What you need to know today.
Fortinet, Zammad, and Ivanti vulnerabilities are actively exploited and added to CISA KEV; critical flaws in Cisco, NetScaler, and other platforms disclosed.

The CISA has added a critical Fortinet FortiMail vulnerability (CVE-2026-104286) to its Known Exploited Vulnerabilities catalog, citing active exploitation. This path traversal flaw allows unauthenticated attackers to write arbitrary files, potentially leading to remote code execution. The vulnerability affects multiple versions of FortiMail, including 8.0.0 through 8.0.1, 7.6.0 through 7.6.6, 7.4.0 through 7.4.8, and 7.2.0 through 7.2.9. Fortinet has released patches for affected versions, and users are strongly urged to update immediately to mitigate the risk of compromise. This critical flaw underscores the ongoing threat posed by unpatched vulnerabilities in network security appliances.
Two zero-day vulnerabilities in Zammad, a customer service platform, have been actively exploited, leading to their inclusion on the CISA KEV list. CVE-2026-102489, a session hijack vulnerability, allows for remote code execution as the Zammad user. While versions 7.0.0 to 7.1.2 are also affected, the bug is not exploitable due to underlying changes. The exploitation of these flaws was notably demonstrated in an AI-powered attack against the Dutch Institute for Vulnerability Disclosure (DIVD). Patches are available for affected versions, and immediate updates are recommended.
A critical OS command injection vulnerability (CVE-2026-10520) in Ivanti Sentry has been added to the CISA KEV list due to active exploitation. This flaw allows remote, unauthenticated attackers to achieve root-level remote code execution on affected versions prior to R10.5.2, R10.6.2, and R10.7.1. The vulnerability was reportedly used in an attack campaign involving the PoeLLM cryptomining botnet, which hid its command-and-control addresses within a GitHub poem. Ivanti has released patches, and users should update their systems promptly.
Critical vulnerabilities affecting Cisco Identity Services Engine (ISE) and NetScaler ADC/Gateway have been highlighted. CVE-2026-76460, an API authentication bypass in Cisco ISE, allows unauthenticated remote attackers to gain unauthorized access. Meanwhile, multiple versions of NetScaler ADC and Gateway are affected by vulnerabilities, including CVE-2026-19490, a critical flaw that could lead to remote code execution, and CVE-2025-5777, a high-severity memory over-read issue. Cisco and Citrix have released advisories and patches for these products, urging users to apply them to prevent exploitation.
Several other critical vulnerabilities have been disclosed across various platforms. A pre-authentication remote code execution flaw (CVE-2025-55182) impacts React Server Components. Langflow AI versions prior to 1.3.0 are susceptible to code injection (CVE-2025-3248) via the /api/v1/validate/code endpoint. Zyxel NAS devices (CVE-2020-9054) and Joomla extensions (CVE-2026-48908, CVE-2026-56290) also have critical vulnerabilities allowing for remote code execution through command injection and arbitrary file uploads, respectively. Metabase (CVE-2021-41277) has a local file inclusion vulnerability. Users of these products should consult vendor advisories for patching information.