Security news.
Critical enterprise infrastructure is under heavy pressure today, led by active zero-day exploitation against Fortinet edge appliances and high-severity access flaws in Dell and GitLab services. State-aligned actors are also aggressively weaponising compromised enterprise tools, with China-linked groups hitting critical infrastructure via SharePoint vulnerabilities and deploying novel backdoors. Meanwhile, federal agencies have mandated emergency fixes as active exploitation catalogs continue to expand.
Critical Fortinet FortiMail Zero-Day Exploited in Attacks
CISA has added CVE-2026-104286 (CVSS 9.8) to its Known Exploited Vulnerabilities catalog following active in-the-wild exploitation that allows unauthenticated attackers to write arbitrary files.
Dell CSM Vulnerabilities Grant Root on Kubernetes Nodes
Dell patched multiple critical security flaws in its Container Storage Modules, including CVE-2026-63688 (CVSS 10.0), which permits unauthenticated admin access and complete node takeover.
GitLab AI Gateway Flaw Enables Remote Command Execution
A critical vulnerability (CVSS 9.9) in GitLab's self-hosted AI Gateway could allow authenticated users with Duo Agent Platform access to execute arbitrary commands on the host server.
Warlock Ransomware Targets Utilities via SharePoint Flaws
China-linked threat group Warlock breached a water provider, telecom operator, and government body by leveraging unpatched Microsoft SharePoint vulnerabilities for initial entry.
CISA Orders Patches for Exploited Zammad Helpdesk Vulnerabilities
CISA added two actively exploited Zammad vulnerabilities (CVE-2026-102489 and CVE-2026-102490) to the KEV catalog, warning of widespread session fixation and improper privilege management risks.
Fortra Patches Critical Authentication Bypass Flaws in BoKS
Fortra addressed high-severity security bugs in its BoKS Server product that allow unauthenticated attackers to bypass authentication, corrupt memory, and execute shell commands.
Antino Backdoor Targets Asian Governments via Microsoft Services
A China-nexus espionage campaign tracked as UAT-11587 is deploying a newly discovered backdoor across government entities, abusing Outlook and OneDrive infrastructure for stealth command-and-control.