Skip to main content
a promotional graphic telling you that PCI Compliance is no longer an annual exercise and that continuous monitory must be built in
What to Do in the First 48 Hours of a KEV AlertCyber Threats & Attacks
4 min readFor Incident Response Teams

What to Do in the First 48 Hours of a KEV Alert

Scope

This guide outlines how your team should respond when the CISA Known Exploited Vulnerabilities (KEV) catalog adds new entries affecting your infrastructure. Using the CVE-2026-104286 FortiMail incident as an example, it provides a framework applicable to any KEV situation involving your software.

You'll find specific requirements, workaround procedures, and a decision framework to apply each time a KEV entry impacts your environment.

Key Concepts and Definitions

Known Exploited Vulnerabilities (KEV) Catalog: CISA's list of vulnerabilities with confirmed real-world exploitation. Federal agencies must remediate KEV entries by set deadlines. Private sector organizations should prioritize these in their patching efforts.

Path Traversal (CWE-22): An attack method that manipulates file paths to access directories outside the intended scope. When combined with NULL byte injection (CWE-158), attackers can write files to arbitrary system locations.

Arbitrary File Write: The ability to create or modify files anywhere on the target system without authentication. This often leads to remote code execution or system compromise.

Indicators of Compromise (IOCs): Observable signs of intrusion. For CVE-2026-104286, Fortinet has published specific IP addresses and file paths to check immediately.

Requirements Breakdown

Affected Versions

CVE-2026-104286 affects FortiMail installations across four major branches:

Version Range Required Action Target Release
8.0.0 - 8.0.1 Upgrade 8.0.2 or above
7.6.0 - 7.6.6 Upgrade 7.6.7 or above
7.4.0 - 7.4.8 Upgrade 7.4.9 or above
7.2.0 - 7.2.9 Upgrade 7.4 branch or above

Note that the 7.2 branch requires a branch upgrade, not just a patch. Plan for configuration review and testing time.

FCEB Agency Deadline

Federal agencies must remediate by October 4, 2026. Contractors supporting federal systems should expect the same timeline in their contracts.

CVSS Score Context

The 9.8 severity score reflects no authentication required, a network-accessible attack vector, and high impact on confidentiality, integrity, and availability. Prioritize patching accordingly.

Implementation Guidance

Hour 0-2: Inventory and Triage

Run your asset inventory against the affected version ranges. Use your CMDB to filter for FortiMail instances and verify current patch levels. Don't rely on outdated scans.

Check for active compromise using Fortinet's published IOCs:

Suspicious IP addresses:

  • 79.141.169[.]187
  • 45.129.0[.]192

File system artifacts:

  • /data/lib/liblog.so (added)
  • /data/bin/webconsole (added)
  • /data/bin/mailservice (added)
  • /data/etc/ld.so.preload (added)
  • /bin/smit (modified)
  • /data/etc/httpd.conf (modified)
  • /data/migadmin.tar.gz (modified)

If you find these files or connections to these IPs, initiate incident response. Isolate the system and preserve forensic evidence before remediation.

Hour 2-8: Apply Workarounds

While awaiting patches or testing them in staging, implement Fortinet's interim controls:

Disable IBE feature support:

config system encryption ibe
set status disable
end

This command disables the Identity-Based Encryption feature, part of the attack surface.

Restrict management interface access:

Limit access to trusted private networks or use jump host access with MFA if your FortiMail management interface is internet-facing.

Document which workarounds you've applied and on which systems. You'll need this for patch validation later.

Hour 8-48: Patch Deployment

Test patches in a non-production environment first. For the 7.2 branch migration to 7.4, allocate extra time; you're changing feature sets, not just applying security fixes.

Coordinate with your mail operations team. FortiMail downtime affects email flow. Schedule maintenance windows and prepare user communications.

After patching, verify that the workarounds are no longer necessary and remove them to restore full functionality.

Common Pitfalls

Assuming "we're not federal" means you can delay. The October 4 deadline is a minimum. Active exploitation means attackers already have working code. Your exposure window starts now.

Treating KEV alerts like regular patch updates. CISA doesn't add vulnerabilities to KEV speculatively. Confirmed exploitation means threat actors are actively scanning for vulnerable systems.

Skipping the IOC check. Patching over an existing compromise secures the door but leaves the intruder inside. Always check for indicators before remediation.

Forgetting about the vendor credit. Fortinet credited Gwendal Guégniaud of their Product Security team with the discovery. Internal discovery with active exploitation suggests the vendor found it while investigating incidents. Treat this as a strong signal.

Ignoring the NULL byte detail. The combination of path traversal and NULL byte injection (CWE-158) is significant. This isn't simple directory traversal; it bypasses certain input validation checks. Understanding this helps assess risk in other products.

Quick Reference Table

Task Timeline Owner Success Criteria
Asset inventory verification 0-2 hours Security Ops Complete list of FortiMail versions
IOC sweep 0-2 hours Incident Response No matches or containment complete
Workaround deployment 2-8 hours System Admin IBE disabled, mgmt interface restricted
Patch testing 8-24 hours Engineering Successful test in staging
Production patching 24-48 hours Change Management All instances at safe version
Workaround removal 48+ hours System Admin Full functionality restored
Post-incident review 72+ hours Security Leadership Lessons captured

Your incident response plan should include a KEV response runbook. This table becomes your checklist each time CISA publishes a new entry affecting your stack.

The FortiMail vulnerability won't be the last KEV alert you see this year. Build the muscle memory now: inventory, check IOCs, apply workarounds, test patches, deploy, verify. Every hour you save reduces your window of exploitability.

Application Security Isn’t Optional Anymore.

You Might Also Like