Fortinet FortiMail zero-day under active attack as CISA flags fresh exploited flaws
Friday brought an actively exploited FortiMail zero-day with no patch for some admins, new entries on CISA's exploited-vulnerabilities catalog, and critical fixes from Citrix, Apple, Google, GitLab and Dell.
The Register reported that Fortinet sounded the alarm over an actively exploited FortiMail zero-day, stating that no login is required, exploitation is underway, and some admins are still waiting for patches. Treat internet-facing FortiMail as a priority: confirm your version against Fortinet's advisory, apply the fix as soon as it is available for your build, and review mail-gateway logs and admin accounts for signs of access.
CISA added two vulnerabilities to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation, both in Zammad: a session fixation flaw and an improper privilege management flaw. CISA states that Binding Operational Directive 26-04 requires federal agencies to prioritise rapid remediation of catalog entries; organisations running Zammad should patch to the vendor's fixed release.
On the exploited edge, CISA's KEV catalog lists CVE-2026-88771 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, base score 9.8) and CVE-2026-88772 (vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H, base score 8.1) in Citrix NetScaler ADC and Gateway, affecting 13.1 up to the fix in 13.1-64.23 — upgrade to 13.1-64.23 per Citrix's bulletin. CISA's KEV catalog also lists CVE-2026-86950 (vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, base score 8.8) in Apple macOS up to the fix in 15.8.1; apply 15.8.1 per Apple's advisory. For federal agencies and anyone following CISA's guidance, apply mitigations in accordance with vendor instructions and BOD 26-04.
Google's Chrome advisory lists three flaws fixed in 154.0.8037.92 — CVE-2026-102331, CVE-2026-102316 and CVE-2026-102309, each with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H and base score 9.6; update Chrome to 154.0.8037.92. These are not on CISA's KEV catalog.
Two critical server-side fixes landed. BleepingComputer and The Hacker News reported that GitLab warned customers to immediately patch a critical AI Gateway flaw; The Hacker News said a logged-in user with Duo Agent Platform access could run commands on the gateway under certain conditions. The Hacker News also reported that Dell released updates for multiple critical flaws in Dell Container Storage Modules that could allow unauthenticated admin access and root on Kubernetes nodes.
On threat activity, BleepingComputer reported that the China-linked Warlock ransomware group breached a water utility, a telecom provider, a regional government body and a university by exploiting SharePoint vulnerabilities for initial access. The Hacker News reported that a China-nexus actor deployed the Antino backdoor, which uses Outlook and OneDrive for command-and-control, against government and policy organisations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand and Myanmar.
In other incidents, BleepingComputer reported that Frontline Education is notifying school districts of a breach after attackers exploited a vulnerability in third-party software and stole employee data including Social Security numbers, and that the U.S. Treasury sanctioned eight Tren de Aragua members over ATM jackpotting attacks. The Record reported that ransomware forced Vicksburg, Mississippi to shut down systems, with Mayor Willis Thompson saying the FBI is investigating, and that a California judge dismissed the Pegasus spyware case brought by El Faro journalists for lack of jurisdiction.
Sources
- The Record — Judge dismisses spyware case brought by Salvadoran journalists targeted with Pegasus
- BleepingComputer — Frontline Education breach exposes school district employee data
- The Hacker News — GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
- SecurityWeek — In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats
- Help Net Security — AI is giving attackers a head start, Microsoft warns
- CISA — CISA Adds Two Known Exploited Vulnerabilities to Catalog
- Schneier on Security — How American Political Campaigns Are Using AI—and What They’re Spending on the Tools
- The Register — Fortinet sounds the alarm over actively exploited FortiMail zero-day
- BleepingComputer — Warlock ransomware breach SharePoint in water, telecom operator attacks
- The Hacker News — Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign
- The Hacker News — Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes
- BleepingComputer — GitLab warns of critical RCE vulnerability in AI Gateway service
- BleepingComputer — US sanctions Tren de Aragua gang members in ATM hacks crackdown
- The Record — Mississippi mayor says ransomware incident led city to shut down systems