CISA added three newly exploited flaws to its Known Exploited Vulnerabilities catalog this week: a critical path-traversal flaw in Fortinet's FortiMail email-security gateway, and two flaws in Zammad, a help-desk ticketing platform. The catalog lists flaws CISA has determined are being exploited, and each entry carries a due date that binds federal civilian agencies.
What each flaw is
Path traversal (FortiMail, CVE-2026-104286) lets an attacker reach files outside the folder a program is meant to confine it to; CISA's catalog says it may allow an unauthenticated attacker to write arbitrary files on the underlying system through crafted HTTP or HTTPS requests. Session fixation (Zammad, CVE-2026-102489) lets an attacker plant or predict a session ID a victim later logs into, then hijack that session; the catalog says it "can lead to remote code execution as the zammad user." Improper privilege management (Zammad, CVE-2026-102490) is a failure to limit what a lower-permission account can do; the catalog says it "can allow the local zammad user to escalate privileges to root." The catalog says the two Zammad flaws can be chained together.
Versions and the fix, from the vendors
Fortinet's advisory (FG-IR-26-175, published October 1) rates the FortiMail flaw critical, CVSS 9.8, and says no virtual patch exists. It lists FortiMail 8.0.0-8.0.1, 7.6.0-7.6.6, 7.4.0-7.4.8 and 7.2.0-7.2.9 as affected. Its fixes are listed as upcoming releases — "Upgrade to upcoming 8.0.2 or above", and the same for 7.6.7 and 7.4.9 — so none had shipped yet; for 7.2 it says to upgrade to branch 7.4 or above. Zammad's team, in an October 1 community post, says the session-fixation flaw hits 6.5 and earlier only ("Zammad 7.0 and later are not affected.") and is fixed in 7.2.0; its release page dates Zammad 7.2 to September 23. For the privilege-escalation flaw, DIVD, the outside party that reported it, claims the flaw "affects nearly every Zammad version ever released", according to Zammad's post; Zammad says "We cannot verify a claim we have not been shown," has asked DIVD for technical details, and still advises upgrading to 7.2.0.
The deadlines, and who they bind
CISA added the FortiMail entry October 1, due October 4; it added both Zammad entries October 2, due October 5. Those dates are compulsory under Binding Operational Directive 26-04, issued June 10, 2026, which "supersedes and hereby revokes" BOD 22-01, the November 2021 directive that used to set KEV deadlines. BOD 26-04 binds Federal Civilian Executive Branch agencies, and CISA's implementation guidance says CISA calculates each entry's due date from the directive's remediation-timeline table while "the final determination for asset exposure is determined by the agency." Everyone else has no deadline: the catalog page says "Organizations should use the KEV catalog as an input to their vulnerability management prioritization framework." CISA marks "known ransomware campaign use" as Unknown for all three entries.
What to do
With its fixed builds still upcoming, Fortinet urges a workaround: disable FortiMail's IBE feature, or keep the webmail interface off the internet, or — behind a web application firewall — block POST requests to /ibe that contain '../'. Zammad's instruction is to update to 7.2.0, upgrade immediately if running 6.5 or older, and watch its GitHub security-advisories page for updates on the privilege-escalation flaw.
Source links
- CISA Known Exploited Vulnerabilities catalog (JSON feed)
- CISA Known Exploited Vulnerabilities Catalog page
- CISA, Binding Operational Directive 26-04
- CISA, BOD 26-04 implementation guidance
- CISA, Binding Operational Directive 22-01 (revoked)
- Fortinet PSIRT advisory FG-IR-26-175
- Zammad community post on CVE-2026-102489 and CVE-2026-102490, October 1, 2026
- Zammad product release notes
