← Back to briefings

U.S. CISA Adds Fortinet FortiMail Flaw to Known Exploited Vulnerabilities Catalog

Cybersecurity2026-10-02·4 min read

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-104286, a critical zero-day in Fortinet's FortiMail, to its Known Exploited Vulnerabilities catalog on October 2, 2026.

The flaw allows unauthenticated attackers to write arbitrary files directly to the underlying operating system of exposed FortiMail appliances.

Fortinet warned customers on October 1 that the path traversal vulnerability was being exploited in the wild and urged immediate patching.

CISA issued an emergency directive requiring federal civilian agencies to address the vulnerability by October 3, 2026, providing a three-day remediation deadline.

The vulnerability affects FortiMail versions 7.2.0 through 7.2.9, 7.4.0 through 7.4.8, 7.6.0 through 7.6.6, and 8.0.0 through 8.0.1.

As an email gateway, FortiMail sits at the network perimeter and processes all incoming and outgoing email, making successful exploits particularly dangerous.

The exploitation could lead to operating system compromise, data theft, or email interception and manipulation.

Federal agencies and private organizations are urged to review the vulnerability and apply patches to protect their networks and data.

Source: Security Affairs. This article summarizes the linked reporting and distinguishes announced plans from demonstrated results.