INCIBE-CERT warns of critical vulnerabilities in Fortinet's FortiMail and HPE's Intelligent Management Center
INCIBE-CERT has published advisories on a critical path traversal vulnerability in FortiMail and an authentication bypass in HPE Intelligent Management Center. Both products are commonly used by Spanish companies for email and network management.

News summary
On 8 October 2026, INCIBE-CERT published an advisory on a critical path traversal vulnerability in FortiMail, Fortinet's email gateway. The following day, it added another advisory, also critical, on an authentication bypass in HPE Intelligent Management Center (IMC), HPE's network management platform.
In the same batch, INCIBE-CERT also covered seven Cisco vulnerabilities (one critical and six high), twenty-two from Splunk, and a new buffer overflow in Citrix's NetScaler ADC and Gateway. The week's events confirm that email, network, and remote access equipment remain the primary front.
A compromised email gateway provides access to all of a company's message traffic; a network management console provides access to the configuration of switches and routers. For this reason, these products should not be exposed to the internet more than is strictly necessary.
INCIBE-CERT's advisories link to each manufacturer's official bulletins, which specify the affected and patched versions. This is the guidance that must be followed before applying updates.
Source: INCIBE-CERT — 9 October 2026
Frequently Asked Questions
- Are these vulnerabilities already being exploited?
- The cited advisories describe the severity and the fix; to determine if there is active exploitation, you should consult the manufacturer's bulletin and the CISA KEV catalogue.
- Where can I consult the official advisories in Spain?
- In the early warning advisories section of INCIBE-CERT, which summarises each vulnerability and links to the manufacturer's source.
Concepts mentioned in this article: Vulnerability
Keeping email, network, and remote access up to date requires a methodical approach. At Seintec, we review your inventory, prioritise critical patches, and eliminate unnecessary exposure. Speak with our cybersecurity team.
Contact SeintecRelated service
Cybersecurity
We shield your business so it never stops.