Actively Exploited FortiMail Zero‑Day Lets Attackers Write Files Without Login, CISA Warns
Attackers are exploiting a critical FortiMail vulnerability, CVE‑2026‑104286, that allows unauthenticated arbitrary file writes, prompting CISA to list it as a Known Exploited Vulnerability while some product fixes remain pending.
A critical flaw in Fortinet’s FortiMail email security appliances is under active attack, giving intruders a direct route to plant files on exposed systems without logging in.
The vulnerability, tracked as CVE‑2026‑104286, allows unauthenticated arbitrary file writes on affected FortiMail devices, according to technical advisories. In practice, a remote attacker can place files on a vulnerable system without providing credentials, and then use that access to run code, deploy web shells or alter configurations.
U.S. cyber authorities say attackers are already exploiting the bug. The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE‑2026‑104286 to its Known Exploited Vulnerabilities catalog, a list reserved for weaknesses with confirmed use in real‑world attacks. Fortinet has published indicators of compromise and workarounds, but full software fixes are still not available for some FortiMail versions.
Organisations that use FortiMail to filter email now face the risk that the security appliance itself becomes a point of entry. Because the exploit does not require authentication, measures such as strong passwords or multifactor checks on the device do not block an attacker from attempting to write files.
If an attacker can modify files on a security appliance, they can try to move deeper into the network, intercept or redirect traffic, or create hidden access that survives basic cleanup. For service providers running FortiMail on behalf of multiple customers, a single compromise could expose several environments.
This incident fits a wider pattern in which devices deployed at the edge of networks, including firewalls and other security tools, are prime targets. When one such system is compromised, it can offer visibility into large parts of an organisation’s infrastructure.
Fortinet is urging customers to apply available mitigations, look for the indicators it has released and prepare to deploy full patches quickly once they are published. CISA’s listing signals that U.S. federal agencies using FortiMail will be required to remediate the flaw within a set deadline.
Administrators now have to weigh the disruption of limiting access to or temporarily taking down affected email gateways against the danger of leaving a known, actively exploited weakness exposed.
Key developments to track include when Fortinet issues complete fixes for all supported FortiMail versions, whether incidents are publicly tied to this vulnerability, and any signs of broader scanning or exploit use against FortiMail systems.
Sources
- OSINT