Skip to content
Hugin
A close view of a heavy weathered chain lying on a dark grey surface, its end link open and unclosed.

Hugin News

CISA adds a FortiMail path-traversal flaw and two Zammad flaws to its exploited-vulnerabilities catalog, with federal deadlines October 4 and 5

3 min read

Original editorial artwork from the Hugin archive; symbolic illustration, not a depiction of the subject.

CISA's Known Exploited Vulnerabilities catalog, updated October 2 to 1,733 entries, added a critical FortiMail path-traversal flaw (CVE-2026-104286, CVSS 9.8, added October 1, due October 4), plus two Zammad flaws added October 2, due October 5: a session-fixation bug (CVE-2026-102489), fixed in Zammad 7.2.0, and an improper-privilege-management bug (CVE-2026-102490) whose reported scope Zammad says it cannot verify. CISA marks ransomware use Unknown for all three. Fortinet lists its fixed builds as upcoming, so its advisory urges a workaround.

cybersecurityvulnerabilitiesfortinetzammadfederal-agencies
8source receipts4source hosts3 minread timelinkedprimary source

CISA added three newly exploited flaws to its Known Exploited Vulnerabilities catalog this week: a critical path-traversal flaw in Fortinet's FortiMail email-security gateway, and two flaws in Zammad, a help-desk ticketing platform. The catalog lists flaws CISA has determined are being exploited, and each entry carries a due date that binds federal civilian agencies.

What each flaw is

Path traversal (FortiMail, CVE-2026-104286) lets an attacker reach files outside the folder a program is meant to confine it to; CISA's catalog says it may allow an unauthenticated attacker to write arbitrary files on the underlying system through crafted HTTP or HTTPS requests. Session fixation (Zammad, CVE-2026-102489) lets an attacker plant or predict a session ID a victim later logs into, then hijack that session; the catalog says it "can lead to remote code execution as the zammad user." Improper privilege management (Zammad, CVE-2026-102490) is a failure to limit what a lower-permission account can do; the catalog says it "can allow the local zammad user to escalate privileges to root." The catalog says the two Zammad flaws can be chained together.

Versions and the fix, from the vendors

Fortinet's advisory (FG-IR-26-175, published October 1) rates the FortiMail flaw critical, CVSS 9.8, and says no virtual patch exists. It lists FortiMail 8.0.0-8.0.1, 7.6.0-7.6.6, 7.4.0-7.4.8 and 7.2.0-7.2.9 as affected. Its fixes are listed as upcoming releases — "Upgrade to upcoming 8.0.2 or above", and the same for 7.6.7 and 7.4.9 — so none had shipped yet; for 7.2 it says to upgrade to branch 7.4 or above. Zammad's team, in an October 1 community post, says the session-fixation flaw hits 6.5 and earlier only ("Zammad 7.0 and later are not affected.") and is fixed in 7.2.0; its release page dates Zammad 7.2 to September 23. For the privilege-escalation flaw, DIVD, the outside party that reported it, claims the flaw "affects nearly every Zammad version ever released", according to Zammad's post; Zammad says "We cannot verify a claim we have not been shown," has asked DIVD for technical details, and still advises upgrading to 7.2.0.

The deadlines, and who they bind

CISA added the FortiMail entry October 1, due October 4; it added both Zammad entries October 2, due October 5. Those dates are compulsory under Binding Operational Directive 26-04, issued June 10, 2026, which "supersedes and hereby revokes" BOD 22-01, the November 2021 directive that used to set KEV deadlines. BOD 26-04 binds Federal Civilian Executive Branch agencies, and CISA's implementation guidance says CISA calculates each entry's due date from the directive's remediation-timeline table while "the final determination for asset exposure is determined by the agency." Everyone else has no deadline: the catalog page says "Organizations should use the KEV catalog as an input to their vulnerability management prioritization framework." CISA marks "known ransomware campaign use" as Unknown for all three entries.

What to do

With its fixed builds still upcoming, Fortinet urges a workaround: disable FortiMail's IBE feature, or keep the webmail interface off the internet, or — behind a web application firewall — block POST requests to /ibe that contain '../'. Zammad's instruction is to update to 7.2.0, upgrade immediately if running 6.5 or older, and watch its GitHub security-advisories page for updates on the privilege-escalation flaw.

Source links