search
CVE-2026-104286
Trends
- 1Citrix and Fortinet zero-days under active exploitation●Recent news highlights critical cybersecurity threats as Citrix NetScaler (CVE-2026-88772) and FortiMail (CVE-2026-10428
Security researchers warn that newly disclosed zero-day vulnerabilities in Citrix NetScaler (CVE-2026-88772) and FortiMail (CVE-2026-104286) are being actively exploited, with critical infrastructure and government organisations among the targets. Apple has separately patched a CoreGraphics flaw already used in attacks. Administrators are urged to apply patches urgently and review systems for signs of compromise.
- 2CISA Flags Actively Exploited Critical FortiMail Flaw●CISA adds CVE-2026-104286 (CVSS 9.8) to KEV—critical flaw in Fortinet FortiMail allowing unauthenticated attackers to wr
CISA has added CVE-2026-104286 to its Known Exploited Vulnerabilities catalog after reports of active attacks. The flaw, rated 9.8 out of 10 in severity, affects Fortinet's FortiMail and lets unauthenticated attackers write arbitrary files on vulnerable servers. Security teams are urged to patch immediately, as the flaw is described as a zero-day already being exploited in the wild.
- 3FortiMail zero-day actively exploited with no patch available●2026-W40 — Weekly Threat Roundup 🔥 A zero-day in Fortinet FortiMail (CVE-2026-104286) is actively exploited with no patc
A weekly threat roundup reports that a zero-day vulnerability in Fortinet's FortiMail, tracked as CVE-2026-104286, is being actively exploited while no patch is available, forcing administrators to rely on interim workarounds. The same roundup notes Operation KillSwitch dismantled the KillSec ransomware group, allegedly run by a 16-year-old, with seizures reportedly carried out.
- 4Fortinet FortiMail Bug CVE-2026-104286 Actively Exploited●Fortinet FortiMail CVE-2026-104286 Actively Exploited: Critical Path Traversal and NULL Byte Vulnerability Alert
Fortinet has a critical vulnerability, tracked as CVE-2026-104286, in its FortiMail email security product. The flaw involves path traversal combined with NULL byte handling, and security researchers report it is being actively exploited in the wild. Administrators are being urged to apply patches immediately to prevent attackers from compromising mail servers.