CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Fortinet warns of critical FortiMail flaw exploited in zero-day attacks

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 9201

As cited

Copy frozen at (site build).

vulnerabilities

Fortinet warns of critical FortiMail flaw exploited in zero-day attacks

Fortinet disclosed CVE-2026-104286, a critical FortiMail vulnerability with a CVSS score of 9.8 that attackers are actively exploiting in zero-day attacks. The flaw allows remote code execution on vulnerable devices.

Why it matters: Organizations running FortiMail must patch immediately; this vulnerability is listed on the Known Exploited Vulnerabilities (KEV) catalog and is under active exploitation.

VendorsFortinet
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary