Actively Exploited FortiMail Zero‑Day Lets Attackers Write Files Without Login, CISA Warns
Attackers are abusing a critical FortiMail flaw that enables unauthenticated arbitrary file writes, and US cyber authorities have put the bug on their Known Exploited Vulnerabilities list while some fixes remain in development.
Attackers are actively exploiting a critical zero‑day vulnerability in FortiMail that allows unauthenticated arbitrary file writes, giving them a path to take over targeted systems without valid credentials.
The US Cybersecurity and Infrastructure Security Agency (CISA) has added the issue, tracked as CVE‑2026‑104286, to its catalog of Known Exploited Vulnerabilities, a list reserved for flaws with confirmed real‑world abuse. Fortinet has published indicators of compromise and temporary workarounds, but full fixes for some FortiMail versions are still pending.
FortiMail is a secure email gateway product used to filter and route email in many organizations’ networks, including enterprises, service providers and public‑sector bodies. A vulnerability that allows unauthenticated arbitrary file writes means an attacker can plant or overwrite files on the device without logging in, potentially uploading web shells, changing configuration files, or adding backdoors to maintain remote access.
Once a FortiMail system is compromised, it can serve as a staging point for deeper intrusions. An attacker with control over the gateway can intercept or manipulate email traffic, capture credentials, and move laterally into internal networks. Because such appliances are often treated as trusted infrastructure, malicious activity that originates from them can be harder to detect in routine monitoring.
Government agencies and operators of critical services are among those at higher risk, as Fortinet products are widely deployed in the public sector and in sectors that depend on reliable and secure communications.
Fortinet has urged customers to apply available mitigations and watch logs for suspicious behavior, using the published indicators of compromise to look for signs of exploitation. With some software versions still awaiting patches, administrators face choices about whether to isolate or reconfigure affected systems while relying on workarounds.
The case highlights how attackers continue to search for exploitable flaws in email security and other edge networking products. These systems sit between corporate networks and the internet, so a single vulnerability can give intruders a strong foothold.
Over the coming days, key developments will include the release of complete patches for all affected FortiMail versions, any detailed exploitation reports from major security firms, and possible directives from CISA or other national authorities for government and critical infrastructure operators. Incident disclosures tied to this vulnerability will help show how widely attackers have been able to compromise FortiMail appliances.
Sources
- OSINT