โ† October 2026
News 2026-10-03

๐Ÿ›ก๏ธ Cybersecurity Vulnerability Watch

Patch FortiMail now. Fortinet is warning of a CVSS 9.8 improper path-traversal / NULL-byte flaw (reported as CVE-2026-104286) that lets an unauthenticated attacker write arbitrary files to theโ€ฆ

๐Ÿ›ก๏ธ Cybersecurity Vulnerability Watch
Open report

๐Ÿ›ก๏ธ Cybersecurity Vulnerability Watch

Week of: 2026-09-27 โ€“ 2026-10-03 Reporting window: Most recently completed Sundayโ€“Saturday (excludes the in-progress week).


1. Top Action Item

Patch FortiMail now. Fortinet is warning of a CVSS 9.8 improper path-traversal / NULL-byte flaw (reported as CVE-2026-104286) that lets an unauthenticated attacker write arbitrary files to the underlying system via crafted HTTP/HTTPS requests, and the vendor states it has been exploited in the wild. CISA added it to the Known Exploited Vulnerabilities catalog on Thursday. Apply Fortinet's published workaround immediately and move to a fixed FortiMail release per the PSIRT advisory.


2. Exploited This Week

Fortinet FortiMail โ€” CVE-2026-104286

  • Source: The Hacker News / Fortinet FortiGuard PSIRT
  • Link: The Hacker News
  • Severity: Critical (CVSS 9.8)
  • What's happening: An unauthenticated attacker can write arbitrary files on the underlying system via crafted HTTP or HTTPS requests; Fortinet reports the flaw has been exploited in the wild and CISA added it to the KEV catalog.
  • Fix: Apply the workaround in Fortinet PSIRT advisory FG-IR-26-175 (CVSS 9.8, "improper limitation of a pathname to a restricted directory" / NULL-byte neutralization) and upgrade to a fixed FortiMail version โ€” see source for the patched release.

Citrix NetScaler โ€” CVE-2026-88771 and CVE-2026-88772

  • Source: Palo Alto Unit 42
  • Link: Unit 42
  • Severity: see source
  • What's happening: Citrix reports these NetScaler zero-days have been exploited in the wild; Unit 42 says it is aware of possible zero-day activity against NetScaler devices.
  • Fix: Apply Citrix's updates/mitigations for both CVEs โ€” see the Unit 42 threat brief and the associated Citrix advisory for versions.

Microsoft SharePoint (Warlock ransomware campaign)

  • Source: The Hacker News
  • Link: The Hacker News
  • Severity: see source
  • What's happening: The suspected China-linked actor Warlock is weaponizing Microsoft SharePoint vulnerabilities โ€” likely both old and new โ€” to disable security tools and deploy ransomware against critical infrastructure, government, and education organizations in Portuguese- and Spanish-speaking countries.
  • Fix: Patch SharePoint (the specific CVEs and versions are not named in the source โ€” see source), and treat disabled/tampered security tooling as a compromise indicator.

3. Critical Patch Roundup

Dell โ€” Container Storage Modules (CSM)

  • Source: The Hacker News
  • Link: The Hacker News
  • Severity: Critical (CVE-2026-63688, CVSS 10.0)
  • What's happening: A missing authentication for critical function flaw in the csm-authorization-storage gRPC server, part of a set of critical CSM flaws, can be exploited to gain unauthenticated admin access and root on Kubernetes nodes.
  • Fix: Apply Dell's released CSM security updates โ€” see source for affected versions.

GitLab โ€” AI Gateway

  • Source: The Hacker News
  • Link: The Hacker News
  • Severity: Critical (9.9 per source)
  • What's happening: A flaw in the self-hosted AI Gateway (the service connecting a GitLab instance to AI models) could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions.
  • Fix: Upgrade the gateway to 19.2.4, 19.3.2, or 19.4.1. Only organizations hosting their own gateway are affected.

Fortra โ€” BoKS

  • Source: SecurityWeek
  • Link: SecurityWeek
  • Severity: Critical (per source)
  • What's happening: Critical BoKS vulnerabilities could lead to authentication bypass, shell command execution, and memory corruption.
  • Fix: Apply Fortra's BoKS patches โ€” see source for versions.

Microsoft โ€” Exchange Server (CVE-2026-96940)

  • Source: Microsoft MSRC
  • Link: Microsoft MSRC
  • Severity: see source
  • What's happening: Weak authorization in Exchange Server allows an authenticated attacker to elevate privileges over a network.
  • Fix: Apply the update-guide remediation โ€” see source.

Chromium โ€” ANGLE heap buffer overflow (CVE-2025-10502)

  • Source: Microsoft MSRC
  • Link: Microsoft MSRC
  • Severity: see source
  • What's happening: Heap buffer overflow in ANGLE affecting Chromium-based browsers; the advisory was published this week.
  • Fix: Update your Chromium-based browser to a build containing the fix โ€” see source for version.

SWIFT banking / government middleware โ€” RCE

  • Source: Dark Reading
  • Link: Dark Reading
  • Severity: see source
  • What's happening: Middleware vulnerabilities in SWIFT banking and government environments can be chained toward remote code execution and hardware-based MFA exploits.
  • Fix: Patch the middleware now โ€” specific CVEs/versions are not given in the source.

4. Home / SOHO Impact

  • Update your browser: Microsoft published an advisory for CVE-2025-10502, a heap buffer overflow in ANGLE (the graphics component used by Chromium-based browsers). Install the latest Chrome or Edge update โ€” see source for the version.
  • Be wary of "Custom GPT" prompts: Threat actors are using malicious custom GPTs in ClickFix-style attacks that abuse legitimate OpenAI and Google domains to trick users into running commands that deliver remote-access trojans. Don't paste or run commands a chatbot or web page tells you to.
  • Think twice about giving an AI assistant full disk access: Google's Gemini may soon be able to read any file on a macOS device, open apps, and browse the web without asking each time. Review and restrict those permissions before turning them on.
  • On Android, consider Advanced Protection: Google will restrict accessibility-service access to verified "Accessibility Tools" apps when Advanced Protection is enabled, blocking a major malware and financial-fraud pathway. Enable it if it's available on your device.
  • If you run FortiMail at home or in a small office: treat it as urgent โ€” that flaw is being actively exploited and is in CISA's KEV catalog. Apply Fortinet's workaround and update.

5. Enterprise Impact

  • FortiMail (CVE-2026-104286): highest priority. Unauthenticated arbitrary file write, confirmed exploited, CISA KEV. Apply the FG-IR-26-175 workaround and patch; hunt for webshells or dropped files on internet-facing mail gateways.
  • Citrix NetScaler (CVE-2026-88771, CVE-2026-88772): zero-days exploited in the wild. Patch and review NetScaler logs for exploitation attempts; assume edge devices are a primary target.
  • Microsoft SharePoint (Warlock): an active ransomware operator is chaining SharePoint flaws to disable security tooling before encrypting. Patch SharePoint fully, alert on EDR/AV tampering, and prioritize external-facing SharePoint servers.
  • Dell Container Storage Modules (CVE-2026-63688, CVSS 10.0): unauthenticated access to the csm-authorization-storage gRPC server can yield admin access and root on Kubernetes nodes. Patch and restrict network exposure of the gRPC endpoint.
  • GitLab self-hosted AI Gateway (9.9): patch to 19.2.4 / 19.3.2 / 19.4.1 and review who holds Duo Agent Platform access.
  • Fortra BoKS: critical auth-bypass and command-execution flaws in identity/privileged access infrastructure โ€” patch promptly.
  • Microsoft Exchange (CVE-2026-96940): authenticated privilege escalation over the network โ€” include in your Exchange patch cycle.
  • Kubernetes operators / non-human identities: Unit 42's OperTraitor research highlights excessive RBAC in Kubernetes operators; audit operator privileges and service-account permissions.
  • Ongoing espionage exposure: Cisco Talos' UAT-11587 tracked a China-nexus campaign delivering the "Antino" backdoor against government and policy organizations across Asia, and separate reporting describes Linux implants masquerading as Asian mail-security products โ€” review edge/mail infrastructure for impersonated or unexpected services.

6. What To Patch First

  1. Fortinet FortiMail โ€” CVE-2026-104286 (exploited in the wild; CISA KEV; CVSS 9.8)
  2. Citrix NetScaler โ€” CVE-2026-88771, CVE-2026-88772 (exploited in the wild)
  3. Microsoft SharePoint โ€” Warlock exploitation chain (exploited; ransomware; see source for versions)
  4. Dell Container Storage Modules โ€” CVE-2026-63688 (CVSS 10.0, critical, Kubernetes node takeover)
  5. GitLab AI Gateway โ€” 19.2.4 / 19.3.2 / 19.4.1 (critical; self-hosted deployments only)
  6. Fortra BoKS โ€” critical auth bypass and command execution (see source)
  7. Microsoft Exchange Server โ€” CVE-2026-96940 (widely deployed; see source for severity)
  8. Chromium-based browsers (Chrome/Edge) โ€” CVE-2025-10502 (widely deployed browser component; see source)

Sources

More from News