CISA added CVE-2026-104286 to its Known Exploited Vulnerabilities (KEV) catalogue on 1 October 2026. The vulnerability affects Fortinet FortiMail and is named the Fortinet FortiMail Path Traversal Vulnerability. It allows an unauthenticated attacker to write arbitrary files to the underlying system using crafted HTTP or HTTPS requests.
The flaw combines path traversal with improper neutralisation of a NULL byte or NULL character. An attacker does not need to authenticate, and can exploit the issue remotely through web requests. The vulnerability has a CVSS score of 9.8 and is rated Critical. The available data does not confirm whether a patch is available.
CISA has confirmed active exploitation by adding the vulnerability to the KEV catalogue. The data does not identify use in ransomware campaigns. Federal Civilian Executive Branch (FCEB) agencies must remediate CVE-2026-104286 by 4 October 2026.
CISA requires agencies to apply mitigations in accordance with vendor instructions, while complying with BOD 26-04, “Prioritizing Security Updates Based on Risk”, and CISA’s “Forensics Triage Requirements”. Agencies must follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders must assess each asset’s internet exposure and follow BOD 26-04 patching guidance. All organisations should review their FortiMail deployments and exposure.
See the NVD entry and CISA KEV catalogue for full details.