Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

FortiMail Path Traversal (CVE‑2026‑104286) Added to CISA KEV Catalog – Critical Remote Code Risk

CISA has listed Fortinet FortiMail CVE‑2026‑104286 in its Known Exploited Vulnerabilities catalog, confirming active exploitation. Organizations must prioritize remediation to satisfy risk‑based vulnerability‑management controls and maintain audit‑ready evidence.

LiveThreat™ Intelligence · 📅 October 02, 2026· 📰 cisa.gov
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
4 recommended
📰
Source
cisa.gov

FortiMail Path Traversal (CVE‑2026‑104286) Added to CISA KEV Catalog – Critical Remote Code Risk

What It Is – Fortinet disclosed a path‑traversal flaw in FortiMail that allows an unauthenticated attacker to read arbitrary files on the underlying system and potentially achieve full control.

Exploitability – The vulnerability is confirmed to be actively exploited in the wild; CISA has placed it in the Known Exploited Vulnerabilities (KEV) catalog. No public proof‑of‑concept is required to trigger the flaw.

Affected Products – Fortinet FortiMail email security appliances (all versions prior to the vendor‑released patch).

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for a continuous vulnerability‑management control that tracks, prioritises, and remediates high‑risk flaws across the asset inventory.
  • Provides audit‑ready evidence that organisations are aligning with risk‑based remediation mandates such as CISA’s BOD 26‑04 and the NIST CSF “Identify – Risk Assessment” function.
  • Enables a defensible posture for customers and regulators by showing that known‑exploited vulnerabilities are patched promptly, reducing the likelihood of a breach that could compromise data integrity.

Recommended Actions

  • Confirm whether any FortiMail devices are in‑scope and publicly reachable.
  • Apply Fortinet’s security update for CVE‑2026‑104286 immediately; document the patch date.
  • Update your vulnerability‑management tool to flag KEV catalog entries as high priority.
  • Capture remediation evidence (patch tickets, scan results) for audit trails.

Source: CISA Alert – Known Exploited Vulnerability Added (CVE‑2026‑104286)

📰 Original Source
https://www.cisa.gov/news-events/alerts/2026/10/01/cisa-adds-one-known-exploited-vulnerability-catalog ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →