Do you need to patch tonight?

Latest analysis

All updates
CVE-2026-104286FortinetFortiMail zero-day lets attackers write files without logging inA path traversal in FortiMail's Identity-Based Encryption (IBE) web service lets unauthenticated attackers write arbitrary files (CVSS 9.8). Exploited before disclosure; attackers set up mail archiving to their own server.CVE-2026-50751Check PointCheck Point VPN login bypass in legacy IKEv1, used by Qilin affiliateA logic flaw in IKEv1 certificate validation lets an unauthenticated attacker open a Remote Access VPN session without a valid password (CVSS 9.3). Exploited since May 7, 2026 against a few dozen organizations, including a Qilin ransomware affiliate case.CVE-2026-0300Palo Alto NetworksRoot RCE in the User-ID Authentication Portal, exploited as a zero-dayAn unauthenticated buffer overflow in the Authentication Portal (Captive Portal) gives root on PA-Series and VM-Series firewalls. A likely state-sponsored group exploited it for about four weeks before disclosure.CVE-2026-40050CrowdStrikeUnauthenticated file read in self-hosted LogScale clustersA cluster API endpoint in self-hosted LogScale lets anyone who can reach it read files from the server without logging in (CVSS 9.8). SaaS and Next-Gen SIEM are already protected; self-hosted clusters need an upgrade.CVE-2026-24858FortinetAny FortiCloud account could log in to other customers' devicesWith FortiCloud SSO login enabled, an attacker with their own FortiCloud account could log in as admin to devices belonging to other customers. Exploited on fully patched FortiGates in January 2026 to create admin accounts and steal configurations.CVE-2025-25249FortinetFortiGate heap overflow over CAPWAP, exploited months after a quiet fixA heap overflow in FortiOS's CAPWAP daemon (cw_acd) gives unauthenticated code execution on interfaces with Fabric access enabled. Fixed in 2025, disclosed in January 2026, exploited from July 2026 with 178 confirmed infections.

Vendors we cover

All vendors

Get alerts

A notification when we publish a new analysis or a covered vendor gets a new actively exploited CVE. No account, no email.