CISA adds a critical Fortinet FortiMail vulnerability to its Known Exploited Vulnerabilities catalog after reports of active attacks. Tracked as CVE-2026-104286 with a CVSS score of 9.8, the flaw lets unauthenticated attackers write arbitrary files on the system.
Organizations using FortiMail face an actively exploited flaw that permits unauthenticated file writes. Its inclusion in CISA’s KEV catalog makes it a high-priority issue for security teams.