CISA Adds Fortinet FortiMail 0-day Vulnerability to KEV Following Active Exploitation

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


The U.S. Cybersecurity and Infrastructure Security Agency has added a critical Fortinet FortiMail vulnerability (CVE-2026-104286) , to its Known Exploited Vulnerabilities catalog after evidence of active exploitation.

The flaw affects Fortinet FortiMail, an email-security product commonly deployed at the network perimeter to filter malicious emails and protect enterprise messaging systems.

An unauthenticated remote attacker could exploit the issue by sending specially crafted HTTP or HTTPS requests to a vulnerable FortiMail appliance. Successful exploitation may allow the attacker to write arbitrary files to the underlying system.

CVE-2026-104286 is a path traversal flaw caused by improper NULL-byte neutralization, allowing attackers to manipulate file paths to access or write files outside intended directories.

Fortinet FortiMail 0-day Vulnerability Exploitation

NULL-byte handling weaknesses can help attackers bypass input-validation controls that rely on incorrectly processed file names or extensions. The vulnerability is associated with CWE-22 and CWE-158.

CISA added the vulnerability to the KEV catalog on October 1, 2026, and set an October 4, 2026, remediation deadline for affected federal civilian executive branch agencies.

The agency requires organizations to apply vendor-recommended mitigations in line with Binding Operational Directive 26-04, which prioritizes security updates according to risk.

CISA’s KEV entry for CVE-2026-104286 does not link the flaw to ransomware, but exploitation of internet-facing email-security appliances could provide high-impact initial access.

Arbitrary file-write access could potentially enable threat actors to place malicious files, alter configurations, establish persistence, or prepare systems for follow-on compromise, depending on the appliance configuration and file permissions.

CISA also marked the issue as requiring forensic triage under BOD 26-04. Organizations using FortiMail should identify all exposed devices, verify whether they are affected, apply Fortinet’s prescribed mitigation or security update, and review logs for suspicious HTTP or HTTPS requests.

Security teams should also inspect for unexpected files, changes to system configurations, unauthorized accounts, and unusual outbound network activity.

Where an effective mitigation is unavailable, CISA advises stakeholders to follow applicable guidance for cloud services or discontinue use of the affected product.

Organizations should prioritize externally accessible FortiMail deployments because internet exposure increases the likelihood of opportunistic scanning and exploitation.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC

The post CISA Adds Fortinet FortiMail 0-day Vulnerability to KEV Following Active Exploitation appeared first on Cyber Security News.