LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingCVE-2026-7273 · Zyxel GS1900 Switch Flaw Exploited, Now in EU CatalogueCVE-2026-102489 · Zammad Session Fixation Vulnerability Exploited Same Day as DisclosureCVE-2026-102490 · Zammad GmbH Zammad Vulnerability Exploited Same Day as Publication

fortinet news

6 stories
CVE-2026-104286critical

Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action

A critical-severity zero-day vulnerability, tracked as CVE-2026-104286, has been reported in Fortinet's FortiMail email security gateway. The flaw is described as a path traversal vulnerability that permits attackers to write arbitrary files to the underlying system. Organizations leveraging FortiMail deployments are advised to take immediate mitigation steps due to the active exploitation of…

CVE-2026-104286critical

U.S. CISA adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Fortinet FortiMail vulnerability, identified as CVE-2026-104286, to its Known Exploited Vulnerabilities (KEV) catalog. The flaw, which carries a CVSS score of 9.8, is a path traversal vulnerability that attackers are reportedly exploiting in the wild.

CVE-2026-25089critical

CISA Adds Fortinet and Microsoft Flaws to Exploited Vulnerabilities List

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, requiring federal agencies to address them by July 19, 2026. The newly listed flaws include one affecting Microsoft SharePoint and two impacting Fortinet FortiSandbox products.

CVE-2026-24858high

FortiBleed: Credential Reuse, Legacy Hashes, and the Risk of Internet-Exposed FortiGate Devices

The cybersecurity landscape is grappling with the fallout from "FortiBleed," a widespread credential abuse campaign targeting internet-exposed FortiGate devices. Public reports emerged in June 2026 detailing extensive datasets containing Fortinet-related URLs, device records, usernames, and credentials. This activity is not attributed to a single new vulnerability but rather the reuse of…

fortinetcritical

FortiBleed Campaign Exposing Credentials for 73,932 FortiGate Systems

A campaign dubbed "FortiBleed" has exposed administrative and VPN credentials for an estimated 73,932 FortiGate firewall systems globally. The compromised data, reportedly originating from a Russian-speaking threat group, has impacted organizations across critical sectors including government, telecommunications, financial services, healthcare, manufacturing, and multinational corporations.

fortinethigh

Alert: NCSC issues advice following global targeting of Fortinet firewalls and VPN gateways

Organizations utilizing Fortinet firewalls and VPN gateways are being alerted to a global campaign that has targeted these devices. The National Cyber Security Centre (NCSC) in the UK has issued guidance for affected entities, urging them to investigate potential compromises and implement mitigation strategies.