# US Warns of Critical FortiMail Zero‑Day Letting Attackers Write Files Without Login

*Friday, October 2, 2026 at 6:06 AM UTC — Hamer Intelligence Services Desk*

**Published**: 2026-10-02T06:06:17.915Z (2h ago)
**Category**: cyber | **Region**: Global
**Importance**: 8/10
**Sources**: OSINT
**Permalink**: https://hamerintel.com/data/articles/19385.md
**Source**: https://hamerintel.com/summaries

---

**Deck**: Attackers are exploiting a critical FortiMail vulnerability, tracked as CVE‑2026‑104286, that enables unauthenticated arbitrary file writes, prompting its addition to the US known‑exploited list while some product fixes remain pending.

A critical zero‑day flaw in Fortinet’s FortiMail email security product is being actively exploited, giving attackers the ability to write files to affected systems without logging in and triggering urgent warnings from US authorities.

The vulnerability, identified as CVE‑2026‑104286, has been added by the US Cybersecurity and Infrastructure Security Agency (CISA) to its Known Exploited Vulnerabilities (KEV) catalog. Inclusion in the KEV list signals that the flaw is confirmed to be used in real‑world attacks and is considered a priority for remediation.

Fortinet has published indicators of compromise and workarounds for the FortiMail issue. However, the company has said that fixes are still pending for some versions, leaving a window in which organizations must rely on temporary measures rather than full patches.

The bug allows unauthenticated arbitrary file writes, meaning an attacker can place files onto a vulnerable FortiMail device without valid credentials. In practice, such access can enable the installation of malicious tools, tampering with configuration files, and the creation of hidden footholds inside networks that depend on FortiMail to filter email.

Because FortiMail appliances sit in the path of an organization’s email traffic, a compromise can expose sensitive communications and provide a staging point for further intrusion into internal systems. Attackers can potentially leverage the device’s trusted position to move laterally or disguise malicious activity as routine messaging operations.

For enterprises and public bodies using FortiMail, the immediate priorities are to apply Fortinet’s recommended workarounds, restrict unnecessary external access to affected devices, and review logs and systems for the indicators of compromise the company has shared. CISA’s decision to add CVE‑2026‑104286 to the KEV catalog means US federal agencies are expected to remediate the issue within defined timeframes, and it often prompts wider action across critical sectors.

In the near term, the most important developments will be Fortinet’s release of complete patches for all supported FortiMail versions, the speed with which administrators deploy those updates or compensating controls, and any public incident reports that explicitly tie breaches to exploitation of CVE‑2026‑104286.
