CISA gave three days to fix FortiMail. Fortinet has not shipped the fix.
On 1 October Fortinet published advisory FG-IR-26-175 for CVE-2026-104286, a critical flaw in FortiMail, its secure email gateway. It scores CVSS 9.8, needs no credentials and no…
Read the brief