CISA has added CVE-2026-104286, a critical Fortinet FortiMail flaw, to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild. Fortinet says the issue can let unauthenticated attackers write arbitrary files on affected FortiMail systems, and it has issued mitigations and upgrade guidance for impacted versions. #Fortinet #FortiMail #CVE-2026-104286
Keypoints
- CISA added CVE-2026-104286 to the KEV catalog due to active exploitation.
- The flaw affects Fortinet FortiMail and has a CVSS score of 9.8.
- It allows unauthenticated attackers to write arbitrary files through crafted HTTP or HTTPS requests.
- Fortinet advised disabling IBE support and limiting management interface access.
- Federal Civilian Executive Branch agencies must patch or apply workarounds by October 4, 2026.
Read More: https://thehackernews.com/2026/10/critical-fortimail-zero-day-flaw.html