Cookie Consent by Free Privacy Policy Generator

Critical Fortinet FortiMail zero-day exploited in the wild

The US Cybersecurity and Infrastructure Security Agency has added a critical Fortinet FortiMail vulnerability to its Known Exploited Vulnerabilities catalog following confirmed active exploitation. The flaw, tracked as CVE-2026-104286 with a CVSS score of 9.8, allows unauthenticated attackers to write arbitrary files to the underlying system. Fortinet has released patches and organisations using FortiMail are advised to apply updates immediately. The vulnerability affects email security appliances widely deployed across enterprise environments to filter spam, malware and phishing attempts before messages reach users.

Why this matters for UK organisations

FortiMail sits at a critical point in many organisations' security architecture, handling inbound email before it reaches users. A vulnerability that allows unauthenticated arbitrary file writes gives attackers a direct route to compromise the appliance without needing credentials or prior access. Once compromised, an attacker could intercept email, modify filtering rules to allow malicious messages through, deploy malware, exfiltrate sensitive communications or use the compromised system as a foothold into the wider network. For UK businesses relying on FortiMail for email security, the combination of a critical severity rating and confirmed exploitation in the wild means this is not a theoretical risk but an active threat requiring immediate attention. Email security appliances are high-value targets because they process all inbound communications and often have privileged network access.

What to review

Organisations using Fortinet FortiMail should verify that patches have been applied across all instances, including any that may be managed by third parties, hosted in branch offices or sitting outside the usual patch cycle. It is worth reviewing whether email security appliances are included in vulnerability scanning, patch management processes and incident response playbooks with the same priority as other internet-facing systems. If patching cannot be completed immediately, consider whether temporary mitigations such as network segmentation, additional monitoring or access restrictions can reduce exposure until patches are deployed. This is also a prompt to confirm that responsibility for patching network security appliances is clearly assigned and that there is a process for ensuring critical updates are applied promptly, particularly when active exploitation is confirmed.

Source: The Hacker News

News and blog posts
Today's stories highlight three persistent challenges facing UK organisations:...
The US Cybersecurity and Infrastructure Security Agency has added a critical...
A critical vulnerability in Cisco Catalyst SD-WAN Manager is being actively...
Research from Intel 471 reported by Help Net Security shows that cybercriminals...