VYPR
AI Brief2026-10-03· generated Oct 3, 2026

What you need to know today.

Actively Exploited Critical Flaws in Fortinet, Progress, Ivanti, and Microsoft Lead Today's CVE Briefing.

A critical path traversal vulnerability in Fortinet FortiMail (CVE-2026-104286) is actively being exploited in the wild and has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. This flaw allows unauthenticated attackers to write arbitrary files on affected systems, potentially leading to further compromise. Fortinet has released patches for various versions of FortiMail, including 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9. Security teams should prioritize patching or mitigating this vulnerability immediately due to its active exploitation. The Register reported, Help Net Security noted, and SecurityWeek highlighted.

Progress Software's Kemp LoadMaster appliance is facing scrutiny due to a critical OS command injection vulnerability (CVE-2026-8037) that allows unauthenticated attackers to execute arbitrary commands. This flaw has been added to the CISA KEV catalog, with reports indicating hundreds of exploit attempts. The vulnerability stems from unsanitized input in multiple command endpoints within the API. Progress has released advisories and patches for affected products, and organizations using Kemp LoadMaster should apply these updates urgently. The Hacker News extensively covered the addition to the KEV catalog and the active exploitation.

A critical authentication bypass vulnerability in Ivanti Connect Secure (CVE-2023-46805) is being actively exploited, leading to its inclusion in the CISA KEV catalog. This flaw allows remote attackers to access restricted resources by bypassing control checks in the web component of Ivanti ICS and Policy Secure. Ivanti has released security advisories and patches for affected versions, urging customers to update immediately. This vulnerability has been linked to broader attacks targeting LATAM infrastructure, as reported by Infosecurity Magazine.

Microsoft's SMBv3 protocol is affected by a critical remote code execution vulnerability (CVE-2020-0796) that has been added to the CISA KEV catalog. This flaw allows attackers to execute arbitrary code on vulnerable Windows systems by sending specially crafted requests. While the vulnerability is old, its presence in the KEV catalog underscores the persistent threat of legacy vulnerabilities being actively exploited. Microsoft has previously released patches for this vulnerability, and systems should be updated accordingly.

Oracle WebLogic Server is impacted by a critical vulnerability (CVE-2019-2725) that allows unauthenticated attackers to achieve remote code execution. This flaw, present in versions 10.3.6.0.0 and 12.1.3.0.0, has been added to the CISA KEV catalog due to active exploitation. Oracle has released patches, and users are strongly advised to apply them to protect their environments.

A critical vulnerability in Drupal core (CVE-2018-7602) allows for remote code execution across multiple subsystems in Drupal 7.x and 8.x. This long-standing vulnerability has been added to the CISA KEV catalog, indicating it is being actively exploited. Attackers can exploit this flaw to compromise Drupal sites. Patches are available, and administrators should ensure their Drupal installations are up to date. Tenable's blog provided analysis on a related Drupal vulnerability.

VMware's Zimbra Collaboration (ZCS) has a vulnerability (CVE-2022-27925) that allows authenticated administrators to upload arbitrary files, potentially leading to system compromise. This vulnerability has been linked to sophisticated attack campaigns, including those using AI for post-compromise operations, as detailed by Cisco Talos and Securelist. While not yet on the KEV catalog, its exploitation in advanced attacks warrants immediate attention and patching.

A critical vulnerability in Samsung MagicINFO 9 Server (CVE-2024-7399) allows attackers to write arbitrary files with system authority. This flaw has been exploited in the wild, with attackers using it to deploy cryptominers within victim systems, as reported by Cyber Security News. Patches are available from Samsung, and users should apply them to prevent unauthorized file modifications.

Adobe Flash Player, a long-deprecated technology, still poses a risk with vulnerabilities like CVE-2016-1019 and CVE-2018-15982. These flaws, including denial-of-service and use-after-free vulnerabilities, could lead to arbitrary code execution. While Flash Player is end-of-life, legacy systems may still run it, making them susceptible to exploitation. Organizations should ensure Flash Player is removed or disabled wherever possible.

Microsoft Exchange Server is affected by a remote code execution vulnerability (CVE-2021-27065) that has been added to the CISA KEV catalog. This critical flaw allows attackers to execute arbitrary code on vulnerable Exchange servers, posing a significant risk to organizations relying on this platform. Microsoft has released patches, and prompt application is crucial. Tenable's blog mentioned this CVE in the context of vulnerability prioritization.

Ivanti Policy Secure and Ivanti Connect Secure are affected by a stack-based buffer overflow vulnerability (CVE-2025-0282) that allows remote, unauthenticated attackers to achieve remote code execution. This critical flaw has been added to the CISA KEV catalog, highlighting its active exploitation. Ivanti has released patches for affected versions, and users should prioritize updating their systems.

Gigabyte's GDrv low-level driver (CVE-2018-19323) presents a critical vulnerability that allows attackers to read and write Machine Specific Registers (MSRs). This could lead to system compromise or privilege escalation. While this vulnerability is older, its presence in critical systems warrants attention. Users of Gigabyte APP Center, AORUS GRAPHICS ENGINE, XTREME GAMING ENGINE, and OC GURU II should check for and apply available updates.

Zyxel's EMG2926 home router is vulnerable to command injection (CVE-2017-6884) through its diagnostic tools, specifically the nslookup function. This vulnerability allows malicious users to execute arbitrary commands on the router. While this is an older vulnerability, it highlights the ongoing risks associated with insecure IoT devices. Users should ensure their router firmware is up to date.

Oracle Fusion Middleware is affected by multiple vulnerabilities, including CVE-2012-1710 in the WebCenter Forms Recognition component, which could impact confidentiality, integrity, and availability. Additionally, CVE-2019-2725 in WebLogic Server allows for unauthenticated remote code execution. Both have been added to the CISA KEV catalog, emphasizing the need for immediate patching of Oracle Fusion Middleware deployments.

QNAP devices are vulnerable to command injection (CVE-2018-19949) that could allow remote attackers to run arbitrary commands. QNAP has released patches for affected QTS versions, and users should update their devices to prevent exploitation.

Adobe ColdFusion versions 9.0.1 and earlier are susceptible to multiple directory traversal vulnerabilities (CVE-2010-2861) that allow attackers to read arbitrary files. This critical vulnerability has been added to the CISA KEV catalog. Adobe has released patches, and users should update their ColdFusion installations.

RARLAB's UnRAR utility (CVE-2022-30333) has a directory traversal vulnerability that allows attackers to write to arbitrary files during extraction, including sensitive files like ~/.ssh/authorized_keys. This vulnerability affects UnRAR versions prior to 6.12 on Linux and UNIX. Users should update to UnRAR 6.12 or later to mitigate this risk.

Microsoft Internet Explorer is affected by a memory corruption vulnerability (CVE-2021-26411) that has been added to the CISA KEV catalog. This critical flaw allows for remote code execution. Given that Internet Explorer is end-of-life, organizations should prioritize migrating away from it entirely.

Synthesized by Vypr AI
Critical Flaws in Fortinet, Progress, Ivanti, Microsoft Exploited · VYPR