Fortinet Email Gateway Vulnerability Under Active Attack, Added to Federal Tracking List

A critical vulnerability in Fortinet's FortiMail platform has been added to the U.S. Cybersecurity and Infrastructure Security Agency's catalog of known exploited vulnerabilities following confirmed active attacks. The flaw, rated 9.8 on the severity scale, permits attackers without credentials to write arbitrary files to affected systems. Fortinet users are urged to apply patches as exploitation is actively occurring in the wild.
The Fortinet FortiMail platform, widely deployed for email security across organizations, contains a severe flaw that attackers can exploit without needing valid login credentials. By writing arbitrary files to vulnerable systems, threat actors can potentially compromise email infrastructure that many businesses rely on for secure communications. The addition to the federal government's tracking list signals that exploitation attempts are already underway in real-world environments, making immediate remediation a priority for affected organizations.
Organizations using FortiMail systems could face significant disruption if this vulnerability remains unpatched, potentially allowing attackers to access sensitive email data or use compromised servers as footholds for broader network intrusions. The active exploitation underway may particularly impact enterprises and critical infrastructure sectors that depend heavily on email for operations. Rapid patching by system administrators could substantially reduce these risks, though organizations with limited IT resources or legacy systems may face delays in securing their environments.