Active FortiMail Zero‑Day Lets Attackers Write Files to Email Security Appliances, CISA Warns
Attackers are exploiting a critical FortiMail flaw tracked as CVE‑2026‑104286 that allows unauthenticated arbitrary file writes, prompting CISA to add it to its Known Exploited Vulnerabilities list while Fortinet races to finish patches for all supported versions.
A critical vulnerability in Fortinet’s FortiMail email security product is being used in real‑world attacks while some versions still lack full fixes.
Security reporting says attackers are exploiting a FortiMail flaw that enables unauthenticated arbitrary file writes on affected systems. The issue is tracked as CVE‑2026‑104286 and has been added to the U.S. Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities (KEV) catalog, a signal that federal agencies are expected to prioritise mitigation.
Fortinet has released indicators of compromise and documented workarounds, but patches are still pending for some FortiMail versions. That gap leaves organisations with exposed devices relying on configuration changes and monitoring while they wait for vendor updates.
An unauthenticated arbitrary file write allows an attacker to place chosen files on a target system without logging in first. Depending on how a particular deployment is configured, that access can be combined with other weaknesses to gain wider control over the appliance or use it as a foothold into the surrounding network.
Because FortiMail sits in front of email systems to filter spam, malware and phishing attempts, compromise of the appliance itself can have knock‑on effects. Attackers may be able to interfere with scanning, harvest data that passes through the device, or turn a trusted security box into part of their intrusion chain.
CISA’s decision to add CVE‑2026‑104286 to its KEV list marks it out as more than a theoretical bug. The catalog is reserved for vulnerabilities with evidence of exploitation and typically comes with deadlines for U.S. civilian agencies to address listed issues.
Key developments to track now include Fortinet’s release of patches covering all supported FortiMail versions, technical write‑ups from researchers analysing how the exploit is being used, and any breach disclosures that identify this zero‑day as an entry point.
Sources
- OSINT