching is delayed, isolate management interfaces from untrusted networks immediately.
  • GlobalProtect (CVE-2026-0250): Patch at next maintenance window. Evaluate ZTNA/SSE migration to reduce long-term VPN client attack surface.
  • Social media account hygiene: Audit all high-follower brand accounts for phishing-resistant MFA enforcement, SSO integration, and session monitoring. Treat them as privileged accounts.
  • HR system segmentation: Review network segmentation around HR platforms. Implement DLP controls and anomaly detection for bulk data access patterns.

Detection Queries

FortiMail file write detection - look for unexpected file creation in web-accessible directories. This Splunk SPL query identifies new files written to common webshell paths on FortiMail appliances. Adjust the index and sourcetype to match your FortiMail log ingestion.

index=fortimail sourcetype=fortimail:log
| search action="file_write" OR action="create"
| where match(file_path, "(?i)\.(php|jsp|asp|aspx|cgi|sh)$")
| stats count earliest(_time) AS first_seen latest(_time) AS last_seen BY src_ip file_path file_name
| where first_seen > relative_time(now(), "-7d")
| sort -count

Supplement with endpoint detection for any FortiMail system forwarding logs to your SIEM. Look for new processes spawned by the FortiMail web server process, unexpected cron entries, or outbound connections to previously unseen IP addresses.

References


Subscribe to it-learn Brief

Get it-learn Brief in your inbox (Mon–Fri) - Daily cybersecurity news, SE angles, and detection queries.