The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities (KEV) catalog, following credible reports of active exploitation in the wild. The inclusion of this vulnerability highlights the ongoing risks organizations face regarding enterprise security and the rapid exploitation cycles leveraged by threat actors targeting corporate and governmental email security gateways. The vulnerability, which is tracked internationally as CVE-2026-104286 and carries a maximum CVSS severity score of 9.8, represents a severe security risk to deployments worldwide. Specifically, the defect allows unauthenticated, remote attackers to write arbitrary files on the underlying system hosting the affected software. Read Also: Financial Services Face a New Threat Reality as AI-Driven Exploits Target Aging Software Supply Chains SolarWinds Issues Urgent Security Patch for High-Severity Remote Code Execution Flaw in Access Rights Manager According to an official advisory published by Fortinet, the issue stems from a combination of two distinct weakness types. The first is an improper limitation of a pathname to a restricted directory, commonly referred to as a path traversal vulnerability and cataloged as CWE-22. The second underlying issue involves the improper neutralization of a NULL byte or NULL character, tracked as CWE-158. Together, these weaknesses may allow an unauthenticated attacker to manipulate file paths and write arbitrary files on the underlying system via carefully crafted HTTP or HTTPS requests. Fortinet credited Gwendal Guégniaud of the Fortinet Product Security team with discovering and reporting the flaw. In response to the active exploitation campaigns observed in the wild, Fortinet has urged customers to apply critical workarounds immediately until official patches and firmware updates are fully available for all affected versions. For administrators managing impacted deployments where patches are not yet readily available, Fortinet has outlined specific configuration changes to mitigate the risk. The workaround requires administrators to disable the system encryption IBE status by executing a configuration sequence that turns the status off within the command line interface: config system encryption ibe set status disable end Given the severity of the flaw and the confirmation of active attacks, the U.S. Cybersecurity and Infrastructure Security Agency has set strict compliance timelines. Federal Civilian Executive Branch (FCEB) agencies are strongly recommended to apply the necessary patches or implement the recommended workarounds by October 4, 2026. While the mandate specifically targets federal agencies, private sector organizations, critical infrastructure providers, and enterprises globally are urged to treat the deadline with equal urgency to prevent unauthorized system compromise. This urgent development arrives amid a broader, highly active threat landscape characterized by a wave of zero-day and critical vulnerabilities striking various enterprise management platforms, firewalls, and networking infrastructure. Over recent weeks, security researchers and vendors have rushed to address numerous high-severity flaws that are actively being exploited by malicious actors. Among the notable security events dominating the cybersecurity landscape are critical management server flaws disclosed by Check Point, tracked as CVE-2026-85102 and CVE-2026-93616. Similarly, high-impact issues have struck the Arista VeloCloud Orchestrator via CVE-2026-93952, and F5 has been forced to patch a critical zero-day vulnerability in its BIG-IP Access Policy Manager, tracked as CVE-2026-94127. Additional enterprise threats include vulnerabilities in the Cisco Catalyst SD-WAN Manager under CVE-2026-76504, alongside post-exploitation concerns affecting Citrix NetScaler ADC and NetScaler Gateway through vulnerabilities tracked as CVE-2026-88771 and CVE-2026-88772. The convergence of these active exploitation campaigns across multiple major enterprise vendors underscores a challenging environment for security operations centers and IT administrators. As attackers increasingly automate the weaponization of newly disclosed path traversal and arbitrary file write flaws, timely vulnerability management, adherence to CISA directives, and the immediate deployment of vendor workarounds remain vital components of modern organizational defense strategies. Post navigation International Law Enforcement Dismantles Notorious KillSec Cybercrime Syndicate With Multiple Arrests and Server Seizures OpenAI Ousts Safety Researchers Amid Growing Scrutiny Over Autonomous AI Risks and Unauthorized System Probes