Friday’s brief: FortiMail due Saturday, then BoKS, vm2, Satellite

By George Bailey   Published: 10/02/26   2 min read

Published: 10/02/26

Friday opens on an email-security clock. Fortinet confirmed active exploitation of a FortiMail management-interface file-write bug, and CISA’s federal due date is Saturday. Also on the desk: a critical Fortra BoKS autoregistration overflow, a vm2 sandbox escape with a public PoC on Node 24+, and a Foreman safemode bypass that lets low-priv template editors root Satellite. (Cisco’s Catalyst SD-WAN Manager KEV due Saturday remains on yesterday’s patch list — do not drop it.)

Lead Story

Your FortiMail management plane has a Saturday deadline

CVE-2026-104286 lets an unauthenticated attacker write arbitrary files through the FortiMail management GUI. Actively exploited. Fixed builds for several trains are still upcoming — pull management off the internet or disable IBE today, hunt Fortinet’s IoCs, and schedule 7.4.9 / 7.6.7 / 8.0.2 the moment they ship.

Why it matters: Secure-mail appliances with exposed management are a foothold into the mail stack, not just a GUI.

See the workaround list →

Also Worth Your Attention

Fortra BoKS autoregistration has a critical overflow

CVE-2026-12627 is a remote stack buffer overflow in boks_autoregisterd. Move to 8.1.0.24 / 9.0.0.7 and lock down (or disable) port 6507.

Why it matters: PAM control planes are the keys to elevated access — keep autoregistration off flat networks.

See the upgrade path →

vm2 on Node 24+ needs 3.11.7 today

CVE-2026-92948 is a sandbox escape via a double-prefixed node:test import. PoC is public. Bump to 3.11.7 and plan stronger isolation.

Why it matters: Untrusted JS runners that still trust vm2 are one payload from host RCE.

Check your lockfiles →

Foreman template editors can root Satellite

CVE-2026-96658 bypasses safemode so a low-priv authenticated user can run commands on the host. Apply RHSA-2026:74503 and shrink template roles.

Why it matters: Provisioning hosts that build your estate should not be rootable from a template form.

See the Satellite errata →

Slack paste: Friday brief — FortiMail CVE-2026-104286 actively exploited (workaround + hunt; KEV due Sat Oct 4); BoKS 8.1.0.24/9.0.0.7; vm2 ≥3.11.7; Satellite RHSA-2026:74503. Also finish yesterday’s SD-WAN Manager upgrades due Sat Oct 3.

Go Deeper

Identity & Access Management → · Cybersecurity Tools →

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.