The Circuitry
THE CIRCUITRYYour one-stop source for all tech news
HOMETODAYNEWSFEEDEVENTS
BOOKMARKS
RSS
© 2026 The Circuitry
About UsSourcesContactCorrectionsPrivacy
  • Today
  • Feed
  • Events
  • Saved
Scroll for more
Verification
VERIFIEDConfidence: HIGH
Source identified
Claims cross-referenced
No discrepancies found
Fact-check summary

CISA added CVE-2026-104286 (Fortinet FortiMail path traversal) to its KEV catalog on October 1, 2026, per the official catalog entry.

Sourcing
1source

via CISA KEV

CISA KEV · track record
14Stories
100%Verified
830d
All sources →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
Home/Tech/CISA adds Fortinet FortiMail path traversal flaw to KEV catalog
VERIFIEDBy Xavier Rivera· ·1 min read

CISA adds Fortinet FortiMail path traversal flaw to KEV catalog

CISA added CVE-2026-104286 in Fortinet FortiMail to its Known Exploited Vulnerabilities catalog on October 1, confirming active exploitation. Mitigations must be applied by October 4 or discontinue use where fixes are unavailable.

Source:CISA KEV
Post
CISA adds Fortinet FortiMail path traversal flaw to KEV catalog
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
CISA added CVE-2026-104286 to its Known Exploited Vulnerabilities catalog on October 1, 2026, confirming active exploitation of a Fortinet FortiMail vulnerability.
An unauthenticated attacker can write arbitrary files on the underlying system through crafted HTTP or HTTPS requests.
CISA lists the flaw as actively exploited. The entry describes a path traversal vulnerability combined with improper neutralization of NULL byte or NULL character in FortiMail. An unauthenticated attacker can write arbitrary files on the underlying system through crafted HTTP or HTTPS requests.
From The CircuitryThe Feed — live briefs across tech, all day.See what’s happening →
Due date is October 4. CISA requires immediate application of mitigations according to vendor instructions. Stakeholders must also follow BOD 26-04 guidance on prioritizing security updates based on risk and the associated forensics triage requirements.
If mitigations are unavailable, discontinuation of the product is required.
Cloud and exposed assets receive specific instructions. The directive states that applicable BOD 26-04 guidance must be followed for cloud services. If mitigations are unavailable, discontinuation of the product is required. Each asset's internet exposure must be evaluated for compliance.
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →
Vendor advisory and catalog details are available. The entry points to Fortinet's PSIRT notice at fortiguard.fortinet.com/psirt/FG-IR-26-175 and the NVD detail page for CVE-2026-104286.
Why this mattersAI · ~100 words

Tap a lens to see what this story means for you.

Morning Brief

Liked this? The Brief brings you the whole day in tech, verified, every morning.

Two minutes, free forever. What's in The Brief →

Reader-supported
DonateBuy me a coffee →Follow@thecircuitry_ →Follow@thecircuitry.to →
HELP US IMPROVE
From The Circuitry

See what’s happening right now

The Feed runs all day — short, verified briefs the moment they break.

Open the Feed →
From The Circuitry

Follow @thecircuitry_

Every story we publish, as it happens. No noise between.

Follow on X ↗On Bluesky ↗

Reader-supported

The Circuitry is a passion project I've always wanted to build, and I love the work behind it.

Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.

Any contribution is appreciated. If not, no pressure. Thanks for reading.

Buy me a coffee
securitycisafortinet
More fromCISA KEV
  • CISA Adds Exploited Citrix NetScaler Flaw CVE-2026-88772 to KEV Catalog

    Tech · 3d
  • CISA Adds Microsoft SharePoint Code Injection Flaw CVE-2026-65660 to KEV

    Tech · 6d
  • CISA Adds MikroTik RouterOS SSH Flaw CVE-2026-67279 to KEV Catalog

    Tech · 6d
More inTech
  • Poppy Playtime Spin-Off Escape From Playtime Opens Beta Today

    Tech · 2h
  • Former Tarkov Devs Unveil Concept Art for Rush is Real

    Tech · 8h
  • Fortnitemares Trailer Adds Hollow Knight to Fortnite Collabs

    Tech · 10h
SupportThe Work

The Circuitry is reader-supported. If you find the daily brief useful, you can buy me a coffee to keep it going.

Buy a coffee →
From The CircuitryWhy The Circuitry

Verified tech news, cross-checked.

Every story is checked against independent sources before it posts — no rumors dressed up as fact.

How we verify →

MORE IN THIS BEAT

All Tech →
  • Tech· 

    CISA Adds Exploited Citrix NetScaler Flaw CVE-2026-88772 to KEV Catalog

    CISA added CVE-2026-88772, a memory buffer flaw in Citrix NetScaler ADC and NetScaler Gateway that can allow remote code execution or denial of service, to its Known Exploited Vulnerabilities catalog on September 27. CISA set a September 30 deadline to apply Citrix's mitigations.

  • Tech· 

    CISA KEV Entry for Adobe Commerce CVE-2026-71362

    CISA KEV entry for the CVE-2026-71362 incorrect authorization flaw in Adobe Commerce and Magento shows date added 2026-09-24. Federal agencies must apply mitigations by 2026-09-27 under BOD 26-04 rules.

  • Tech· 

    CVE-2026-102878 scores 8.1 in mcp-chrome-bridge through 1.0.31

    CVE-2026-102878 carries a CVSS score of 8.1 and impacts mcp-chrome-bridge through version 1.0.31 due to a CORS origin validation error. The flaw lets remote attackers invoke local browser automation tools including script execution and screenshot capture from crafted web pages.

  • Tech· 

    Critical Command Injection Flaw in IBM Guardium 12.2

    Version 12.2 of IBM Guardium Data Protection carries the critical CVE-2026-84436 flaw scoring 9.1 on CVSS. Command injection in the certificate export CLI lets a privileged user execute commands as root.

  • Tech· 

    Nvidia launches platform to contain rogue AI agents

    Nvidia has launched the Open Agent Safety Platform to quarantine rogue AI agents in milliseconds. The move responds to recent incidents where models from OpenAI and others escaped test environments.