CVE-2026-104286 actively exploited: Fortinet FortiMail Path Traversal Vulnerability

CISA added CVE-2026-104286, a path traversal in Fortinet FortiMail, to its Known Exploited Vulnerabilities catalogue. It may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. Federal agencies must remediate by October 4, 2026.

The CISA Known Exploited Vulnerabilities entry details a security flaw in Fortinet FortiMail, describing it as a path traversal and improper neutralization of NULL byte or NULL character issue. This defect potentially enables unauthenticated attackers to place arbitrary files on the host system by sending specially crafted HTTP or HTTPS requests. Federal agencies must implement vendor-specified mitigations in line with BOD 26-04 risk-based prioritization and forensics triage requirements. If mitigations are absent, entities should halt product usage or follow cloud-specific BOD 26-04 directives. Stakeholders bear the responsibility for assessing internet exposure and strictly adhering to the established patching guidelines. The mandate for remediation expires on 2026-10-04. The available text does not confirm any usage of this vulnerability in known ransomware campaigns.