# CISA Adds FortiMail Flaw to KEV

CISA added Fortinet FortiMail vulnerability CVE-2026-104286 to its Known Exploited Vulnerabilities (KEV) catalog on October 1, 2026, after active exploitation was identified. Under Binding Operational Directive 26-04, federal civilian executive branch agencies had until October 4 to remediate the vulnerability; that deadline has passed. Contractors supporting government networks should verify whether FortiMail systems are exposed, apply Fortinet’s recommended mitigation or update, and review affected systems for signs of compromise.

- Federal civilian executive branch agencies were subject to the October 4 remediation deadline; contractors should coordinate with agency customers on any remediation affecting supported government systems.
- Security and procurement teams can use the KEV listing to prioritize vulnerability remediation and assess whether Fortinet updates or related security support are needed.
- The signals provide no affected-version details or contract opportunity; verify Fortinet’s and CISA’s official advisories before specifying technical requirements or sourcing remediation.

**Jurisdictions:** federal
**Industries:** Information Technology
**Topics:** Cybersecurity, Regulatory Compliance
**Published:** October 05, 2026

### Government Entities
- Cybersecurity and Infrastructure Security Agency (CISA)

### Vendors
- Fortinet (FortiMail product manufacturer)

### Key Quotes
> U.S. CISA adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog
> — Original poster

### Sources
- [U.S. CISA adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog](https://www.reddit.com/r/cybersecurity/comments/1wxce8k/us_cisa_adds_fortinet_fortimail_flaw_to_its_known) - reddit-cybersecurity
- [CISA Adds Fortinet FortiMail 0-day Vulnerability to KEV Following Active Exploitation](https://cybersecuritynews.com/fortinet-fortimail-0-day-vulnerability-exploitation) - CyberSecurityNews