CISA Adds Exploited FortiMail Path Traversal Flaw to KEV Catalog

High · Security Affairs ·

CISA KEV · Exploited

Key points

  • CVE-2026-104286 is a path traversal flaw in Fortinet's FortiMail.
  • It has a CVSS score of 9.8 and is being actively exploited.
  • CISA added it to the KEV catalog, requiring federal agencies to patch.
  • All organizations using FortiMail should apply mitigations immediately.

The U.S. CISA has placed a weakness impacting Fortinet's FortiMail secure email gateway into its Known Exploited Vulnerabilities catalog. CVE-2026-104286 identifies a flaw involving directory traversal, assigned a CVSS severity rating of 9.8. Its inclusion in the KEV catalog signals that attackers are actively exploiting it in real-world campaigns.

FortiMail is widely deployed by organizations to filter email threats. Any unpatched instance is potentially vulnerable. A path traversal flaw allows an attacker to manipulate file paths to access directories and files outside the intended scope. Because email gateways are often exposed to the internet, they present a high-value target for malicious actors seeking initial access or data theft.

The near-maximum CVSS rating reflects both the ease of exploitation and the potential for severe impact. CISA's KEV catalog mandates that U.S. federal agencies remediate listed vulnerabilities within a specified timeframe, but the warning applies to all sectors. For K-12 schools, which handle sensitive student and staff information, this vulnerability demands immediate attention.

While the facts do not specify whether Fortinet has released a patch, organizations should monitor the vendor's advisories. The KEV addition is a clear indicator that waiting is not an option. IT teams should also review their logging and detection capabilities to identify any exploitation attempts.

Going forward, watch for updated guidance from CISA and Fortinet. Prioritize this vulnerability in your patching cycle, and consider temporary mitigations if a patch is not yet available. The active exploitation status makes this a top-tier threat.

What to do now

  1. Inventory all FortiMail deployments and confirm their software versions immediately.
  2. Apply the latest Fortinet security update as soon as it becomes available; if unavailable, implement vendor-recommended workarounds.
  3. If patching is delayed, restrict internet-facing access to FortiMail or place it behind a VPN or IP allowlist.
  4. Inspect logs for unusual file access patterns, traversal attempts, or signs of compromise.
  5. Subscribe to CISA's KEV catalog alerts and integrate them into your vulnerability management workflow.
  6. Report any suspected exploitation to CISA and Fortinet promptly.
  7. For federal agencies, ensure remediation is completed by the KEV-mandated deadline.

CVE references

  • CVE-2026-104286

Original source

Security Affairs

Original AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.

← All cyber news