Skip to main content
FortinetCybersecurity incident

Fortinet's FortiMail product has a critical (9.8 CVSS) unauthenticated path traversal vulnerability allowing arbitrary file writes and potential code execution, which the company confirmed is...

What happened

Fortinet's FortiMail product has a critical (9.8 CVSS) unauthenticated path traversal vulnerability allowing arbitrary file writes and potential code execution, which the company confirmed is being actively exploited.

Source

Post

Highlighted: the lines this signal was extracted from

FortiMail has a 9.8 unauthenticated path traversal that allows arbitrary file writes and potentially code execution. Fortinet says it’s already being exploited. Some patched versions: upcoming. Security appliances continue their long tradition of occasionally becoming the thing you need security from.

reddit.com/r/sysadmin/comments/1wwlgqq/todays_reminder_that_every_sec...Read the full source

Comments on the post

5 of 55 comments
  • “There’s a big difference between exposing a security service to the Internet and exposing the whole box to the Internet. This is the reason you should default to allowing only what you need. That said, Fortigate has been downright terrible lately for racking up CVEs on the data plane and not just the control plane.”

    u/SevaraB128 points · Oct 3, 2026View

  • “Security Fortinet appliances continue their long tradition of occasionally becoming the thing you need security from. FTFY”

    u/OhMyInternetPolitics44 points · Oct 3, 2026View

  • “True, but some names come up more than others.”

    u/Zedilt17 points · Oct 3, 2026View

  • “Sometimes i feel that all we do with all these security products is move the goalposts, shuffle the vulnerabilities around…”

    u/Cormacolinde7 points · Oct 3, 2026View

  • “***Controversial Take Warning*** I am reading all these comments about Fortinet being an insecure vendor but when I searched a similar type of vulnerability that was published for Cisco Secure Email solution, I find very few mentions about it. About two weeks ago, the following vulnerabilities were posted by Cisco: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/c”

    u/afroman_says1 points · Oct 3, 2026View

Extracted by Autobound

From the Signal API record
Signal
Cybersecurity incident

What this signalsUser posts often show product pain before it reaches reviews or churn.

Subreddit
r/sysadmin
Stage
Confirmed
Event date
Oct 2026

The full record

From the Signal API record

Numbers

Mentions
25

Details

Timing
In progress
Category
Active exploitation
Virality
Very high
Post kind
Text
Prominence
Core
Company's role
Subject
Signal category
Event

Topics and mentions

Topics

  • security
  • vulnerability
  • email security
  • cve

Flair

  • General Discussion

Products named

  • FortiMail

Extraction

Sentiment
Negative
Detected
Oct 3, 2026
signal_type
reddit-company
signal_subtype
cybersecurityIncident

Use this data

Get every Reddit signal for Fortinet and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at Fortinet this week?”

  2. Send it to your own tools

    The Signal API returns Reddit signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full reddit-company record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/85577779-9237-5171-a472-952333964f58 returns this record as JSON. POST /v1/companies/enrich returns every signal for fortinet.com.

{
  "signal_id": "85577779-9237-5171-a472-952333964f58",
  "signal_type": "reddit-company",
  "signal_subtype": "cybersecurityIncident",
  "detected_at": "2026-10-03T11:58:46+00:00",
  "company": {
    "name": "Fortinet",
    "domain": "fortinet.com"
  },
  "data": {
    "nsfw": false,
    "stage": "confirmed",
    "awards": 0,
    "timing": "in_progress",
    "topics": [
      "security",
      "vulnerability",
      "cve",
      "email security"
    ],
    "post_id": "1wwlgqq",
    "summary": "Fortinet's FortiMail product has a critical (9.8 CVSS) unauthenticated path traversal vulnerability allowing arbitrary file writes and potential code execution, which the company confirmed is being actively exploited.",
    "category": "active_exploitation",
    "comments": [
      {
        "url": "https://www.reddit.com/r/sysadmin/comments/1wwlgqq/comment/pdljcz3/",
        "depth": 0,
        "score": 128,
        "author": "SevaraB",
        "excerpt": "There’s a big difference between exposing a security service to the Internet and exposing the whole box to the Internet.\n\n This is the reason you should default to allowing only what you need.\n\n That said, Fortigate has been downright terrible lately for racking up CVEs on the data plane and not just the control plane.",
        "posted_at": "2026-10-03T12:19:20.000Z",
        "author_url": "https://www.reddit.com/user/SevaraB/"
      },
      {
        "url": "https://www.reddit.com/r/sysadmin/comments/1wwlgqq/comment/pdlnzag/",
        "depth": 0,
        "score": 44,
        "author": "OhMyInternetPolitics",
        "excerpt": "Security Fortinet appliances continue their long tradition of occasionally becoming the thing you need security from.\n\n FTFY",
        "posted_at": "2026-10-03T12:46:20.000Z",
        "author_url": "https://www.reddit.com/user/OhMyInternetPolitics/"
      },
      {
        "url": "https://www.reddit.com/r/sysadmin/comments/1wwlgqq/comment/pdlgxqe/",
        "depth": 0,
        "score": 17,
        "author": "Zedilt",
        "excerpt": "True, but some names come up more than others.",
        "posted_at": "2026-10-03T12:04:27.000Z",
        "author_url": "https://www.reddit.com/user/Zedilt/"
      },
      {
        "url": "https://www.reddit.com/r/sysadmin/comments/1wwlgqq/comment/pdlj5dw/",
        "depth": 0,
        "score": 7,
        "author": "Cormacolinde",
        "excerpt": "Sometimes i feel that all we do with all these security products is move the goalposts, shuffle the vulnerabilities around…",
        "posted_at": "2026-10-03T12:18:03.000Z",
        "author_url": "https://www.reddit.com/user/Cormacolinde/"
      },
      {
        "url": "https://www.reddit.com/r/sysadmin/comments/1wwlgqq/comment/pdog29o/",
        "depth": 0,
        "score": 1,
        "author": "afroman_says",
        "excerpt": "***Controversial Take Warning***\n\n I am reading all these comments about Fortinet being an insecure vendor but when I searched a similar type of vulnerability that was published for Cisco Secure Email solution, I find very few mentions about it. About two weeks ago, the following vulnerabilities were posted by Cisco:\n\n https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/c",
        "posted_at": "2026-10-03T20:26:49.000Z",
        "author_url": "https://www.reddit.com/user/afroman_says/"
      },
      {
        "url": "https://www.reddit.com/r/sysadmin/comments/1wwlgqq/comment/pdmkw1c/",
        "depth": 0,
        "score": 1,
        "author": "pAlelane02",
        "excerpt": "this is why segmenting management interfaces onto their own vlan with strict ACLs matters so much. doesnt fix the vuln but at least shrinks the blast radius while you wait for a patch that may or may not exist yet",
        "posted_at": "2026-10-03T15:28:47.000Z",
        "author_url": "https://www.reddit.com/user/pAlelane02/"
      },
      {
        "url": "https://www.reddit.com/r/sysadmin/comments/1wwlgqq/comment/pdmb2c2/",
        "depth": 0,
        "score": 1,
        "author": "Dingadingdangmy",
        "excerpt": "What’s the gold standard for security among the names?\n\n I’m aware the best practice is to harden my own infra under the care of a ciso or opsec sme but at some point there has to be an appliance or institution whose name I am subscribing to.",
        "posted_at": "2026-10-03T14:43:40.000Z",
        "author_url": "https://www.reddit.com/user/Dingadingdangmy/"
      },
      {
        "url": "https://www.reddit.com/r/sysadmin/comments/1wwlgqq/comment/pdpn5x3/",
        "depth": 0,
        "score": 1,
        "author": "hubbyofhoarder",
        "excerpt": "Our HR people were on us forever to get them a secure email appliance. No; use Purview encryption. I'm not interested in adding another thing to scan and secure, particularly one full of juicy PII",
        "posted_at": "2026-10-04T00:03:14.000Z",
        "author_url": "https://www.reddit.com/user/hubbyofhoarder/"
      }
    ],
    "evidence": [
      "[post] FortiMail has a 9.8 unauthenticated path traversal that allows arbitrary file writes and potentially code execution.",
      "[post] Fortinet says it’s already being exploited.",
      "[post] Some patched versions: upcoming."
    ],
    "virality": "very_high",
    "post_date": "2026-10-03T11:58:46.000Z",
    "post_kind": "text",
    "post_text": "FortiMail has a 9.8 unauthenticated path traversal that allows arbitrary file writes and potentially code execution. Fortinet says it’s already being exploited.\n\nSome patched versions: upcoming.\n\nSecurity appliances continue their long tradition of occasionally becoming the thing you need security from.",
    "sentiment": "negative",
    "subreddit": "sysadmin",
    "event_date": "2026-10",
    "post_flair": [
      "General Discussion"
    ],
    "post_title": "Today’s reminder that every security appliance is also just another web application you exposed to the Internet",
    "prominence": "core",
    "source_url": "https://www.reddit.com/r/sysadmin/comments/1wwlgqq/todays_reminder_that_every_security_appliance_is/",
    "entity_role": "subject",
    "post_author": "Haunting_Ganache_850",
    "upvote_ratio": 0.9636363636363636,
    "mention_count": 25,
    "mention_surge": true,
    "subreddit_url": "https://www.reddit.com/r/sysadmin/",
    "total_upvotes": 357,
    "comments_total": 55,
    "total_comments": 55,
    "event_date_text": "Today’s",
    "post_author_url": "https://www.reddit.com/user/Haunting_Ganache_850/",
    "signal_category": "event",
    "comments_included": 11,
    "products_mentioned": [
      "FortiMail"
    ]
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.