Fortinet FortiMail zero-day under active attack tops a heavy patch day for Citrix, Apple and Chrome
A critical FortiMail flaw is being exploited in zero-day attacks and has been added to CISA's catalog, alongside actively exploited Citrix and Apple bugs and three high-severity Chrome fixes.
Fortinet is warning customers of a critical FortiMail vulnerability that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices, BleepingComputer reported. CISA added the flaw to its Known Exploited Vulnerabilities Catalog on 1 October, describing it as a "Fortinet FortiMail Path Traversal Vulnerability" and citing evidence of active exploitation. CISA's Binding Operational Directive 26-04 requires Federal Civilian Executive Branch agencies to prioritise rapid remediation of KEV-listed vulnerabilities on publicly exposed assets. If you run FortiMail, follow Fortinet's advisory and treat any internet-facing instance as the priority.
Three more actively exploited flaws carry fixes. CISA's KEV catalog lists CVE-2026-88771 in Citrix NetScaler ADC, scored 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), affecting version 13.1 and fixed in 13.1-64.23, and CVE-2026-88772, scored 8.1, in the same product and fix. Both are known to be exploited. CISA's KEV catalog also lists CVE-2026-86950 in Apple macOS, scored 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H), affecting releases up to the fix in macOS 15.8.1 and known to be exploited. Citrix's security bulletin and Apple's advisory cover the fixed releases.
Google's Chrome stable channel update fixes three flaws each scored 9.6 — CVE-2026-102331, CVE-2026-102316 and CVE-2026-102309 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H) — in Chrome up to the fix in 154.0.8037.92, per Google's advisory. CISA does not list these three as exploited.
On enforcement, Spanish police arrested a 16-year-old suspected of running the KillSec ransomware group, The Hacker News reported — one of three people arrested on 30 September in an operation that also seized the group's leak site and servers. Help Net Security reported that Eurojust says KillSec is responsible for almost 1,000 attacks worldwide and has been active since 2024. Separately, The Record reported that an Iranian national accused by the U.S. of taking part in dozens of breaches involving the theft of academic data and intellectual property has been extradited from Montenegro.
AI featured across the day's reporting. The Register reported that chained Zammad flaws let AI agents hijack sessions, execute code and escalate to root at a security research organisation to steal email addresses. The Record reported that two cybersecurity companies found China-linked hacking operations, including a phishing campaign that impersonated Western experts and targeted AI firms and Asian governments.
Sources
- BleepingComputer — Fortinet warns of critical FortiMail flaw exploited in zero-day attacks
- The Register — AI agents hacked the hackers, stealing email addresses from security research org
- The Record — Iranian accused of hacking American universities extradited from Montenegro
- SecurityWeek — Zero Trust Creator Says Model Holds Firm Against AI-Assisted Attacks
- The Hacker News — Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers
- Help Net Security — 16-year-old suspected leader of KillSec ransomware group arrested
- CISA — CISA Adds One Known Exploited Vulnerability to Catalog
- Schneier on Security — Connected Cars Are a Surveillance Platform
- BleepingComputer — Autonomous AI agents tried to hack US, Canadian government websites
- BleepingComputer — Microsoft says threat actors are ahead in the early AI race
- The Record — Researchers find Chinese hacking campaigns targeting AI firms, Asian governments
- The Register — EU’s hodgepodge tech policy exposes members to Chinese vendor risks, says think tank
- SecurityWeek — Osavul Lands $10 Million to Spot Hostile Intent Across Cyber, Physical Domains
- The Hacker News — ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories