CISA Flags Actively Exploited Fortinet FortiMail Vulnerability
CISA has added a newly identified vulnerability, CVE-2026-104286, affecting Fortinet FortiMail, to its Known Exploited Vulnerabilities (KEV) Catalog. The flaw is a path traversal vulnerability, a type of weakness attackers commonly use to access files or data they should not be able to reach. CISA confirmed this vulnerability is being actively exploited in the wild.
Federal agencies are required under a binding directive to remediate such high-risk, actively exploited vulnerabilities quickly, particularly on systems exposed to the internet. While this requirement applies only to US federal agencies, CISA recommends all organisations treat KEV Catalog entries as priority patching items, since these are vulnerabilities proven to be used by real attackers rather than theoretical risks.
Australian businesses using FortiMail for email security should check Fortinet's advisories for patch availability and apply updates promptly. Since FortiMail is often internet-facing to handle mail traffic, unpatched systems present an attractive target for attackers seeking initial access into business networks.