Posts Tagged ‘zero-day’
FortiMail Zero-Day Vulnerability Exploited in the Wild
A FortiMail zero-day vulnerability, CVE-2026-104286 (CVSS 9.8), lets an unauthenticated attacker write arbitrary files onto Fortinet’s email security appliance with nothing more than crafted web requests. Fortinet confirmed active exploitation on October 1, CISA added the flaw to its Known Exploited Vulnerabilities catalog the same day, and fixed releases for the 7.4, 7.6 and 8.0…
Read MoreTop 5 Cybersecurity News
This week’s Top 5 Cybersecurity News for October 2, 2026 follows a pattern that has been building across the year: attackers are targeting the layers that other infrastructure trusts. A critical-severity zero-day in Cisco’s SD-WAN Manager — the console that programs an entire enterprise WAN — arrived in CISA’s Known Exploited Vulnerabilities catalog on September…
Read MoreWindows Defender ShieldCrash Exploit Bypasses Patch
A new Windows Defender ShieldCrash exploit went public on September 9, granting SYSTEM-level access on fully patched Windows 10, Windows 11, and Windows Server systems, including machines that had already installed Microsoft’s own September Patch Tuesday fix for the previous bug in the same family. No CVE has been assigned, and no patch or official…
Read MoreAdobe Commerce Magento RCE Vulnerability Under Attack
An Adobe Commerce Magento RCE vulnerability nicknamed StyleSmuggler let attackers plant Rust-based Linux backdoors on live webshops for at least five days before Adobe shipped a fix. Tracked as CVE-2026-75650 with a maximum CVSS score of 10.0, the flaw requires no authentication and has already been used to backdoor real merchant sites, not just proof-of-concept…
Read MoreChrome Zero-Day Vulnerability Exploited Before the Patch
Google says a Chrome zero-day vulnerability was already being exploited in the wild when it shipped a fix for it. Tracked as CVE-2026-85046 (CVSS 8.8), the flaw sits in V8, Chrome’s JavaScript and WebAssembly engine, and lets a crafted web page execute attacker-controlled code inside the browser sandbox. Security reporting identifies it as the sixth…
Read More
