Decrypted: The UK Cyber Briefing
Oct 3, 2026 · 5 min · 8 segments
Attackers are exploiting CVE-2026-104286, a 9.8-rated flaw in FortiMail's encryption feature that lets them write files without logging in. Also: MI5's alert on China-funded research and a Danish…
FortiMail's encryption portal let attackers write files without logging in.
The mail gateway is meant to check the post before it reaches your staff.
This week, Fortinet confirmed that attackers are using a flaw in its FortiMail product to write their own files onto that gateway without logging in.
Fortinet published its advisory on first October.
CISA added the flaw, CVE-2026-104286, to its Known Exploited Vulnerabilities Catalog the same day.
US federal agencies have a deadline of 4th October.
Next: what the flaw does.
FortiMail's encryption portal let attackers write files without logging in.
The mail gateway is meant to check the post before it reaches your staff.
This week, Fortinet confirmed that attackers are using a flaw in its FortiMail product to write their own files onto that gateway without logging in.
Fortinet published its advisory on first October.
CISA added the flaw, CVE-2026-104286, to its Known Exploited Vulnerabilities Catalog the same day.
US federal agencies have a deadline of 4th October.
Next: what the flaw does.
The rest of this transcript — segmented and speaker-labeled, so you land on the exact moment something was said
Search every transcript — by keyword, by phrase, or by meaning, across every show Radar indexes
Trends — what is surging across podcasts, measured against its own baseline
Alerts — when a name you follow appears in a newly indexed episode
No account is needed to search Radar.