Vulnerability news
CVE news for internet-facing software.
Exploited and critical vulnerabilities in the software organizations put on the internet: VPN gateways and edge appliances, web and mail servers, content management systems and DevOps tools. Each post gives the CVE IDs, affected and fixed versions, CISA KEV status where it applies, and a short list of what to check on your own hosts this week.
FortiMail Zero-Day Lets Attackers Write Files to Mail Gateways Without Logging In
CVE-2026-104286, a CVSS 9.8 path traversal in Fortinet FortiMail's IBE feature, was exploited as a zero-day and added to CISA's KEV catalog on October 1, 2026. Affected and fixed versions, the workaround, and the indicators Fortinet published.
Read article →A New NetScaler Zero-Day Is Crashing Appliances Already Patched for Last Week's Bugs
CVE-2026-88779, a memory overflow in NetScaler ADC and Gateway configured for SAML, was exploited to crash appliances running the builds that fixed CVE-2026-88771. CISA added it to KEV on October 4, 2026. Fixed builds and what to check.
Read article →Two NetScaler Zero-Days Were Exploited for Weeks Before Citrix Patched Them
Citrix disclosed eight NetScaler ADC and Gateway flaws on September 27, 2026, including two unauthenticated RCE bugs (CVE-2026-88771, CVE-2026-88772, CVSS 9.5) already exploited as zero-days. CISA added both to KEV the same day. Fixed builds and what to check.
Read article →Arista VeloCloud Orchestrator Zero-Day (CVSS 10.0) Exploited, and Two Release Trains Have No Fix Yet
CVE-2026-93952 in on-premises Arista VeloCloud Orchestrator (CVSS 3.1 10.0) is exploited and on CISA KEV since September 22, 2026. Fixes exist for 5.2.3 and 6.4.2 only. Affected versions, indicators and what to check.
Read article →F5 BIG-IP APM and Check Point VPN Gateways Hit by Pre-Auth Exploits in the Same Week
On September 22, 2026 CISA added an exploited F5 BIG-IP APM zero-day (CVE-2026-94127, CVSS 9.8) and two exploited Check Point flaws (CVE-2026-85102, CVE-2026-93616) to its KEV catalog. Affected versions, fixes and what to check.
Read article →Nearly 1,000 Zyxel GS1900 Switches Hacked Through a Bug Rated "LAN Only"
CVE-2026-7273, a pre-auth stack overflow in Zyxel GS1900 switches patched in June 2026, was used to compromise 996 switches in 48 countries. CISA added it to the KEV on September 21. Affected firmware, fixes and what to check.
Read article →GitLab's CVSS 10 File-Read Bug Was Exploited a Day After the Patch
CVE-2026-85706 lets an unauthenticated attacker read arbitrary files from a self-managed GitLab server. GitLab patched it on September 10, 2026; CISA listed it as exploited on September 11. Versions, fixes and what to check.
Read article →Cisco Firewall Management Center and FortiGate Firewalls Exploited: Two Old Patches Become Three-Day Deadlines
On September 9, 2026 CISA added Cisco Secure FMC CVE-2026-20079 (CVSS 10.0) and Fortinet FortiOS CVE-2025-25249 to its KEV catalog. Both were patched months ago and are now exploited. Affected and fixed versions, and what to check.
Read article →Citrix NetScaler Auth Bypass CVE-2026-19490 Is Now Exploited. CISA Gave Agencies Three Days.
CVE-2026-19490, a CVSS 9.3 authentication bypass in NetScaler ADC and Gateway, was added to CISA's KEV catalog on September 9, 2026 after exploitation attempts began. Affected builds, fixed builds and how to check your exposure.
Read article →N-able N-central Pre-Auth RCE Exploited on Fully Patched Servers. Hotfix 3 Is Not Enough.
CVE-2026-86218 is an exploited pre-authentication RCE in N-able N-central before 2026.3.1.14 (CVSS 4.0 10.0). CISA added it to the KEV on September 8, 2026. What happened, which hotfix you need, and how to check exposure.
Read article →StyleSmuggler: Unauthenticated RCE in Magento and Adobe Commerce Was Exploited Three Days Before the Patch
CVE-2026-75650 (StyleSmuggler, CVSS 10.0) gives unauthenticated remote code execution on Adobe Commerce and Magento Open Source 2.4.4 to 2.4.9. Exploited from September 4, patched September 7, added to CISA KEV September 8. Versions, hotfix and what to check.
Read article →CISA Adds Seven Exploited Flaws in One Day. Two Score a Perfect 10, All Sit on Internet-Facing Software.
On September 2, 2026 CISA added seven actively exploited CVEs to its KEV catalog, including a CVSS 10 SonicWall SMA 1000 flaw and a CVSS 10 Kestra bug. Under BOD 26-04, publicly exposed assets get three days. How to know what you expose.
Read article →