Fortinet FortiMail Zero-Day (CVE-2026-104286) Actively Exploited. A critical path traversal flaw in FortiMail's management interface allows unauthenticated attackers to write arbitrary files, potentially enabling code execution. CISA added it to the KEV catalog with a three-day remediation window for federal agencies; Fortinet has not yet released a patch and recommends disabling IBE or restricting web management access as interim mitigations. Learn more
Dell Container Storage Modules: Max-Severity Kubernetes Flaws. CVE-2026-63688 and CVE-2026-63692 allow unauthenticated remote attackers to bypass authentication in Dell CSM's Authorization module, forge tokens, and escalate to root on Kubernetes cluster nodes (CVE-2026-67269). Organizations running Dell enterprise storage integrated with Kubernetes should update to CSM version 1.18.0 or later immediately.
GitLab Critical RCE in AI Gateway Service (CVE-2026-90970). A CVSS 9.9 flaw allows authenticated users with Duo Agent Platform access to escape the prompt template sandbox and execute arbitrary commands on self-hosted AI Gateway deployments. Patched versions 19.2.4, 19.3.2, and 19.4.1 are available; cloud-hosted instances are already protected.
Zimbra Zero-Day Exploited Before Public Disclosure. CVE-2026-73570, a critical OS command injection flaw in Zimbra Collaboration Suite, was actively exploited in the window between patching and public disclosure. Attackers achieved RCE, deployed webshells, and exfiltrated credentials, reinforcing that the patch window is not a safe window. Learn more
Key Takeaway
Prioritize FortiMail workarounds immediately, patch Dell CSM and GitLab AI Gateway this week, and treat any Zimbra-adjacent systems as potentially compromised if patching was delayed.
