TThe Hacker NewsinCVE·critical
CISA Adds Actively Exploited FortiMail Zero-Day to Known Exploited Vulnerabilities Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-104286 to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerability, affecting Fortinet FortiMail, has a CVSS score of 9.8 and allows unauthenticated attackers to write arbitrary files on the underlying system. CISA's action follows reports of active exploitation in the wild prior to the catalog addition.
11m
