Vulnerabilities & Patches
FortiMail Zero-Day Vulnerability Exploited in the Wild
A FortiMail zero-day vulnerability, CVE-2026-104286 (CVSS 9.8), lets an unauthenticated attacker write arbitrary files onto Fortinet’s email security appliance with nothing more than crafted web requests. Fortinet confirmed active exploitation on October 1, CISA added the flaw to its Known Exploited Vulnerabilities catalog the same day, and fixed releases for the 7.4, 7.6 and 8.0…
Read MoreSpectre v2 Branch Target Reuse vulnerability
Researchers disclosed a new Spectre v2 Branch Target Reuse vulnerability on September 29 that lets an attacker recover a Linux system’s root password hash in minutes, on a fully patched Intel machine, by abusing a gap between how CPUs and just-in-time compilers handle recycled memory. The flaw touches Intel, AMD and Arm processors alike, and…
Read MoreCitrix NetScaler unauthenticated RCE vulnerability
Citrix confirmed on September 27 that a Citrix NetScaler unauthenticated RCE vulnerability, tracked as two separate CVEs, was already being exploited in the wild before any patch existed. CVE-2026-88771 lets an attacker with no credentials run arbitrary commands on any NetScaler ADC or Gateway appliance in a vulnerable version, default configuration included. Its sibling flaw,…
Read MoreArista VeloCloud Orchestrator vulnerability
An Arista VeloCloud Orchestrator vulnerability, CVE-2026-93952 (CVSS 10.0), lets an attacker reach privileged internal functions on the on-premises controller for an entire SD-WAN fabric without any credentials at all. Arista confirmed active exploitation and shipped a patch on September 22. This is the second maximum-severity CVE in this exact product line in 2026, after the…
Read MoreF5 BIG-IP APM RCE Vulnerability Exploited
F5 has confirmed active, unauthenticated exploitation of a critical F5 BIG-IP APM RCE vulnerability, tracked as CVE-2026-94127 (CVSS 9.8), affecting Access Policy Manager instances configured as OAuth Authorization Servers. CISA added the flaw to its Known Exploited Vulnerabilities catalog the same day F5 disclosed it, September 22, and gave federal agencies until Friday, September 25…
Read More
