CISA Adds Actively Exploited FortiMail Zero-Day to Known Exploited Vulnerabilities Catalog
CVE-2026-104286: Unauthenticated Arbitrary File Write Flaw Affects Fortinet FortiMail

Key Takeaways
- CISA has added CVE-2026-104286 to the KEV catalog due to reports of active exploitation.
- The vulnerability affects Fortinet FortiMail email security appliances.
- CVSS score: 9.8 (Critical).
- The flaw allows unauthenticated attackers to write arbitrary files on the underlying system.
Related Security News

GitLab warns of critical RCE vulnerability in AI Gateway service
GitLab has identified a critical remote code execution vulnerability in its AI Gateway service. The flaw requires immediate patching to prevent potential arbitrary command execution on vulnerable instances. Details of active exploitation are currently unreported, but the vendor has urged customers to update to the latest patched version without delay.

Kiteworks and Citrix Face Zero-Day Response Challenges
Reports indicate that Kiteworks instructed customers to power down its data-protection platform during a nine-hour window amid a zero-day incident, while Citrix released a patch without prior public disclosure of active attacks. Both cases underscore the operational difficulties in coordinating zero-day responses and the impact of communication gaps on customer environments.

