FortiMail CVE-2026-104286: No Patch, No Authentication Required, No Excuse to Wait
CISA has added an unauthenticated, actively exploited FortiMail zero-day to its KEV catalog. There's no patch yet, only a workaround, which means detection and containment are doing the job a fix usually would.















