Critical Fortinet FortiMail Zero-Day: CVE-2026-104286 Enables Unauthenticated Arbitrary File Writes
In October 2026, CISA added CVE-2026-104286 to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation targeting Fortinet FortiMail email security gateways. This CVSS 9.8 vulnerability arises from the intersection of improper pathname limitation (CWE-22) and improper neutralization of null bytes (CWE-158) within the web management interface. Unauthenticated attackers can leverage crafted HTTP requests containing path traversal sequences and null bytes to bypass directory restrictions, allowing arbitrary file writes outside the intended web root. This flaw enables remote code execution (RCE) through webshell deployment, potential credential theft from mailboxes, and subsequent lateral movement within corporate networks.
Citrix NetScaler: Critical SAML Memory Overflow Vulnerability CVE-2026-8452
CVE-2026-8452 is a critical memory overflow vulnerability residing in the SAML implementation of Citrix NetScaler ADC and Gateway. The flaw is triggered during the processing of SAML requests and assertions, where improper input buffer handling leads to memory corruption. This can result in a Denial of Service (DoS) or unpredictable system behavior. Due to the edge-facing nature of these appliances, the risk of unauthorized remote access or service disruption is significant. CISA has officially added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog following confirmed in-the-wild exploitation, mandating federal remediation by August 29, 2026. This flaw is part of a broader pattern of memory safety issues categorized by researchers as "CitrixBleed Infinity."
Oracle WebLogic Server Authentication Bypass CVE-2024-21182
CVE-2024-21182 is a critical authentication bypass vulnerability within the Oracle WebLogic Server Core component. This flaw allows unauthenticated attackers to circumvent security mechanisms via the T3 and IIOP protocols, potentially enabling a full unauthenticated system takeover. Due to confirmed active exploitation in the wild, CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, imposing a mandatory June 4 remediation deadline for federal entities. Failure to patch immediately risks large-scale unauthorized access, confidentiality compromise, and total control of affected WebLogic environments.