Fortinet has confirmed active exploitation of CVE-2026-104286, a CVSS 9.8 flaw in FortiMail. Here is what it does, who is affected and what to do before a fix reaches you.
Tag:
email security
-
-
A critical Cisco email gateway vulnerability shows why perimeter security appliances need the same scrutiny and testing as the applications they protect.
-
A Russian state-backed campaign against Zimbra webmail went straight for 2FA backup codes, not passwords. Here is why that part of MFA gets ignored, and what to do about it.
-
Google’s Threat Analysis Group found a critical Zimbra XSS vulnerability in the Classic Web Client that lets a crafted email hijack a live session. Zimbra has patched it in version …