Critical FortiMail zero-day exploited in the wild (CVE-2026-104286)

Fortinet is warning customers that attackers are exploiting a zero-day vulnerability (CVE-2026-104286) in FortiMail, its email security gateway. Fortinet says the flaw has been reported to be exploited in the wild, and urges customers to apply the workaround it shared until fixes are available…

security

Sources

Vulnerabilities

Why this score
Signals contributing to the severity score
SignalPoints
kev added50
kev short fuse — 3 days to remediate15
ssvc active35
cvss critical — 9.820
widely deployed15
Critical FortiMail zero-day exploited in the wild (CVE-2026-104286) · TechNews