
Critical FortiMail and Cisco SD-WAN Zero-Days Under Active Exploitation
Security agencies have issued urgent warnings following the active exploitation of critical zero-day vulnerabilities in Fortinet FortiMail and Cisco Catalyst SD-WAN Manager, leading to CISA KEV inclusion.
Encrygma is selling the entire Full Cyber Weapon Research of Critical FortiMail and Cisco SD-WAN Zero-Days Under Active Exploitation for ₿ 0.10 BTC. Contact us.
Executive Takeaway — TL;DR
- Category:
- Zero-Day Exploits
- Severity:
- Critical
- Actor Type:
- APT
- Geography:
- Global
- Confidence:
- Confirmed
- CVE:
- CVE-2026-104286, CVE-2026-76504
- Source:
- CISA / Fortinet / Cisco
- Read Time:
- 4 min
Executive Summary
In the last 48 hours, the cybersecurity landscape has been dominated by the active exploitation of two critical zero-day vulnerabilities affecting enterprise infrastructure. Fortinet has confirmed that CVE-2026-104286, a critical flaw in FortiMail, is being leveraged by threat actors to achieve arbitrary file writes. Simultaneously, Cisco is managing the fallout from CVE-2026-76504, an authentication bypass vulnerability in its Catalyst SD-WAN Manager that has also been confirmed as exploited in the wild. Both vulnerabilities have been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, mandating immediate remediation for federal agencies.
Threat Analysis
The rapid weaponization of these vulnerabilities suggests a coordinated effort by sophisticated threat actors to target edge devices. The FortiMail vulnerability (CVE-2026-104286) allows unauthenticated remote attackers to bypass security controls, while the Cisco SD-WAN flaw (CVE-2026-76504) provides a gateway for unauthorized access to critical network management interfaces. These exploits are particularly dangerous as they target the perimeter, providing attackers with a foothold to move laterally within corporate networks.
Technical Details
CVE-2026-104286 in FortiMail (CVSS 9.8) stems from a combination of path traversal (CWE-22) and improper handling of NULL bytes (CWE-158). By sending specially crafted HTTP/HTTPS requests, an attacker can write arbitrary files to the underlying system. Cisco’s CVE-2026-76504 involves an API authentication bypass that allows unauthenticated users to interact with the SD-WAN Manager, potentially leading to full system compromise. Both vulnerabilities were identified as being exploited in the wild, with evidence of modified system files observed in real-world incidents.
Attribution Assessment
While specific threat actor groups have not been publicly named by vendors, the nature of these exploits—targeting high-value network appliances—is consistent with the tactics, techniques, and procedures (TTPs) of state-sponsored Advanced Persistent Threat (APT) groups. The speed at which these vulnerabilities were weaponized following disclosure indicates a high level of technical capability and pre-existing exploit development pipelines.
Implications
Organizations relying on FortiMail and Cisco Catalyst SD-WAN are at immediate risk of data exfiltration, persistent backdoor installation, and potential ransomware deployment. The inclusion of these flaws in the CISA KEV catalog underscores the severity of the threat to both public and private sector entities.
Recommendations
- Immediate Patching: Apply the latest security updates provided by Fortinet and Cisco without waiting for standard maintenance cycles.
- Compromise Assessment: Audit affected systems for unauthorized file modifications, unexpected administrative accounts, or anomalous API traffic.
- Perimeter Hardening: Restrict access to management interfaces to trusted IP ranges and implement multi-factor authentication where applicable.
- Monitoring: Enhance logging for HTTP/HTTPS requests directed at edge appliances to detect potential exploitation attempts.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Critical Zero-Day Exploitation Surge: FortiMail and Cisco SD-WAN Under Active Attack

Critical Cisco SD-WAN Manager Zero-Day Under Active Exploitation

