CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-104286 Fortinet FortiMail Path Traversal Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security…
Read at CISA Cybersecurity Advisories
CVE-2026-104286Exploited
- Severity
- 9.8 Critical · CVSS 3.1 · Fortinet
- Exploited
- Since 2026-10-01 (CISA)
- CISA deadline
- 2026-10-04
- Published
- Fortinet FortiMail
Affected: 8.0.0; 7.6.0 through 7.6.5; 7.4.0 through 7.4.6; 7.2.0 through 7.2.9; 7.0.0 through 7.0.9