Critical FortiMail Zero-Day Flaw Actively Exploited
A critical unauthenticated file write vulnerability in Fortinet's FortiMail is being actively exploited. CISA has added CVE-2026-104286 to its KEV catalog.
TL;DR
- CVE-2026-104286 is a critical FortiMail flaw allowing unauthenticated arbitrary file writes.
- CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog.
- The flaw has a CVSS score of 9.8, indicating severe impact.
- Organizations using FortiMail should apply mitigations immediately.
- Active exploitation has been reported, increasing urgency for patching.
A critical zero-day vulnerability in Fortinet's FortiMail secure email gateway is under active exploitation, prompting urgent action from organizations worldwide. The flaw, identified as CVE-2026-104286, enables unauthenticated attackers to write arbitrary files to the underlying system.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, underscoring the immediate risk it poses to enterprise networks. With a CVSS score of 9.8, the vulnerability represents a severe threat that could lead to full system compromise if left unaddressed.
Vulnerability Details
- CVE-2026-104286 affects Fortinet FortiMail appliances and allows unauthenticated arbitrary file writes
- The vulnerability has a critical CVSS score of 9.8 out of 10
- No authentication is required for exploitation, making it highly dangerous
- Successful exploitation could lead to remote code execution and full system compromise
Impact and Recommendations
- CISA has added the flaw to its KEV catalog, requiring federal agencies to remediate within specified timelines
- Reports confirm active exploitation in the wild before public disclosure
- Organizations should immediately review their FortiMail deployments and apply available patches
- Network defenders should monitor for suspicious file creation activities on affected systems
- Consider implementing network segmentation and enhanced logging around email gateway infrastructure
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.