Interestana
Home/News/Critical FortiMail Zero-Day Flaw Exploited in Attacks
The Hacker News••3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Critical FortiMail Zero-Day Flaw Exploited in Attacks

Critical FortiMail Zero-Day Flaw Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) officially added a critical security vulnerability affecting Fortinet's FortiMail email security gateway to its Known Exploited Vulnerabilities (KEV) catalog on Thursday, March 7, 2024. This inclusion signifies that the vulnerability is currently being actively exploited in real-world attacks, posing an immediate threat to organizations utilizing the affected FortiMail systems. The vulnerability, officially designated as CVE-2026-104286, carries a severe CVSS (Common Vulnerability Scoring System) score of 9.8 out of a possible 10, indicating its high criticality and potential for significant damage. According to the advisory, this flaw allows unauthenticated attackers to write arbitrary files to the underlying system of the FortiMail appliance. This capability is particularly dangerous as it bypasses the need for any form of user authentication, meaning an attacker does not need a valid username or password to exploit the vulnerability. The ability to write arbitrary files means an attacker could potentially overwrite critical system files, inject malicious code, or otherwise compromise the integrity and functionality of the FortiMail device. This could lead to a complete system takeover, enabling attackers to intercept email traffic, deploy malware, or use the compromised FortiMail as a pivot point to attack other systems within an organization's network. The KEV catalog is a crucial resource maintained by CISA, which lists vulnerabilities that have been confirmed to be exploited in the wild. Inclusion in this catalog mandates that federal agencies remove any identified vulnerabilities from their networks within a specified timeframe, typically 14 days, to mitigate immediate risks. While the mandate specifically applies to federal agencies, CISA strongly urges all organizations, regardless of sector, to prioritize the patching and remediation of vulnerabilities listed in the KEV catalog. Fortinet, the manufacturer of FortiMail, is expected to have released patches or workarounds for this vulnerability. Organizations using FortiMail are strongly advised to consult Fortinet's security advisories and apply any available updates immediately to protect their systems from exploitation. The specific details of how the arbitrary file write is achieved are not fully disclosed in the public advisories to prevent further aiding attackers, but the impact is clear: unauthorized modification of system files. This type of vulnerability can be a precursor to more complex attacks, such as remote code execution or denial-of-service attacks, by enabling attackers to establish a foothold and manipulate the system's state. The active exploitation of CVE-2026-104286 underscores the persistent threat landscape and the importance of robust vulnerability management programs, including regular scanning, timely patching, and proactive threat intelligence monitoring. The FortiMail product line is widely used by businesses and government entities for email security, including spam filtering, antivirus scanning, and data loss prevention, making a vulnerability in this product a significant concern for a broad range of users.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next