Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes
Summary
A critical zero-day vulnerability in Fortinet's FortiMail product, identified as CVE-2026-104286, is now being actively exploited. The flaw allows unauthenticated attackers to write arbitrary files to the underlying system, posing a significant security risk.
IFF Assessment
The exploitation of a critical vulnerability by unauthenticated attackers represents a direct threat to organizations using the affected product.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: October 04, 2026. Known ransomware use: Unknown.
Defender Context
Organizations using FortiMail should prioritize patching this critical vulnerability immediately, as it is already under active exploitation. Defenders should also enhance monitoring for unauthorized file writes and suspicious activity on their FortiMail appliances.