FortiMail Path Traversal (CVE‑2026‑104286) Added to CISA KEV Catalog – Critical Remote Code Risk
What It Is – Fortinet disclosed a path‑traversal flaw in FortiMail that allows an unauthenticated attacker to read arbitrary files on the underlying system and potentially achieve full control.
Exploitability – The vulnerability is confirmed to be actively exploited in the wild; CISA has placed it in the Known Exploited Vulnerabilities (KEV) catalog. No public proof‑of‑concept is required to trigger the flaw.
Affected Products – Fortinet FortiMail email security appliances (all versions prior to the vendor‑released patch).
Why It Matters for Trust & Control Assurance
- Demonstrates the need for a continuous vulnerability‑management control that tracks, prioritises, and remediates high‑risk flaws across the asset inventory.
- Provides audit‑ready evidence that organisations are aligning with risk‑based remediation mandates such as CISA’s BOD 26‑04 and the NIST CSF “Identify – Risk Assessment” function.
- Enables a defensible posture for customers and regulators by showing that known‑exploited vulnerabilities are patched promptly, reducing the likelihood of a breach that could compromise data integrity.
Recommended Actions
- Confirm whether any FortiMail devices are in‑scope and publicly reachable.
- Apply Fortinet’s security update for CVE‑2026‑104286 immediately; document the patch date.
- Update your vulnerability‑management tool to flag KEV catalog entries as high priority.
- Capture remediation evidence (patch tickets, scan results) for audit trails.
Source: CISA Alert – Known Exploited Vulnerability Added (CVE‑2026‑104286)