Skip to main content

INCIBE-CERT warns of critical vulnerabilities in Fortinet's FortiMail and HPE's Intelligent Management Center

INCIBE-CERT has published advisories on a critical path traversal vulnerability in FortiMail and an authentication bypass in HPE Intelligent Management Center. Both products are commonly used by Spanish companies for email and network management.

CybersecuritySeintec team2-3 min read
INCIBE-CERT warns of critical vulnerabilities in Fortinet's FortiMail and HPE's Intelligent Management Center

News summary

On 8 October 2026, INCIBE-CERT published an advisory on a critical path traversal vulnerability in FortiMail, Fortinet's email gateway. The following day, it added another advisory, also critical, on an authentication bypass in HPE Intelligent Management Center (IMC), HPE's network management platform.

In the same batch, INCIBE-CERT also covered seven Cisco vulnerabilities (one critical and six high), twenty-two from Splunk, and a new buffer overflow in Citrix's NetScaler ADC and Gateway. The week's events confirm that email, network, and remote access equipment remain the primary front.

A compromised email gateway provides access to all of a company's message traffic; a network management console provides access to the configuration of switches and routers. For this reason, these products should not be exposed to the internet more than is strictly necessary.

INCIBE-CERT's advisories link to each manufacturer's official bulletins, which specify the affected and patched versions. This is the guidance that must be followed before applying updates.

Source: INCIBE-CERT — 9 October 2026

Frequently Asked Questions

Are these vulnerabilities already being exploited?
The cited advisories describe the severity and the fix; to determine if there is active exploitation, you should consult the manufacturer's bulletin and the CISA KEV catalogue.
Where can I consult the official advisories in Spain?
In the early warning advisories section of INCIBE-CERT, which summarises each vulnerability and links to the manufacturer's source.

Concepts mentioned in this article: Vulnerability

Keeping email, network, and remote access up to date requires a methodical approach. At Seintec, we review your inventory, prioritise critical patches, and eliminate unnecessary exposure. Speak with our cybersecurity team.

Contact Seintec

Related service

Cybersecurity

We shield your business so it never stops.

Next step

Would you like to implement these improvements in your company?

Speak with a Seintec expert and we will review how this applies to your infrastructure together.