CISA added critical Fortinet FortiMail flaw CVE-2026-104286 to its KEV catalog following evidence of active exploitation.