What's new
Latest updates
New analyses, newly exploited CVEs and the latest vendor advisories, newest first.
New analyses
- FortiMail zero-day lets attackers write files without logging in
A path traversal in FortiMail's Identity-Based Encryption (IBE) web service lets unauthenticated attackers write arbitrary files (CVSS 9.8). Exploited before disclosure; attackers set up mail archiving to their own server.
- Management server zero-day allows unauthenticated script execution
A pre-authentication path traversal in the Check Point management web service lets attackers run scripts on the management server (CVSS 9.8). Check Point saw targeted exploitation from July 23, 2026, and CISA added it to KEV.
- Falcon sensor for Windows local privilege escalation
A race condition in Falcon's Office macro removal feature lets a local low-privileged user write files to protected locations and reach SYSTEM. A public proof of concept (FalconFlank) exists; CrowdStrike sees no exploitation in the wild.
- Gateway VPN certificate flaw allows unauthenticated code execution
Improper certificate validation during VPN negotiation lets an unauthenticated attacker run code on Check Point gateways (CVSS 9.8). Check Point saw exploitation from September 12, 2026, and CISA added it to KEV.
- Check Point VPN login bypass in legacy IKEv1, used by Qilin affiliate
A logic flaw in IKEv1 certificate validation lets an unauthenticated attacker open a Remote Access VPN session without a valid password (CVSS 9.3). Exploited since May 7, 2026 against a few dozen organizations, including a Qilin ransomware affiliate case.
- Root RCE in the User-ID Authentication Portal, exploited as a zero-day
An unauthenticated buffer overflow in the Authentication Portal (Captive Portal) gives root on PA-Series and VM-Series firewalls. A likely state-sponsored group exploited it for about four weeks before disclosure.
- Unauthenticated file read in self-hosted LogScale clusters
A cluster API endpoint in self-hosted LogScale lets anyone who can reach it read files from the server without logging in (CVSS 9.8). SaaS and Next-Gen SIEM are already protected; self-hosted clusters need an upgrade.
- Any FortiCloud account could log in to other customers' devices
With FortiCloud SSO login enabled, an attacker with their own FortiCloud account could log in as admin to devices belonging to other customers. Exploited on fully patched FortiGates in January 2026 to create admin accounts and steal configurations.
- FortiGate heap overflow over CAPWAP, exploited months after a quiet fix
A heap overflow in FortiOS's CAPWAP daemon (cw_acd) gives unauthenticated code execution on interfaces with Fabric access enabled. Fixed in 2025, disclosed in January 2026, exploited from July 2026 with 178 confirmed infections.
- FortiWeb authentication bypass that creates admin accounts
A path traversal plus a trusted request header lets an unauthenticated attacker act as any FortiWeb user, including admin. Exploited since at least early October 2025, with a public proof of concept, and fixed from 8.0.2.
- Management interface authentication bypass, chained for root access
A path confusion between Nginx and Apache lets anyone who can reach the PAN-OS management interface skip login. Exploited within a day of disclosure, and chained with CVE-2024-9474 to get root.
- One header skips the login on the PAN-OS management interface
Sending X-PAN-AUTHCHECK set to off gave attackers admin access to exposed management interfaces. Chained with CVE-2024-9474 for root, it compromised about 2,000 firewalls within days of disclosure.
- Admin-to-root command injection, the second half of the 2024 firewall chain
A PAN-OS administrator can run commands as root through the management interface. Alone it needs admin rights; chained with CVE-2024-0012 or CVE-2025-0108, it gave attackers root on exposed firewalls.
- GlobalProtect zero-day gives root with a crafted session cookie
An unauthenticated command injection in GlobalProtect gave root on PAN-OS firewalls (CVSS 10). A likely state-backed group exploited it for weeks before disclosure, then mass exploitation followed the public exploit.
- GlobalProtect authentication bypass via forged override cookies
Attackers forge GlobalProtect authentication override cookies and open VPN sessions without credentials. Exploited since May 17, 2026, and used by Qilin ransomware affiliates for initial access.
