1. Top Action Item

Patch FortiMail now. Fortinet is warning of a CVSS 9.8 improper path-traversal / NULL-byte flaw (reported as CVE-2026-104286) that lets an unauthenticated attacker write arbitrary files to the underlying system via crafted HTTP/HTTPS requests, and the vendor states it has been exploited in the wild. CISA added it to the Known Exploited Vulnerabilities catalog on Thursday. Apply Fortinet's published workaround immediately and move to a fixed FortiMail release per the PSIRT advisory.


2. Exploited This Week

Fortinet FortiMail — CVE-2026-104286

Citrix NetScaler — CVE-2026-88771 and CVE-2026-88772

Microsoft SharePoint (Warlock ransomware campaign)


3. Critical Patch Roundup

Dell — Container Storage Modules (CSM)

GitLab — AI Gateway

Fortra — BoKS

Microsoft — Exchange Server (CVE-2026-96940)

Chromium — ANGLE heap buffer overflow (CVE-2025-10502)

SWIFT banking / government middleware — RCE


4. Home / SOHO Impact


5. Enterprise Impact


6. What To Patch First

  1. Fortinet FortiMail — CVE-2026-104286 (exploited in the wild; CISA KEV; CVSS 9.8)
  2. Citrix NetScaler — CVE-2026-88771, CVE-2026-88772 (exploited in the wild)
  3. Microsoft SharePoint — Warlock exploitation chain (exploited; ransomware; see source for versions)
  4. Dell Container Storage Modules — CVE-2026-63688 (CVSS 10.0, critical, Kubernetes node takeover)
  5. GitLab AI Gateway — 19.2.4 / 19.3.2 / 19.4.1 (critical; self-hosted deployments only)
  6. Fortra BoKS — critical auth bypass and command execution (see source)
  7. Microsoft Exchange Server — CVE-2026-96940 (widely deployed; see source for severity)
  8. Chromium-based browsers (Chrome/Edge) — CVE-2025-10502 (widely deployed browser component; see source)

Sources