Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes
CISA adds a critical Fortinet FortiMail vulnerability to its Known Exploited Vulnerabilities catalog after reports of active attacks. Tracked as CVE-2026-104286 with a CVSS score of 9.8, the flaw lets unauthenticated attackers write arbitrary files on the system.
