<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>PatchTonight</title><description>Practical analysis of exploited vulnerabilities in security products: firewalls, VPNs, proxies, mail gateways, EDR and SSE.</description><link>https://patchtonight.com/</link><language>en</language><item><title>CVE-2024-0012: One header skips the login on the PAN-OS management interface</title><link>https://patchtonight.com/cve/CVE-2024-0012/</link><guid isPermaLink="true">https://patchtonight.com/cve/CVE-2024-0012/</guid><description>Sending X-PAN-AUTHCHECK set to off gave attackers admin access to exposed management interfaces. Chained with CVE-2024-9474 for root, it compromised about 2,000 firewalls within days of disclosure.</description><pubDate>Sat, 10 Oct 2026 00:00:00 GMT</pubDate><category>Palo Alto Networks</category><category>PAN-OS management web interface</category></item><item><title>CVE-2024-3400: GlobalProtect zero-day gives root with a crafted session cookie</title><link>https://patchtonight.com/cve/CVE-2024-3400/</link><guid isPermaLink="true">https://patchtonight.com/cve/CVE-2024-3400/</guid><description>An unauthenticated command injection in GlobalProtect gave root on PAN-OS firewalls (CVSS 10). A likely state-backed group exploited it for weeks before disclosure, then mass exploitation followed the public exploit.</description><pubDate>Sat, 10 Oct 2026 00:00:00 GMT</pubDate><category>Palo Alto Networks</category><category>PAN-OS GlobalProtect portal and gateway</category></item><item><title>CVE-2024-9474: Admin-to-root command injection, the second half of the 2024 firewall chain</title><link>https://patchtonight.com/cve/CVE-2024-9474/</link><guid isPermaLink="true">https://patchtonight.com/cve/CVE-2024-9474/</guid><description>A PAN-OS administrator can run commands as root through the management interface. Alone it needs admin rights; chained with CVE-2024-0012 or CVE-2025-0108, it gave attackers root on exposed firewalls.</description><pubDate>Sat, 10 Oct 2026 00:00:00 GMT</pubDate><category>Palo Alto Networks</category><category>PAN-OS management web interface</category></item><item><title>CVE-2025-0108: Management interface authentication bypass, chained for root access</title><link>https://patchtonight.com/cve/CVE-2025-0108/</link><guid isPermaLink="true">https://patchtonight.com/cve/CVE-2025-0108/</guid><description>A path confusion between Nginx and Apache lets anyone who can reach the PAN-OS management interface skip login. Exploited within a day of disclosure, and chained with CVE-2024-9474 to get root.</description><pubDate>Sat, 10 Oct 2026 00:00:00 GMT</pubDate><category>Palo Alto Networks</category><category>PAN-OS management web interface</category></item><item><title>CVE-2025-25249: FortiGate heap overflow over CAPWAP, exploited months after a quiet fix</title><link>https://patchtonight.com/cve/CVE-2025-25249/</link><guid isPermaLink="true">https://patchtonight.com/cve/CVE-2025-25249/</guid><description>A heap overflow in FortiOS&apos;s CAPWAP daemon (cw_acd) gives unauthenticated code execution on interfaces with Fabric access enabled. Fixed in 2025, disclosed in January 2026, exploited from July 2026 with 178 confirmed infections.</description><pubDate>Sat, 10 Oct 2026 00:00:00 GMT</pubDate><category>Fortinet</category><category>FortiOS Security Fabric (CAPWAP)</category></item><item><title>CVE-2025-64446: FortiWeb authentication bypass that creates admin accounts</title><link>https://patchtonight.com/cve/CVE-2025-64446/</link><guid isPermaLink="true">https://patchtonight.com/cve/CVE-2025-64446/</guid><description>A path traversal plus a trusted request header lets an unauthenticated attacker act as any FortiWeb user, including admin. Exploited since at least early October 2025, with a public proof of concept, and fixed from 8.0.2.</description><pubDate>Sat, 10 Oct 2026 00:00:00 GMT</pubDate><category>Fortinet</category><category>FortiWeb management GUI</category></item><item><title>CVE-2026-0300: Root RCE in the User-ID Authentication Portal, exploited as a zero-day</title><link>https://patchtonight.com/cve/CVE-2026-0300/</link><guid isPermaLink="true">https://patchtonight.com/cve/CVE-2026-0300/</guid><description>An unauthenticated buffer overflow in the Authentication Portal (Captive Portal) gives root on PA-Series and VM-Series firewalls. A likely state-sponsored group exploited it for about four weeks before disclosure.</description><pubDate>Sat, 10 Oct 2026 00:00:00 GMT</pubDate><category>Palo Alto Networks</category><category>PAN-OS User-ID Authentication Portal</category></item><item><title>CVE-2026-104286: FortiMail zero-day lets attackers write files without logging in</title><link>https://patchtonight.com/cve/CVE-2026-104286/</link><guid isPermaLink="true">https://patchtonight.com/cve/CVE-2026-104286/</guid><description>A path traversal in FortiMail&apos;s Identity-Based Encryption (IBE) web service lets unauthenticated attackers write arbitrary files (CVSS 9.8). Exploited before disclosure; attackers set up mail archiving to their own server.