U.S. CISA adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog
Brief
U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog.
The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added a Fortinet FortiMail flaw, tracked as CVE-2026-104286 (CVSS score of 9. 8), to its Known Exploited Vulnerabilities (KEV) catalog .
The flaw is a path traversal vulnerability that can be triggered through specially crafted HTTP or HTTPS requests. An unauthenticated attacker can exploit the issue to bypass restrictions on file paths and write arbitrary files to the underlying system.
The vulnerability also involves improper handling of NULL characters, which can help the attacker bypass security checks. The flaw is reportedly being exploited in the wild, so affected customers are urged to apply the recommended workaround.
