ForgeNEX

FortiMail Under Attack: Critical Zero-Day Allows Arbitrary File Write

CISA adds to its catalog of exploited vulnerabilities a critical flaw in FortiMail that allows unauthenticated attackers to write arbitrary files. We analyze the impact and measures for SMBs.

Perimeter security is once again in the spotlight. This week, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added to its Known Exploited Vulnerabilities (KEV) catalog a critical flaw affecting Fortinet FortiMail, the company's secure email gateway. The vulnerability, identified as CVE-2026-104286 and with a CVSS score of 9.8, allows unauthenticated attackers to write arbitrary files on the underlying system. According to reports, it is already being actively exploited.

Illustrative detail: Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes

What does arbitrary file write imply?

The ability to write files without authentication is one of the most dangerous vulnerabilities. An attacker could upload malicious files, such as webshells, scripts, or binaries, and execute them to take full control of the server. In the case of FortiMail, this could compromise the entire organization's email, allowing interception of messages, credential theft, or sending fraudulent emails from a trusted system.

FortiMail is used by many companies to filter spam, malware, and phishing attacks. If an attacker manages to compromise it, they not only access email but can also move laterally to other systems in the corporate network. For an SMB, this can mean loss of sensitive data, business interruption, and reputational damage.

CISA's reaction and urgent measures

Inclusion in the KEV catalog means that U.S. federal agencies must apply mitigations by a deadline. Although not specified in the news, such actions typically entail a two-week deadline. For other organizations, it is a wake-up call: if attackers are already exploiting it, any exposure is an immediate risk.

Fortinet has not yet issued an official patch, according to available information. Meanwhile, it is recommended to apply compensating measures, such as restricting access to the management interface, segmenting the network, and monitoring for possible indicators of compromise.

ForgeNEX analysis: lessons for SMBs and IT teams

This incident reinforces a trend we have been observing: attackers are accelerating the exploitation of critical vulnerabilities, often before patches exist. In a recent article, AI accelerates exploits: your CVE spreadsheet is no longer enough, we warned that traditional patch management is no longer sufficient. Now, more than ever, SMBs must adopt a proactive security approach.

The key question is: is your organization prepared to respond to a zero-day in a critical component such as email? The answer cannot be only technical; it requires processes, training, and a security culture.

Immediate recommendations

  1. Identify if you use FortiMail: review your asset inventory. If you have FortiMail exposed to the Internet, you are at risk.
  2. Apply temporary mitigations: if there is no patch, limit access to the management interface only to internal networks or VPN, and monitor logs for suspicious activity.
  3. Segment the network: isolate the email server in a separate VLAN and restrict communication with other critical systems.
  4. Strengthen monitoring: implement alerts for the creation of unexpected files in email server directories.
  5. Prepare a response plan: define containment and eradication procedures in case of compromise.

Additionally, it is essential to review the security configuration of perimeter devices. In our success story in perimeter protection, we highlighted the importance of proper segmentation and access policies to prevent a single point of failure from compromising the entire network.

The future of email security

Attackers will continue to look for vulnerabilities in email gateways, as they are entry points rich in information. SMBs should consider layered security solutions, including not only filtering but also behavior analysis and automated response. The integration of threat intelligence and the adoption of frameworks such as Zero Trust are necessary steps.

At ForgeNEX, we help companies design resilient architectures, with continuous monitoring and response plans. If you need advice on how to protect your email infrastructure, do not hesitate to contact us.

Source: The Hacker News. Analysis and adaptation: ForgeNEX.

Keep reading