Newly exploited
Added to CISA's Known Exploited Vulnerabilities catalog in the last six months.
| Added to KEV | CVE | Vendor / product | Issue |
|---|---|---|---|
| 1 Oct 2026 | CVE-2026-104286 | Fortinet · FortiMail | FortiMail Path Traversal |
| 22 Sept 2026 | CVE-2026-93616 | Check Point · Security Management and SmartConsole | Directory Traversal and File upload allows execution of arbitrary script on the Management Server |
| 22 Sept 2026 | CVE-2026-85102 | Check Point · Quantum Security Gateway | Improper Certificate Validation in Quantum Security Gateway |
| 9 Sept 2026 | CVE-2025-25249 | Fortinet · FortiOS | Heap-based buffer overflow in FortiOS, FortiSwitchManager |
| 27 Jul 2026 | CVE-2025-68686 | Fortinet · FortiOS | FortiOS Exposure of Sensitive Information to an Unauthorized Actor |
| 22 Jul 2026 | CVE-2026-16232 | Check Point · Security Management and SmartConsole | Authentication Bypass in the SmartConsole Login Process Using an Application Token |
| 16 Jul 2026 | CVE-2026-25089 | Fortinet · FortiSandbox | FortiSandbox OS Command Injection |
| 16 Jul 2026 | CVE-2026-39808 | Fortinet · FortiSandbox | FortiSandbox OS Command Injection |
| 8 Jun 2026 | CVE-2026-50751 | Check Point · Quantum Security Gateway | User Authentication Bypass in VPN Remote Access and Mobile AccessRansomware |
| 29 May 2026 | CVE-2026-0257 | Palo Alto Networks · PAN-OS | GlobalProtect Authentication Bypass VulnerabilitiesRansomware |
| 6 May 2026 | CVE-2026-0300 | Palo Alto Networks · PAN-OS | Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal |
| 13 Apr 2026 | CVE-2026-21643 | Fortinet · FortiClient and EMS | FortiClient EMS SQL Injection |
Latest vendor advisories
| Published | CVE | Vendor / product | Issue | Severity | EPSS |
|---|---|---|---|---|---|
| 1 Oct 2026 | CVE-2026-104286 | Fortinet · FortiMail | FortiMail Path Traversal | CRITICAL | 2.2% |
| 22 Sept 2026 | CVE-2026-84388 | Fortinet · Other security products | Improper restriction of rendered ui layers or frames in FortiPAM Chrome Extension | CRITICAL | 0.38% |
| 22 Sept 2026 | CVE-2026-93616 | Check Point · Security Management and SmartConsole | Directory Traversal and File upload allows execution of arbitrary script on the Management Server | CRITICAL | 20% |
| 16 Sept 2026 | CVE-2026-91843 | Check Point · Security Management and SmartConsole | Stack overflow in login process to the Security Management and Log Servers | CRITICAL | 0.52% |
| 15 Sept 2026 | CVE-2026-40058 | CrowdStrike · Falcon sensor | Vulnerability Affecting Office Macro Removal in CrowdStrike Falcon Sensor for Windows | HIGH | 0.08% |
| 11 Sept 2026 | CVE-2026-15710 | Netskope · Netskope Client and Endpoint DLP | Netskope Client Endpoint DLP Kernel Driver Information Leakage | MEDIUM | 0.10% |
| 10 Sept 2026 | CVE-2026-16174 | Netskope · Netskope Client and Endpoint DLP | Netskope Endpoint DLP Driver Integer Overflow Leading to Kernel Pool Overflow | HIGH | 0.13% |
| 10 Sept 2026 | CVE-2026-16172 | Netskope · Netskope Client and Endpoint DLP | Netskope Endpoint DLP Service Out-of-Bounds Read Leading to Process Crash | MEDIUM | 0.11% |
| 9 Sept 2026 | CVE-2026-0310 | Palo Alto Networks · PAN-OS | Buffer Overflow Vulnerability via XML Processing | HIGH | 0.37% |
| 9 Sept 2026 | CVE-2026-0309 | Palo Alto Networks · PAN-OS | Authenticated Command Injection in CLI with Luna HSM Configuration | MEDIUM | 0.45% |
| 9 Sept 2026 | CVE-2026-0308 | Palo Alto Networks · PAN-OS | Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface | LOW | 0.27% |
| 9 Sept 2026 | CVE-2026-0307 | Palo Alto Networks · GlobalProtect App | Local Privilege Escalation Vulnerabilities | MEDIUM | 0.10% |
| 9 Sept 2026 | CVE-2026-0306 | Palo Alto Networks · Prisma Access | EndPoint DLP Bypass Vulnerability on Windows | MEDIUM | 0.10% |
| 9 Sept 2026 | CVE-2026-0305 | Palo Alto Networks · Prisma Access | Information Disclosure Vulnerability on Linux | MEDIUM | 0.10% |
| 9 Sept 2026 | CVE-2026-0304 | Palo Alto Networks · Cortex XDR | Privilege Escalation Vulnerability | MEDIUM | 0.22% |