CISA lists FortiMail path traversal flaw CVE-2026-104286 as actively exploited

What happened
CVE-2026-104286, a path traversal vulnerability in Fortinet's FortiMail email security product, entered CISA's Known Exploited Vulnerabilities (KEV) catalog on October 1, 2026, on evidence of active exploitation. The Hacker News reported the same day that the flaw is a zero-day that lets an unauthenticated attacker write arbitrary files. CISA's alert does not say who is exploiting the flaw, how many systems are affected, or whether a patch exists.
What we know
- Per CISA, CVE-2026-104286 is a Fortinet FortiMail path traversal vulnerability, added to the KEV catalog on October 1, 2026.
- CISA says KEV additions are based on evidence of active exploitation.
- The Hacker News's headline calls the flaw a critical zero-day, exploited in attacks, that allows unauthenticated arbitrary file writes.
- CISA's alert cites Binding Operational Directive (BOD) 26-04, which requires US federal civilian agencies to prioritize fast remediation of KEV-listed flaws on publicly exposed assets that give total control after exploitation.
- BOD 26-04 also sets expectations for agencies to check whether attackers compromised a system before the patch was applied. CISA encourages all organizations, not only federal agencies, to follow risk-based remediation of KEV entries.
What we don't know yet
- Whether a vendor patch or mitigation is available. The CISA alert text we have does not name one, and the usable text of The Hacker News article was not available to us.
- Who is exploiting the flaw, how many FortiMail systems have been compromised, and which versions are affected.
- Whether the CVE in CISA's entry is the same flaw The Hacker News describes. The two sources are consistent on product and timing, but CISA's alert does not mention file writes or the zero-day label.
- Whether FortiMail deployments fall under BOD 26-04's criteria for publicly exposed assets that grant total control. CISA's alert states the criteria in general terms and does not apply them to this entry.
Why it matters
Organizations running FortiMail, which handles inbound and outbound corporate email, now have a government-listed exploited flaw to check. US federal civilian agencies are bound to prioritize it under BOD 26-04 and to look for compromise that predates any patch.
Claims
- ConfirmedCISA added CVE-2026-104286, a Fortinet FortiMail path traversal vulnerability, to its Known Exploited Vulnerabilities catalog on October 1, 2026.
- ConfirmedCISA added the flaw to the KEV catalog based on evidence of active exploitation.
- UnconfirmedThe FortiMail flaw is a zero-day that allows unauthenticated arbitrary file writes.
- ConfirmedCISA's alert states that BOD 26-04 applies only to US Federal Civilian Executive Branch agencies.
Why you can trust this story
79%Source map · 2 outlets / 2 articles
- The Hacker News
- CISA
- Article 1cisa.govofficial
How this credibility score is calculated
- Source reliability
- Corroboration
- Primary source
- Atom-verified claims
- No contradiction
- Settled
- Claim attribution
- AI disclosure
Atom-verified claims matched cited source text. Weights are fixed and explainable.
Human accountability
- 2 independent origins / 2 sources
- Drafted by the Newsmesis judgment agent (agent-cli); human approval required before publishing.
Verification ledger · 4
- Claim: CISA added CVE-2026-104286, a Fortinet FortiMail path traversal vulnerability, to its Known Exploited Vulnerabilities catalog on October 1, 2026.Status: ConfirmedVerification trailVerifiedChecked by verification engine
At least one extracted atom matched cited source full text.
- Claim: CISA added the flaw to the KEV catalog based on evidence of active exploitation.Status: ConfirmedVerification trailVerifiedChecked by verification engine
At least one extracted atom matched cited source full text.
- Claim: The FortiMail flaw is a zero-day that allows unauthenticated arbitrary file writes.Status: UnconfirmedVerification trailUnverifiedChecked by verification engine
No atom-level source-text verification is available.
- Claim: CISA's alert states that BOD 26-04 applies only to US Federal Civilian Executive Branch agencies.Status: ConfirmedVerification trailVerifiedChecked by verification engine
At least one extracted atom matched cited source full text.
Update log · 0
AI accelerates. Humans approve.