Image: securityaffairs.com · rights & removal
U.S. CISA adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog
Reporting by Security Affairs (Pierluigi Paganini)Read the original at securityaffairs.com
Executive Summary
Facts Only
* CISA added Fortinet FortiMail flaw CVE-2026-104286 to its Known Exploited Vulnerabilities (KEV) catalog.
* The flaw is a path traversal vulnerability triggered by specially crafted HTTP or HTTPS requests.
* An unauthenticated attacker can exploit this to bypass file path restrictions and write arbitrary files on the underlying system.
* The vulnerability involves improper handling of NULL characters, which aids in bypassing security checks.
* Affected versions and solutions include: FortiMail 8.0 (8.0.0 through 8.0.1) requires upgrade to 8.0.2 or above; FortiMail 7.6 (7.6.0 through 7.6.6) requires upgrade to 7.6.7 or above; FortiMail 7.4 (7.4.0 through 7.4.8) requires upgrade to 7.4.9 or above; FortiMail 7.2 (7.2.0 through 7.2.9) requires upgrading to branch 7.4 or above.
* Workarounds include disabling the IBE feature using a CLI command or blocking external internet access to the management interface.
* CISA orders federal agencies to fix the flaw by October 3rd, 2026.
Full Take
The pattern of cataloging and publicizing severe vulnerabilities like this demonstrates a systemic tension between rapid threat notification and the operational reality faced by organizations in applying necessary mitigations. The existence of specific version-based fixes implies a structure where security efficacy is contingent upon vendor responsiveness, which itself relies on external pressure from bodies like CISA. The need for immediate workarounds—disabling features or restricting network access—highlights a gap: the infrastructure often cannot pause operations to implement patches immediately without incurring significant operational risk, forcing a choice between immediate tactical defense and long-term systemic remediation. Furthermore, the reliance on public disclosure of specific version ranges creates an information asymmetry; while the vulnerability exists and is exploited in the wild, the granularity of customer exposure remains undisclosed by the vendor, leading entities to rely on generalized advice rather than comprehensive threat modeling against their specific configurations. This dynamic reveals a persistent issue where abstract risk categorization (CVSS score) meets concrete operational necessity (the need for immediate procedural changes).
Bridge Questions: If operational constraints prevent immediate patching, what internal governance structures can be established to prioritize mitigation strategies against known KEVs? How does the public mandate for federal agencies interact with the continuous security posture management of private entities? What are the secondary costs—both financial and organizational—of relying on temporary workarounds rather than immediate, permanent remediation?
From the original · Security Affairs (Pierluigi Paganini)
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Fortinet FortiMail flaw, tracked as CVE-2026-104286 (CVSS score of 9.8), to its Known Exploited Vulnerabilities (KEV) catalog. The flaw is a path traversal vulnerability that can be triggered through specially crafted HTTP or HTTPS requests.Read the full story at securityaffairs.com
Sentinel — Human
The text reads like a faithful summary of an official security advisory, characterized by precise technical detail and adherence to documented procedural requirements.
