Fortinet rates FortiMail CVE-2026-104286 critical at CVSS 9.8; FG-IR-26-175 lists fixes as upcoming and publishes only an IBE or management-interface workaround

Operators of exposed FortiMail gateways have a vendor-confirmed unauthenticated file-write flaw, a known-exploited flag, and no shipped patch on the 8.0, 7.6, or 7.4 branches. IN BRIEF: On October 1, 2026, Fortinet published PSIRT advisory FG-IR-26-175 for CVE-2026-104286, a critical…