
Security
CVE-2026-104286: FortiMail exploited as a zero-day, patch pending
Fortinet issued an advisory on Thursday 1 October 2026 for CVE-2026-104286, a critical FortiMail admin interface flaw already exploited as a zero-day. No fix exists for the 7.4, 7.6 and 8.0 branches: only workarounds protect exposed appliances.