What the CISA KEV Listing for CVE-2026-104286 Tells Defenders
A signal, not a formality
CISA added CVE-2026-104286 to the Known Exploited Vulnerabilities catalog on October 1, 2026. The FortiMail path traversal carries a CVSS score of 9.8 and, according to Fortinet, has been exploited in the wild.
KEV inclusion is not a severity rating. It is a statement that reliable evidence of exploitation exists. That distinction changes how the finding should be prioritized relative to other critical-severity items in the same backlog.
What the flaw does
The vulnerability combines path traversal (CWE-22) with improper neutralization of a NULL byte (CWE-158). Crafted HTTP or HTTPS requests allow an unauthenticated attacker to write files outside the intended directory. Fortinet lists the impact as the ability to execute unauthorized code or commands.
Obligations and timelines
Federal civilian executive branch agencies operating under BOD 26-04 had an October 4, 2026 deadline to act. The directive also sets expectations for checking whether a system was compromised before remediation, which is a useful pattern for organizations outside the federal scope.
For everyone else, the practical reading is that the exploitation window opened before the patch existed. Networks that exposed the FortiMail management interface to the internet should assume the window applies to them.
Using the catalog well
A KEV entry is most valuable as an input to prioritization, not as a substitute for it. Teams should pair the listing with their own asset data to work out which appliances were reachable, then decide between immediate mitigation and full replacement.
References
- Fortinet PSIRT advisory FG-IR-26-175 covering CVE-2026-104286.
- CISA alert, "CISA Adds One Known Exploited Vulnerability to Catalog," October 1, 2026: https://www.cisa.gov/news-events/alerts/2026/10/01/cisa-adds-one-known-exploited-vulnerability-catalog
- CVE.org entry: https://www.cve.org/CVERecord?id=CVE-2026-104286
- securityonline.info report: https://securityonline.info/fortimail-vulnerability-cve-2026-104286/
Top comments (0)