Status: KEV
| Advisory ID: CVE-2026-104286
Key Details
| CVE | CVE-2026-104286 |
| Affected products | Fortinet FortiMail |
| Exploitation status | Listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed active exploitation. |
| Classified as | CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')) |
| KEV listing | Added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2026-10-01. |
| Federal remediation deadline | 2026-10-04 (CISA KEV, Binding Operational Directive). |
Affected Products, Subsystems & Sectors
| Subsystems | General OT |
| Sectors | Multiple |
What to Know
Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.
What to Do
Monitor Fortinet's web page for any future patch releases.
References
KEV Required Action