Fortinet patches a FortiMail zero-day already exploited to write arbitrary files
CVE-2026-104286, rated CVSS 9.8, lets an unauthenticated attacker write arbitrary files on FortiMail's management interface through a path traversal combined with a NULL byte. No fix is out yet — disable IBE and take the admin console off the internet.