Fortinet Releases FortiMail Updates to Patch Zero-Day CVE-2026-104286
Fortinet has started distributing updates for its FortiMail email security product to remediate the zero-day vulnerability tracked as CVE-2026-104286.
The flaw permits an attacker to write arbitrary files to the system by sending a specially crafted HTTP request without requiring authentication. Fortinet confirmed that the vulnerability was already being exploited in the wild at the time the advisory was first published.
On October 1, 2026, the vendor released security advisory FG-IR-26-175 and began sharing Indicators of Compromise (IoC) data while preparing patches. The advisory also included recommended workarounds for organizations that could not immediately apply updates.
Five days later, on October 5, 2026, Fortinet updated the advisory and made the fixed releases available: FortiMail 8.0.2, 7.6.7, and 7.4.9. Customers are urged to install the updates as soon as possible.
The 7.2 branch remains affected. Fortinet recommends that organizations still using this branch migrate to the 7.4 branch or newer to obtain the necessary protection.
Related articles
New Spectre-v2 Variant Uses JIT Compiler Branch Target Reuse for Cross-Process Data Extraction
Researchers from the Netherlands and Italy have published a paper detailing a fresh Spectre-v2 attack that reuses branch predictor state instead of injecting new instructions. The technique leverages the JIT compiler cBPF inside the Linux kernel to train the branch target predictor, enabling speculative execution that leaks sensitive data such as hashed root passwords. Practical demonstrations extracted credentials from the su process in an average of three to five minutes on AMD, Intel, and ARM processors. Partial success was shown with SpiderMonkey in Firefox and GraalVM, although realistic end-to-end attacks were not achieved with those engines. The work also covers additional topics including forensic detection of attacks against 1C servers, a record Debian Linux kernel patch set, zero-day fixes in TeamViewer and Apple Core Graphics, and critical flaws in Dell Container Storage Modules.
Critical CVE-2026-21589 Affects Eight Atlassian Products with CVSS 9.3 Score
Atlassian has disclosed a critical vulnerability tracked as CVE-2026-21589 that impacts eight of its products. The flaw allows unauthenticated access to specific files located in the web application's root directory when an attacker already knows the file name and path. Products affected include Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Atlassian rates the issue Critical with a CVSSv4.0 base score of 9.3 and warns that Data Center editions face elevated risk due to potential exposure of sensitive files. The company released patches for all affected products and urges immediate updates, while also providing mitigation steps and indicators of compromise for organizations unable to patch right away.
Critical CVE-2026-61500 in Rejetto HFS Allows Admin Session Forgery Leading to Remote Code Execution
A critical vulnerability tracked as CVE-2026-61500 is being actively exploited in Rejetto HTTP File Server (HFS), enabling unauthenticated attackers to forge administrator sessions and achieve remote code execution. The flaw impacts versions 3.0.0 through 3.2.0 and was addressed in release 3.2.1, making immediate updates essential for any internet-exposed instances. The root cause lies in the use of JavaScript Math.random() to generate the session cookie signing key instead of a cryptographically secure random number generator. Attackers can reconstruct the internal state of this weak PRNG from login responses, allowing them to create valid admin cookies. Once authenticated as an administrator, the attacker can abuse the server_code functionality to execute arbitrary JavaScript on the server. Exploitation activity was first observed on October 1, 2026, targeting U.S. systems and attributed to an unidentified actor based in China, following the public release of a Python proof-of-concept in late September.
Dell Patches Six Critical Flaws in Container Storage Modules for Kubernetes
Dell has fixed six vulnerabilities in its Container Storage Modules that integrate storage systems with Kubernetes clusters. Two of the issues received the maximum CVSS score of 10.0, allowing remote unauthenticated attackers to obtain full administrative credentials for registered storage backends. Additional flaws enable privilege escalation to root on cluster nodes, exposure of hardcoded credentials, and leakage of Kubernetes secrets across the entire cluster. All versions prior to 1.17.0 are affected, with the fixes delivered in version 1.18.0. No workarounds exist, and Dell recommends rotating JWT signing keys after applying the update because the previous keys must be considered compromised.