</description><pubDate>Sat, 10 Oct 2026 00:00:00 GMT</pubDate><category>Fortinet</category><category>FortiMail</category></item><item><title>CVE-2026-24858: Any FortiCloud account could log in to other customers&apos; devices</title><link>https://patchtonight.com/cve/CVE-2026-24858/</link><guid isPermaLink="true">https://patchtonight.com/cve/CVE-2026-24858/</guid><description>With FortiCloud SSO login enabled, an attacker with their own FortiCloud account could log in as admin to devices belonging to other customers. Exploited on fully patched FortiGates in January 2026 to create admin accounts and steal configurations.</description><pubDate>Sat, 10 Oct 2026 00:00:00 GMT</pubDate><category>Fortinet</category><category>FortiCloud SSO (FortiOS, FortiManager, FortiAnalyzer, FortiProxy)</category></item><item><title>CVE-2026-40050: Unauthenticated file read in self-hosted LogScale clusters</title><link>https://patchtonight.com/cve/CVE-2026-40050/</link><guid isPermaLink="true">https://patchtonight.com/cve/CVE-2026-40050/</guid><description>A cluster API endpoint in self-hosted LogScale lets anyone who can reach it read files from the server without logging in (CVSS 9.8). SaaS and Next-Gen SIEM are already protected; self-hosted clusters need an upgrade.</description><pubDate>Sat, 10 Oct 2026 00:00:00 GMT</pubDate><category>CrowdStrike</category><category>LogScale Self-Hosted</category></item><item><title>CVE-2026-40058: Falcon sensor for Windows local privilege escalation</title><link>https://patchtonight.com/cve/CVE-2026-40058/</link><guid isPermaLink="true">https://patchtonight.com/cve/CVE-2026-40058/</guid><description>A race condition in Falcon&apos;s Office macro removal feature lets a local low-privileged user write files to protected locations and reach SYSTEM. A public proof of concept (FalconFlank) exists; CrowdStrike sees no exploitation in the wild.</description><pubDate>Sat, 10 Oct 2026 00:00:00 GMT</pubDate><category>CrowdStrike</category><category>Falcon sensor for Windows (Office macro removal)</category></item><item><title>CVE-2026-50751: Check Point VPN login bypass in legacy IKEv1, used by Qilin affiliate</title><link>https://patchtonight.com/cve/CVE-2026-50751/</link><guid isPermaLink="true">https://patchtonight.com/cve/CVE-2026-50751/</guid><description>A logic flaw in IKEv1 certificate validation lets an unauthenticated attacker open a Remote Access VPN session without a valid password (CVSS 9.3). Exploited since May 7, 2026 against a few dozen organizations, including a Qilin ransomware affiliate case.</description><pubDate>Sat, 10 Oct 2026 00:00:00 GMT</pubDate><category>Check Point</category><category>Check Point Remote Access VPN and Mobile Access (IKEv1)</category></item><item><title>CVE-2026-85102: Gateway VPN certificate flaw allows unauthenticated code execution</title><link>https://patchtonight.com/cve/CVE-2026-85102/</link><guid isPermaLink="true">https://patchtonight.com/cve/CVE-2026-85102/</guid><description>Improper certificate validation during VPN negotiation lets an unauthenticated attacker run code on Check Point gateways (CVSS 9.8). Check Point saw exploitation from September 12, 2026, and CISA added it to KEV.</description><pubDate>Sat, 10 Oct 2026 00:00:00 GMT</pubDate><category>Check Point</category><category>Quantum Security Gateway VPN</category></item><item><title>CVE-2026-93616: Management server zero-day allows unauthenticated script execution</title><link>https://patchtonight.com/cve/CVE-2026-93616/</link><guid isPermaLink="true">https://patchtonight.com/cve/CVE-2026-93616/</guid><description>A pre-authentication path traversal in the Check Point management web service lets attackers run scripts on the management server (CVSS 9.8). Check Point saw targeted exploitation from July 23, 2026, and CISA added it to KEV.</description><pubDate>Sat, 10 Oct 2026 00:00:00 GMT</pubDate><category>Check Point</category><category>Quantum Security Management</category></item><item><title>CVE-2026-0257: GlobalProtect authentication bypass via forged override cookies</title><link>https://patchtonight.com/cve/CVE-2026-0257/</link><guid isPermaLink="true">https://patchtonight.com/cve/CVE-2026-0257/</guid><description>Attackers forge GlobalProtect authentication override cookies and open VPN sessions without credentials. Exploited since May 17, 2026, and used by Qilin ransomware affiliates for initial access.</description><pubDate>Fri, 09 Oct 2026 00:00:00 GMT</pubDate><category>Palo Alto Networks</category><category>PAN-OS GlobalProtect portal and gateway</category></item></channel></rss>