Skip to content
eastbaycyber

CISA Adds 1 Known Exploited Vulnerability to Catalog (October 1, 2026)

Source: CISA KEV Catalog · Updated 2026-10-01

Summary

On October 1, 2026, CISA added 1 vulnerability to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-104286. A KEV listing means CISA has evidence of active exploitation. CISA sets a remediation due date for US federal civilian agencies under its binding operational directives; any organization running the affected products should treat these as patch-now priorities.

CVE-2026-104286: Fortinet FortiMail Path Traversal Vulnerability

Fortinet · FortiMail

Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

Federal due date
2026-10-04
Ransomware use
Unknown
Added
2026-10-01

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

NVD record · Fortinet KEV history

Check whether you run these products: our vulnerability scanner comparison covers tools that detect KEV-listed flaws. See also the KEV dashboard and KEV history by vendor.