Published: · Region: Global · Category: cyber

Active FortiMail Zero‑Day Allows Remote File Writes as Agencies Rush to Contain Ongoing Exploits

Attackers are exploiting a critical FortiMail vulnerability, tracked as CVE‑2026‑104286, that lets unauthenticated users write files to targeted systems. US cyber authorities have added the bug to their high‑priority remediation list, while Fortinet warns that some product versions still lack full fixes.

A critical flaw in Fortinet’s FortiMail product is under active attack, exposing a key layer of many organisations’ email infrastructure while some software versions still wait for complete patches.

Security warnings issued on 2 October identified the vulnerability as CVE‑2026‑104286. The bug allows arbitrary file writes by an unauthenticated attacker, meaning someone on the internet can push files onto a vulnerable FortiMail system without logging in.

The US Cybersecurity and Infrastructure Security Agency (CISA) has placed the flaw in its Known Exploited Vulnerabilities catalogue, a list reserved for security issues that are already being used in real‑world attacks. Inclusion in that catalogue typically triggers strict remediation deadlines for US federal civilian agencies and often shapes patch priorities in the private sector.

Fortinet has released indicators of compromise and suggested temporary workarounds, but has said that fixes for some FortiMail versions are still pending. Administrators who run those versions must decide how far to tighten access or disable features while they wait for an update that fully closes the hole.

FortiMail systems commonly sit at the edge of corporate and government networks, handling inbound and outbound email. If an attacker can write files to such a device, they may be able to upload tools for remote access, tamper with filtering rules, or use the foothold to move deeper into internal systems.

Because email remains a primary channel for both routine business and targeted attacks, a compromised gateway can expose sensitive correspondence and give intruders a broad view of how an organisation operates.

The FortiMail vulnerability reflects a broader pattern in which attackers focus on widely deployed security appliances and gateways. A single reliable exploit for a popular email, network, or remote‑access product can open paths into many high‑value environments.

With exploitation already underway, the speed of response will largely determine how much damage the flaw causes. Organisations that can apply workarounds quickly, monitor their FortiMail systems for suspicious activity, and move rapidly once patches become available will be better placed to limit intrusions.

Developments to watch include the release of full fixes for all affected FortiMail versions, updated CISA guidance on how fast agencies must remediate, and technical reporting that links specific attack campaigns to CVE‑2026‑104286. Public breach disclosures tied to this vulnerability would offer the clearest view of how attackers are using it and which sectors are most affected.

Sources