CISA Adds One Known Exploited Vulnerability to Catalog
Summary
CISA has added CVE-2026-104286, a path traversal vulnerability in Fortinet FortiMail, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. This addition reinforces the importance of Binding Operational Directive (BOD) 26-04 for federal agencies, which mandates prioritizing remediation of high-risk vulnerabilities like those in the KEV Catalog on publicly exposed assets.
IFF Assessment
The inclusion of a new exploited vulnerability in CISA's KEV catalog indicates a new active threat that defenders must address.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: October 04, 2026. Known ransomware use: Unknown.
Defender Context
Defenders should prioritize patching or mitigating CVE-2026-104286, especially if they utilize Fortinet FortiMail. The inclusion in CISA's KEV catalog means this vulnerability is actively being exploited, posing an immediate risk to affected systems.