FortiMail zero-day CVE-2026-104286 exploited
Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulner
What Happened
Fortinet has disclosed a critical vulnerability in FortiMail, its secure email gateway product, that is being actively exploited in zero-day attacks. Tracked as CVE-2026-104286, the flaw allows unauthenticated attackers to write arbitrary files to vulnerable systems, which can then be leveraged to execute unauthorized code or commands.
CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on Thursday, confirming that threat actors are actively weaponizing the flaw in the wild. The KEV designation triggers binding remediation timelines for U.S. federal agencies and serves as a strong signal to private-sector organizations that exploitation is confirmed and ongoing.
Fortinet issued an advisory urging customers to apply available patches immediately. The company has not disclosed the identity or motivation of the attackers exploiting the flaw, nor the scale of affected deployments.
Why It Matters
FortiMail sits at the perimeter of enterprise email infrastructure, inspecting inbound and outbound mail for threats. A compromise at this layer is particularly dangerous: attackers who gain a foothold on a mail gateway can intercept communications, harvest credentials, pivot into internal networks, and manipulate mail flow without triggering downstream detection.
Because the vulnerability is exploitable without authentication, any internet-facing FortiMail instance is a potential target. Organizations that have not yet patched should treat their appliances as potentially compromised and conduct forensic review. The KEV listing means this is no longer a theoretical risk - exploitation is confirmed.
Technical Details
The vulnerability is an unauthenticated arbitrary file write. Attackers can place files at arbitrary paths on the underlying system without providing credentials. Combined with the ability to control file contents, this enables code execution on the appliance - a pattern consistent with prior Fortinet product flaws such as the FortiSandbox unauthenticated RCE (CVE-2026-25089).
FortiMail’s web management interface and mail processing services are the likely attack surface, though Fortinet’s advisory should be consulted for the exact vector. Indicators of compromise include unexpected files in web-accessible directories, anomalous child processes spawned by mail services, and outbound connections to unfamiliar IP addresses.
This is the latest in a series of Fortinet product vulnerabilities under active exploitation, following issues in FortiPAM (CVE-2026-84388) and others.
Immediate Risk
Risk is rated critical for any organization running an unpatched, internet-exposed FortiMail appliance. Because exploitation requires no credentials, attack automation is trivial once a working exploit circulates. The window between disclosure and mass scanning is measured in hours.
Priority actions:
- Apply Fortinet’s patch immediately; if patching is delayed, restrict management interface access to trusted IP ranges.
- Hunt for indicators of compromise on all FortiMail instances, including file system anomalies and unexpected outbound traffic.
- Rotate credentials for any accounts whose mail flowed through a potentially compromised gateway.
- Review breach reports for incidents linked to mail gateway compromises.
Security Insight
Email gateways occupy a uniquely dangerous position: they are internet-facing, run complex software stacks, and process the most sensitive communications an organization generates. Yet they are often patched on the same cadence as internal infrastructure rather than edge devices. The FortiMail case mirrors the 2023 Barracuda ESG campaign, where attackers compromised email security appliances to maintain persistent access and exfiltrate data for months before detection. The lesson is structural: any appliance that terminates email traffic should be treated as a tier-zero asset, with patching SLAs measured in hours, not weeks, and with logging forwarded to a SIEM that alerts on process anomalies. Organizations that treat their mail gateway as routine infrastructure will discover compromises long after the attacker has read the inbox.
Further Reading
Never miss a security update
Get real-time security alerts delivered to your preferred platform.
Related News
Hackers are exploiting an authentication bypass vulnerability (CVE-2026-35616) in FortiClient Enterprise Management Server (EMS) to deliver an undocumented credential stealer called EKZ. [...]
Researchers warn that a newly identified open-source AI security testing platform called CyberStrikeAI was used by the same threat actor behind a recent campaign that breached hundreds of Fortinet For
Cybersecurity roundup for 2026-05-25 to 2026-05-31. 2 CVE advisories, 5 breach reports, 4 threat news stories.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities