Published: 10/02/26
Friday opens on an email-security clock. Fortinet confirmed active exploitation of a FortiMail management-interface file-write bug, and CISA’s federal due date is Saturday. Also on the desk: a critical Fortra BoKS autoregistration overflow, a vm2 sandbox escape with a public PoC on Node 24+, and a Foreman safemode bypass that lets low-priv template editors root Satellite. (Cisco’s Catalyst SD-WAN Manager KEV due Saturday remains on yesterday’s patch list — do not drop it.)
Lead Story
Your FortiMail management plane has a Saturday deadline
CVE-2026-104286 lets an unauthenticated attacker write arbitrary files through the FortiMail management GUI. Actively exploited. Fixed builds for several trains are still upcoming — pull management off the internet or disable IBE today, hunt Fortinet’s IoCs, and schedule 7.4.9 / 7.6.7 / 8.0.2 the moment they ship.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Why it matters: Secure-mail appliances with exposed management are a foothold into the mail stack, not just a GUI.
Also Worth Your Attention
Fortra BoKS autoregistration has a critical overflow
CVE-2026-12627 is a remote stack buffer overflow in boks_autoregisterd. Move to 8.1.0.24 / 9.0.0.7 and lock down (or disable) port 6507.
Why it matters: PAM control planes are the keys to elevated access — keep autoregistration off flat networks.
vm2 on Node 24+ needs 3.11.7 today
CVE-2026-92948 is a sandbox escape via a double-prefixed node:test import. PoC is public. Bump to 3.11.7 and plan stronger isolation.
Why it matters: Untrusted JS runners that still trust vm2 are one payload from host RCE.
Foreman template editors can root Satellite
CVE-2026-96658 bypasses safemode so a low-priv authenticated user can run commands on the host. Apply RHSA-2026:74503 and shrink template roles.
Why it matters: Provisioning hosts that build your estate should not be rootable from a template form.
Slack paste: Friday brief — FortiMail CVE-2026-104286 actively exploited (workaround + hunt; KEV due Sat Oct 4); BoKS 8.1.0.24/9.0.0.7; vm2 ≥3.11.7; Satellite RHSA-2026:74503. Also finish yesterday’s SD-WAN Manager upgrades due Sat Oct 3.
Go Deeper
Identity & Access Management → · Cybersecurity Tools →
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.