cisaregulatorNewsThe Broadside1 min read

CISA Adds Fortinet FortiMail Path-Traversal CVE to KEV Catalog

The binding remediation requirement stops at FCEB agencies; everyone else gets CISA's encouragement, not a mandate.


TL;DR

CISA added CVE-2026-104286, a Fortinet FortiMail path-traversal vulnerability, to the Known Exploited Vulnerabilities Catalog after evidence of active exploitation. Under BOD 26-04, the listing brings rapid-remediation prioritization for FCEB agencies when the asset is publicly exposed and grants total control after exploitation, with lower-risk work deferred. The directive binds only FCEB agencies; for contractors it's CISA's encouragement, not a requirement.

CISA added CVE-2026-104286, a Fortinet FortiMail path-traversal vulnerability, to its Known Exploited Vulnerabilities Catalog on evidence of active exploitation. That entry is the entire update: no new directive, no new enforcement mechanism. It follows this week's KEV additions for Apple and Cisco products.

The operative document is BOD 26-04, Prioritizing Security Updates Based on Risk. It requires Federal Civilian Executive Branch agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically KEV-listed CVEs on publicly exposed assets that grant total control of the asset after exploitation, while deferring lower-risk work. It also sets expectations for checking whether a threat actor already compromised the system before the patch was applied. CISA calls path traversal a frequent attack vector, but the notice doesn't state whether this FortiMail flaw meets the directive's total-control threshold.

For a contractor, the directive's reach is the point. BOD 26-04 binds FCEB agencies, not vendors; CISA's language for everyone else is "encourages." Whether any federal customer agreement separately transposes KEV remediation into a vendor obligation is unanswered here. The Monday question is narrower: is the FortiMail gateway internet-facing, and has it been patched?


Published ·Deep Fathom