On October 1, 2026, CISA added CVE-2026-104286, a path traversal flaw in Fortinet FortiMail, to the KEV catalog, citing evidence of active exploitation.
CISA said it added CVE-2026-104286 to the Known Exploited Vulnerabilities (KEV) catalog. The path traversal flaw affects Fortinet FortiMail and, according to the alert, there is evidence of active exploitation. The agency describes vulnerabilities of this type as a frequent attack vector and points to significant risks for the federal sector.
Directive BOD 26-04 sets requirements for US Federal Civilian Executive Branch agencies, including prioritizing fixes for KEV vulnerabilities on publicly exposed assets when exploitation enables full control of the asset. It also sets expectations for checking possible compromise before applying a patch. The directive does not apply to all organizations; CISA recommends that all organizations use risk-based vulnerability management and prioritize KEV flaws. Consult CISA’s original alert and confirm the identification, mitigation, and product status with the vendor’s official sources.