# Exploited FortiMail Zero‑Day Lets Attackers Write Files Without Login, CISA Warns of Active Threat

*Friday, October 2, 2026 at 6:14 AM UTC — Hamer Intelligence Services Desk*

**Published**: 2026-10-02T06:14:31.444Z (2h ago)
**Category**: cyber | **Region**: Global
**Importance**: 8/10
**Sources**: OSINT
**Permalink**: https://hamerintel.com/data/articles/19413.md
**Source**: https://hamerintel.com/summaries

---

**Deck**: Attackers are exploiting a FortiMail zero‑day vulnerability that allows unauthenticated arbitrary file writes, prompting CISA to add CVE‑2026‑104286 to its Known Exploited Vulnerabilities list while Fortinet races to complete fixes for all affected versions.

A critical flaw in Fortinet’s FortiMail product is being actively abused, exposing organisations that haven’t yet applied workarounds or available fixes.

According to public reporting, attackers are exploiting a vulnerability in FortiMail tracked as CVE‑2026‑104286 that allows unauthenticated arbitrary file writes on affected systems. In practice, this means someone who can reach a vulnerable FortiMail instance can write files to it without logging in, creating a potential starting point for deeper compromise.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added CVE‑2026‑104286 to its Known Exploited Vulnerabilities (KEV) catalogue. Inclusion in the KEV list signals that the flaw is not just theoretical but is already being used in real‑world attacks.

Fortinet has published indicators of compromise and described temporary workarounds for the issue. Public reporting notes that fixes are still pending for some FortiMail versions, leaving a period in which some customers have no full patch and must lean on configuration changes and heightened monitoring.

FortiMail is widely deployed as an email security platform. Because it sits in a central position handling email traffic, an attacker who can exploit unauthenticated file writes on such a device may be able to plant malicious files, alter configurations, or combine this weakness with others to gain broader access, depending on the specific environment.

For administrators, the immediate tasks are to identify which FortiMail systems are in use, determine whether they run vulnerable versions, and apply Fortinet’s workarounds where full fixes aren’t yet available. Reviewing logs and other telemetry for signs of suspicious file activity or other anomalies on FortiMail appliances will be critical while exploitation is ongoing.

This case fits into a pattern where attackers focus on network‑exposed security appliances, knowing they often sit at or near the edge of organisational networks. A flaw that enables unauthenticated file writes on such a device can offer a convenient entry point.

Key developments to track now include Fortinet’s release schedule for complete patches across all supported FortiMail versions, any new technical details or intrusion reports tied specifically to CVE‑2026‑104286, and whether CISA or other regulators issue additional directives that expand mandatory mitigation requirements beyond current guidance.
