Fortinet Issues Critical Patch for FortiMail Flaw Allowing Unauthorized File Creation

Fortinet has disclosed a critical zero-day vulnerability in FortiMail that is already being exploited in active attacks, with a CVSS severity rating of 9.8. The flaw allows unauthenticated attackers to write arbitrary files to affected systems through specially crafted HTTP or HTTPS requests. This vulnerability represents a significant threat to email infrastructure and requires immediate mitigation.
FortiMail serves as a critical defensive layer for enterprise email systems, filtering threats before messages reach internal networks. By compromising this perimeter appliance, attackers gain a foothold to modify system files, establish persistent access, and potentially pivot deeper into organizational infrastructure. The zero-day's active exploitation and rapid inclusion in federal remediation mandates underscore its severity.
Email security appliances face intensifying scrutiny from threat actors seeking entry points into corporate environments. Vulnerabilities affecting authentication mechanisms or file-handling routines can be particularly damaging, as they bypass normal access controls that protect sensitive systems from remote tampering and unauthorized modification.
This vulnerability could significantly impact organizations across sectors that rely on FortiMail for email protection, potentially exposing them to data theft, service disruption, and compliance violations. Government agencies face immediate pressure to patch, while private enterprises must balance urgent remediation against operational continuity. The incident may drive broader security investments in email infrastructure and reinforce the need for rapid vulnerability response capabilities across enterprise networks.