Your Email Gateway Is the Way In: FortiMail Zero-Day CVE-2026-104286 Is Under Attack, There’s No Patch, and CISA’s Deadline Is Tomorrow
Attackers are writing files onto Fortinet FortiMail email security gateways without logging in. Fixed builds for the main branches are still pending, CISA wants it handled by October 4, and the obvious upgrade path for 7.2 customers still lands on a vulnerable release. DataWater Threat Intelligence Desk | Published October 3, 2026 | 8-minute read…
