Fortinet Zero-Day Hits FortiMail Gateways
Fortinet reports active exploitation of a critical FortiMail flaw, with patches still pending and CISA ordering federal fixes by October 4th.
21 results for “active exploitation”
Fortinet reports active exploitation of a critical FortiMail flaw, with patches still pending and CISA ordering federal fixes by October 4th.
Arista says attackers are actively exploiting CVE-2026-93952, a maximum-severity flaw in on-premises VeloCloud Orchestrator setups using certificate authentication.
Cisco has fixed a maximum-severity ISE authentication bypass that attackers are already exploiting, and CISA set a three-day federal patch deadline.
Sansec reports active attacks on a max-severity Magento flaw, with backdoors and secondary access found.
CERT Poland warns of active exploitation of two critical MikroTik RouterOS vulnerabilities, enabling full router hijacking.
CVE-2026-9586, an unauthenticated SQL injection in Switchvox, is under active exploitation, Horizon3 reports.
SonicWall patches two zero-days in SMA 1000 VPN appliances, warning of active exploitation that combines both flaws.
CVE-2026-82329, a critical Artifactory auth bypass, is reportedly under active attack post-disclosure.
CISA adds CVE-2026-21962 to KEV catalog, citing active exploitation and urging federal agencies to patch by August 27.
GitLab's CVE-2026-19478 is under active exploitation, days after disclosure, urging immediate patching.
Government agencies warn of active exploitation of Siemens S7 controllers using AI-generated attack code.
CISA warns of active exploitation of critical command injection flaw in Progress Kemp LoadMaster; urges patching.
A critical command injection vulnerability in Progress LoadMaster is under active exploitation, prompting urgent CISA remediation requirements.
A deserialization vulnerability in JetBrains TeamCity is under active exploitation, forcing federal agencies to patch systems by August 8, 2026.
A static credential vulnerability in Cisco Secure FMC Software is undergoing active exploitation in the wild, according to the company.
WordPress Core is currently under active exploitation via a SQL injection vulnerability that can be chained to achieve remote code execution.
Enterprise AI systems face active exploitation of a high-complexity remote code execution flaw following a recent patch release.
CISA has confirmed active exploitation of an OS command injection vulnerability in Fortinet FortiSandbox, mandating urgent remediation for federal agencies.
A critical account lockout vulnerability in KNX Association products is now under active exploitation, requiring immediate remediation by federal agencies.
CISA mandates federal agencies secure Oracle E-Business Suite systems by Saturday to mitigate active exploitation risks.
Federal agencies must secure SharePoint servers against active exploitation of three critical remote code execution vulnerabilities.