CISA KEV mandate for FortiMail CVE-2026-104286
Public Sector Action
Summary
Hide ▲
Show ▼
CISA added CVE-2026-104286 to the Known Exploited Vulnerability catalog and required federal agencies to perform forensic triage and mitigate the FortiMail flaw by October 4. The action escalates the federal response to an actively exploited zero-day affecting the FortiMail management interface. It puts a concrete remediation deadline on agencies that may have exposed appliances. The catalog listing signals that the vulnerability is already treated as a live operational risk.
Related Happenings
Fortinet FortiMail mitigation guidance for CVE-2026-104286
Advisory/Mitigation
H score49
First: 02.10.2026 01:42
Last: 02.10.2026 01:42
Sources 1
How related:
Fortinet says the flaw is being actively exploited and is urging customers to apply the shared workarounds until a security update can be installed.
About this happening:
Fortinet issued mitigation guidance for CVE-2026-104286 in FortiMail, warning administrators to use workarounds while the flaw is being actively exploited. The adv...
Fortinet FortiMail mitigation guidance for CVE-2026-104286
Advisory/MitigationHow related: Fortinet says the flaw is being actively exploited and is urging customers to apply the shared workarounds until a security update can be installed.
About this happening: Fortinet issued mitigation guidance for CVE-2026-104286 in FortiMail, warning administrators to use workarounds while the flaw is being actively exploited. The adv...
FortiMail actively exploited path traversal and NULL-byte flaw (CVE-2026-104286)
Vulnerability
H score43
First: 02.10.2026 01:42
Last: 02.10.2026 01:42
Sources 1
How related:
Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices.
About this happening:
Fortinet FortiMail is facing an actively exploited CVE-2026-104286 flaw that lets unauthenticated attackers write arbitrary files and run unauthorized code on vulnerable d...
FortiMail actively exploited path traversal and NULL-byte flaw (CVE-2026-104286)
VulnerabilityHow related: Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices.
About this happening: Fortinet FortiMail is facing an actively exploited CVE-2026-104286 flaw that lets unauthenticated attackers write arbitrary files and run unauthorized code on vulnerable d...
CISA KEV remediation deadlines for exploited CVEs
Public Sector Action
H score34
First: 25.09.2026 20:24
Last: 25.09.2026 20:24
Sources 1
About this happening:
CISA added CVE-2026-5430 and CVE-2026-71362 to the KEV catalog and set September 27 remediation deadlines for federal agencies using the affected products. Age...
CISA KEV remediation deadlines for exploited CVEs
Public Sector ActionAbout this happening: CISA added CVE-2026-5430 and CVE-2026-71362 to the KEV catalog and set September 27 remediation deadlines for federal agencies using the affected products. Age...
CISA KEV listing of Check Point flaws and three-day federal patch mandate
Public Sector Action
H score36
First: 23.09.2026 09:14
Last: 23.09.2026 09:14
Sources 1
About this happening:
CISA added Check Point's exploited zero-day and CVE-2026-85102 to the KEV catalog, triggering a three-day federal patch clock under BOD 26-04. The action f...
CISA KEV listing of Check Point flaws and three-day federal patch mandate
Public Sector ActionAbout this happening: CISA added Check Point's exploited zero-day and CVE-2026-85102 to the KEV catalog, triggering a three-day federal patch clock under BOD 26-04. The action f...
CISA adds CVE-2026-68820 to KEV catalog
Public Sector Action
H score3
First: 12.08.2026 09:41
Last: 12.08.2026 09:41
Sources 1
About this happening:
CISA added CVE-2026-68820 to the Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to apply fixes by August 25, 2026. The action formal...
CISA adds CVE-2026-68820 to KEV catalog
Public Sector ActionAbout this happening: CISA added CVE-2026-68820 to the Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to apply fixes by August 25, 2026. The action formal...
Timeline
-
02.10.2026 01:42 1 articles · 1h ago
Fortinet warns of actively exploited FortiMail zero-day CVE-2026-104286
Initial DisclosureFortinet warned customers that CVE-2026-104286 is a critical FortiMail vulnerability being actively exploited in zero-day attacks to execute unauthorized code or commands through the FortiMail management interface. The flaw affects FortiMail 7.2.0 through 7.2.9, 7.4.0 through 7.4.8, 7.6.0 through 7.6.6, and 8.0.0 through 8.0.1, and Fortinet published workarounds, upcoming fixed versions, indicators of compromise, and log entries tied to compromised appliances.
Show sources
- Fortinet warns of critical FortiMail flaw exploited in zero-day attacks — www.bleepingcomputer.com — 02.10.2026 01:42
-
02.10.2026 01:42 2 articles · 1h ago
CISA adds CVE-2026-104286 to the Known Exploited Vulnerability catalog
Legal Policy Action UpdateCISA added CVE-2026-104286 to the Known Exploited Vulnerability catalog and required federal agencies to perform forensic triage and mitigate the FortiMail flaw by October 4th. The action escalates the response to an actively exploited FortiMail zero-day and places a deadline on affected federal environments.
Show sources
- Fortinet warns of critical FortiMail flaw exploited in zero-day attacks — www.bleepingcomputer.com — 02.10.2026 01:42
- Fortinet warns of critical FortiMail flaw exploited in zero-day attacks — www.bleepingcomputer.com — 02.10.2026 01:42