Fortinet warns of critical FortiMail flaw exploited in zero-day attacks
Fortinet says CVE-2026-104286 in the FortiMail management interface is already being exploited as a zero-day — CVSS 9.8, path traversal plus a NULL byte trick, and an unauthenticated attacker gets to write arbitrary files over HTTP. CISA gave federal agencies until October 4 to mitigate. The fixed builds are still listed as upcoming, so the real mitigation today is getting that management interface off the public internet.