CISA has added CVE-2026-104286 to the KEV catalog, confirming active exploitation of an unauthenticated path traversal flaw in Fortinet FortiMail that can let an attacker write arbitrary files to the underlying system.
What Is It
CVE-2026-104286 is a path traversal vulnerability (CWE-22) in Fortinet FortiMail. CISA's KEV entry also lists an improper neutralization of NULL byte or NULL character weakness (CWE-158). An unauthenticated attacker can send crafted HTTP or HTTPS requests to write arbitrary files on the underlying system.
Fortinet's PSIRT, the CNA, scored the flaw CVSS 3.1 9.8 (Critical) with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. It can be exploited over the network with low complexity, and it needs no privileges or user interaction. NVD lists the record as "Awaiting Analysis."
Why It Matters
CISA's KEV catalog confirms active exploitation. CISA added the CVE on 2026-10-01 and set a remediation due date of 2026-10-04, three days later. CISA's SSVC assessment rates exploitation as "active," the flaw as "automatable," and the technical impact as "total."
The KEV entry also flags the vulnerability for forensic triage. That means affected organizations are expected to look for signs of compromise, not just patch. Known ransomware campaign use is listed as "Unknown."
FortiMail is an email security gateway that is often exposed to the internet. An unauthenticated file-write bug in a device like this deserves immediate attention.
What's Vulnerable
The NVD description lists these affected FortiMail versions:
- 8.0.0 through 8.0.1
- 7.6.0 through 7.6.6
- 7.4.0 through 7.4.8
- 7.2.0 through 7.2.9
The structured affected-version data in the same record does not match the description exactly. It lists 8.0.0, 7.6.0–7.6.5, 7.4.0–7.4.6 and 7.2.0–7.2.9, and it also includes 7.0.0–7.0.9. Until the two are reconciled, check your version against Fortinet advisory FG-IR-26-175 and treat any FortiMail on the 7.0 through 8.0 branches as potentially affected.
Patch Status
The supplied data does not name fixed versions. Refer to Fortinet PSIRT advisory FG-IR-26-175 for vendor mitigations.
CISA's required action:
- Apply mitigations according to the vendor's instructions.
- Follow BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's Forensics Triage Requirements.
- Follow BOD 26-04 guidance for cloud services, or stop using the product if no mitigations are available.
Stakeholders are also responsible for evaluating each asset's internet exposure. Federal agencies must comply by 2026-10-04.