ITSECURITY.GURU WHAT HAPPENED · DOES IT AFFECT YOU · WHAT TO DO
Board › Briefings › Fortinet FortiMail zero-day under active attack as CISA flags fresh exploited flaws
IT SECURITY DESK

Fortinet FortiMail zero-day under active attack as CISA flags fresh exploited flaws

Friday brought an actively exploited FortiMail zero-day with no patch for some admins, new entries on CISA's exploited-vulnerabilities catalog, and critical fixes from Citrix, Apple, Google, GitLab and Dell.

The Register reported that Fortinet sounded the alarm over an actively exploited FortiMail zero-day, stating that no login is required, exploitation is underway, and some admins are still waiting for patches. Treat internet-facing FortiMail as a priority: confirm your version against Fortinet's advisory, apply the fix as soon as it is available for your build, and review mail-gateway logs and admin accounts for signs of access.

CISA added two vulnerabilities to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation, both in Zammad: a session fixation flaw and an improper privilege management flaw. CISA states that Binding Operational Directive 26-04 requires federal agencies to prioritise rapid remediation of catalog entries; organisations running Zammad should patch to the vendor's fixed release.

On the exploited edge, CISA's KEV catalog lists CVE-2026-88771 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, base score 9.8) and CVE-2026-88772 (vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H, base score 8.1) in Citrix NetScaler ADC and Gateway, affecting 13.1 up to the fix in 13.1-64.23 — upgrade to 13.1-64.23 per Citrix's bulletin. CISA's KEV catalog also lists CVE-2026-86950 (vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, base score 8.8) in Apple macOS up to the fix in 15.8.1; apply 15.8.1 per Apple's advisory. For federal agencies and anyone following CISA's guidance, apply mitigations in accordance with vendor instructions and BOD 26-04.

Google's Chrome advisory lists three flaws fixed in 154.0.8037.92 — CVE-2026-102331, CVE-2026-102316 and CVE-2026-102309, each with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H and base score 9.6; update Chrome to 154.0.8037.92. These are not on CISA's KEV catalog.

Two critical server-side fixes landed. BleepingComputer and The Hacker News reported that GitLab warned customers to immediately patch a critical AI Gateway flaw; The Hacker News said a logged-in user with Duo Agent Platform access could run commands on the gateway under certain conditions. The Hacker News also reported that Dell released updates for multiple critical flaws in Dell Container Storage Modules that could allow unauthenticated admin access and root on Kubernetes nodes.

On threat activity, BleepingComputer reported that the China-linked Warlock ransomware group breached a water utility, a telecom provider, a regional government body and a university by exploiting SharePoint vulnerabilities for initial access. The Hacker News reported that a China-nexus actor deployed the Antino backdoor, which uses Outlook and OneDrive for command-and-control, against government and policy organisations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand and Myanmar.

In other incidents, BleepingComputer reported that Frontline Education is notifying school districts of a breach after attackers exploited a vulnerability in third-party software and stole employee data including Social Security numbers, and that the U.S. Treasury sanctioned eight Tren de Aragua members over ATM jackpotting attacks. The Record reported that ransomware forced Vicksburg, Mississippi to shut down systems, with Mayor Willis Thompson saying the FBI is investigating, and that a California judge dismissed the Pegasus spyware case brought by El Faro journalists for lack of jurisdiction.

Related