Zero-Day · Fortinet · Active Exploitation · CISA KEV
CVE-2026-104286: Fortinet Disclosed This FortiMail Zero-Day With No Patch Ready for Any Branch
Fortinet disclosed CVE-2026-104286, a CVSS 9.8 path traversal flaw in FortiMail, with active exploitation already underway and no fixed release available for any affected branch. Here's the mechanism, the IOCs to check, and the workaround Fortinet is recommending until patches ship.