Fortinet FortiMail path traversal exploited (CVE-2026-104286)
CISA says CVE-2026-104286, a critical FortiMail flaw allowing unauthenticated file writes, is exploited. See affected versions, due date and steps to take.
Security news for cloud platforms, applications and developer tooling, including supply chain and AppSec issues.
CISA says CVE-2026-104286, a critical FortiMail flaw allowing unauthenticated file writes, is exploited. See affected versions, due date and steps to take.
CISA says the Zammad flaw CVE-2026-102489 is exploited and can give code execution. Check your version, apply vendor fixes and review sessions by 5 October.
CISA says CVE-2026-102490 in Zammad, which lets the local zammad user become root, is exploited. Remediation is due 5 October 2026.
A recent discovery by Adversa has unveiled a high-severity Claude Code AI security bypass vulnerability in Anthropic’s Claude Code AI coding agent. This critical flaw allows malicious actors to silently circumvent user-configured deny rules using a simple command-padding technique, placing hundreds of thousands of developers at significant risk of credential theft and widespread supply chain…
GitLab has released urgent security updates (versions 18.10.3, 18.9.5, and 18.8.9) for its Community Edition (CE) and Enterprise Edition (EE). These critical GitLab security updates address high-severity flaws that could enable Denial-of-Service (DoS) and code-injection attacks. GitLab strongly advises all administrators of self-managed systems to upgrade immediately to protect their instances from these significant vulnerabilities….
End of content
End of content