CISA adds Fortinet FortiMail zero-day CVE-2026-104286 to KEV catalog
Situation Overview
On 2 October 2026, the US Cybersecurity and Infrastructure Security Agency (CISA) added a critical Fortinet FortiMail vulnerability, CVE-2026-104286, to its Known Exploited Vulnerabilities (KEV) catalog following reports of active exploitation. The flaw, rated CVSS 9.8, allows unauthenticated attackers to write arbitrary files on the underlying system. The KEV listing signals that defenders should prioritize remediation for FortiMail systems exposed to the internet. Fortinet is the vendor of the affected product, while CISA is the US agency issuing the KEV directive and maintaining the catalog used to drive federal and sector response. No other scheduled actions or deadlines were reported in the cluster beyond the KEV addition and the need to patch affected systems.
Geopolitical Implications
- 01
US government KEV action highlights ongoing cross-sector pressure to remediate actively exploited vulnerabilities in critical enterprise communication security tooling.
- 02
Actively exploited zero-days in email security can accelerate broader cyber incident risk for organizations operating across US critical infrastructure and government-adjacent networks.
Key Signals
- —
Whether CISA issues additional guidance or updates to the KEV entry for CVE-2026-104286.
- —
Vendor patch releases and deployment guidance for FortiMail systems exposed to the internet.
- —
Reports of exploitation indicators and attacker TTPs tied to CVE-2026-104286.
Topics & Keywords
Market Impact Analysis
Premium Intelligence
Create a free account to unlock detailed analysis
AI Threat Assessment
Premium Intelligence
Create a free account to unlock detailed analysis
Event Timeline
Premium Intelligence
Create a free account to unlock detailed analysis
Related Intelligence
- CRITICAL
Three max-severity ServiceNow flaws, a root-level cPanel bug, and an actively exploited PaperCut zero-day—are enterprises about to get hit?
USOct 3 - CRITICAL
Microsoft Entra ID CVE-2026-69836: a CVSS 10.0 RCE is already exploited—while MANTRA’s chain halts
USOct 3 - CRITICAL
Iran warns it will end “moderation” and target US interests as US political signals and Balkan outreach unfold
IROct 3 - CRITICAL
Iran–US escalation tightens Hormuz controls as cyberattacks and oil-flow disruptions intensify
IROct 3 - CRITICAL
Russia tightens internal control and internet access while drone and cyber incidents disrupt regional infrastructure
RUOct 3 - CRITICAL
UN Chief Warns Against Attacks on Civilian Infrastructure as US-Iran Deadline Rhetoric Escalates
USOct 3
Full Access
Unlock Full Intelligence Access
Real-time alerts, detailed threat assessments, entity networks, market correlations, AI briefings, and interactive maps.
Request a demo