LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingCVE-2026-7273 · Zyxel GS1900 Switch Flaw Exploited, Now in EU CatalogueCVE-2026-102489 · Zammad Session Fixation Vulnerability Exploited Same Day as DisclosureCVE-2026-102490 · Zammad GmbH Zammad Vulnerability Exploited Same Day as Publication
cve recordhighexploited in the wildzero day3 of 3 cataloguesexploit reported

CVE-2026-104286

Fortinet · FortiMail · Fortinet FortiMail Path Traversal Vulnerability

· Added to CISA KEV
CVSS—
Severityhigh
Weakness—
EPSS2.2%81.9th percentile
Exploited3 KEV sources
Ransomware useUnknown
Federal fix dueOct 4, 2026
patch window

Called exploited the same day it was disclosed.

Measured from the CVE publication date to the earliest of 3 KEV catalogues that list it.

The life of this vulnerability

  1. CVE reserved
  2. CVE publishedsame day
  3. First KEV listingsame day
  4. Last sightingsame day

Gaps are compressed to equal steps. The elapsed time is printed under each.

Which catalogues call it exploited

Sources3 of 3
Listings differ by0 d
Strongest claimconfirmed

3 catalogues list it. CIRCL aggregates the others and is shown but not counted.

Public exploitation evidence

2 public reports collected from VulnCheck and CIRCL, first on Oct 1, 2026. Each links to its original source. We have not verified them.

Description

Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

Required action (CISA)

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-104286

CVE-2026-88771critical

Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploited

A 16-year-old security researcher has identified a vulnerability in Microsoft's internal analytics service, Titan, which could have exposed employee records and Bing search analytics. The flaw reportedly provided access to 17 trillion rows of data. Microsoft has not yet issued a public statement confirming the details of the vulnerability or its remediation.

CVE-2026-104286critical

Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action

A critical-severity zero-day vulnerability, tracked as CVE-2026-104286, has been reported in Fortinet's FortiMail email security gateway. The flaw is described as a path traversal vulnerability that permits attackers to write arbitrary files to the underlying system. Organizations leveraging FortiMail deployments are advised to take immediate mitigation steps due to the active exploitation of…

CVE-2026-104286critical

U.S. CISA adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Fortinet FortiMail vulnerability, identified as CVE-2026-104286, to its Known Exploited Vulnerabilities (KEV) catalog. The flaw, which carries a CVSS score of 9.8, is a path traversal vulnerability that attackers are reportedly exploiting in the wild.

CVE-2026-104286critical

Fortinet warns of critical FortiMail flaw exploited in zero-day attacks

Fortinet has issued a warning regarding a critical vulnerability in its FortiMail email security platform, identified as CVE-2026-104286, which is actively being exploited in zero-day attacks. The flaw, rated with a CVSS score of 9.8, affects the FortiMail management interface and could allow an unauthenticated attacker to execute arbitrary code or commands.

CVE-2026-104286high

Fortinet FortiMail Path Traversal Flaw Exploited Same Day as Disclosure

A path traversal vulnerability in Fortinet FortiMail was exploited on the same day it was disclosed, leaving no patch window for affected organizations.