ITsecurity Daily
Daily Briefing
Fortinet FortiMail zero-day under active attack as CISA flags fresh exploited flaws
Good morning. The Register reported that Fortinet sounded the alarm over an actively exploited FortiMail zero-day, stating that no login is required, exploitation is underway, and some admins are still waiting for patches. Treat internet-facing FortiMail as a priority: confirm your version against Fortinet's advisory, apply the fix as soon as it is available for your build, and review mail-gateway logs and admin accounts for signs of access.
CISA added two vulnerabilities to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation, both in Zammad: a session fixation flaw and an improper privilege management flaw. CISA states that Binding Operational Directive 26-04 requires federal agencies to prioritise rapid remediation of catalog entries; organisations running Zammad should patch to the vendor's fixed release.
On the exploited edge, CISA's KEV catalog lists CVE-2026-88771 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, base score 9.8) and CVE-2026-88772 (vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H, base score 8.1) in Citrix NetScaler ADC and Gateway, affecting 13.1 up to the fix in 13.1-64.23 — upgrade to 13.1-64.23 per Citrix's bulletin. CISA's KEV catalog also lists CVE-2026-86950 (vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, base score 8.8) in Apple macOS up to the fix in 15.8.1; apply 15.8.1 per Apple's advisory. For federal agencies and anyone following CISA's guidance, apply mitigations in accordance with vendor instructions and BOD 26-04.
Zoom out: Help Net Security reports that Microsoft's 2026 Digital Defense Report, covering July 2025 to June 2026, describes a near-term period in which attackers collect the benefits of AI first and defenders have to move quickly to close the gap.
Vulnerability in focus
CVE-2026-86950 — Apple. CVSS 8.8 CISA lists it as known to be exploited.
Affected: macos.
What to do: Follow the vendor advisory for the fixed release and any interim mitigation.
Elsewhere
- The Record: Judge dismisses spyware case brought by Salvadoran journalists targeted with Pegasus Read it
- CISA: CISA Adds Two Known Exploited Vulnerabilities to Catalog Read it
- BleepingComputer: Frontline Education breach exposes school district employee data Read it
- BleepingComputer: Warlock ransomware breach SharePoint in water, telecom operator attacks Read it
- The Hacker News: Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes Read it
- The Hacker News: GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers Read it
- BleepingComputer: GitLab warns of critical RCE vulnerability in AI Gateway service Read it
- BleepingComputer: US sanctions Tren de Aragua gang members in ATM hacks crackdown Read it
- SecurityWeek: In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats Read it
- The Record: 'Warlock' ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking countries Read it
- BleepingComputer: The EDR blind spot: 3 ways browser attacks evade endpoint telemetry Read it
- SecurityWeek: macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor Read it
Sources
- Judge dismisses spyware case brought by Salvadoran journalists targeted with Pegasus The Record
- Frontline Education breach exposes school district employee data BleepingComputer
- GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers The Hacker News
- In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats SecurityWeek
- AI is giving attackers a head start, Microsoft warns Help Net Security
- CISA Adds Two Known Exploited Vulnerabilities to Catalog CISA
- How American Political Campaigns Are Using AI—and What They’re Spending on the Tools Schneier on Security
- Fortinet sounds the alarm over actively exploited FortiMail zero-day The Register
- Warlock ransomware breach SharePoint in water, telecom operator attacks BleepingComputer
- Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign The Hacker News
- Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes The Hacker News
- GitLab warns of critical RCE vulnerability in AI Gateway service BleepingComputer
- US sanctions Tren de Aragua gang members in ATM hacks crackdown BleepingComputer
- Mississippi mayor says ransomware incident led city to shut down systems The Record
Share this issue
Facebook · X · Reddit · LinkedIn · WhatsApp · Email · Bluesky
Every briefing is on the site, with the advisory record behind it. All briefings