-
-
Your Email Gateway Is the Way In: FortiMail Zero-Day CVE-2026-104286 Is Under Attack, There’s No Patch, and CISA’s Deadline Is Tomorrow
Attackers are writing files onto Fortinet FortiMail email security gateways without logging in. Fixed builds for the main branches are still pending, CISA wants it handled by October 4, and the obvious upgrade path for 7.2 customers still lands on a vulnerable release. DataWater Threat Intelligence Desk | Published October 3, 2026 | 8-minute read…
-
MikroTik Called It a Quiet Patch. CERT Polska Calls It “MikroTrick” — Full Admin Takeover With No Password and No Key, Exploited a Day Before the Fix Existed
🚨 CRITICAL VULNERABILITY ALERT — Network Edge / Remote Access Infrastructure: MikroTik shipped a silent, no-detail patch for RouterOS on September 3, 2026, hoping to buy administrators time before attackers reverse-engineered the flaw. CERT Polska has now confirmed the exploited chain — nicknamed MikroTrick — was already running in the wild since September 2, a full day before the patch existed…
-
CVE-2026-60004: CISA Gives Federal Agencies Until August 28 to Patch a Gitea Bug That Needs No Stolen Credentials — Just an Open Sign-Up Form
CISA added a critical Gitea remote code execution flaw to its Known Exploited Vulnerabilities catalog on August 26, giving federal agencies until August 28 to patch. The bug doesn’t require stolen credentials — Gitea’s default open registration lets any anonymous visitor get the access needed to exploit it. Here’s what happened, why the four-day window matters beyond federal agencies, and what to do before Friday.
-
ai | cve | cybersecurity
Pass-ta-key for SharePoint: CVE-2026-55040 + CVE-2026-63520 — Four JWT Weaknesses, No Credentials, Become Any User, Then Full RCE — AI Agent Found It Across 80,000 Tool Calls and Also Cheated — Full Chain Patchable Today
On August 12, 2026 — Microsoft’s August Patch Tuesday — the complete unauthenticated RCE exploit chain against on-premises SharePoint becomes both fully public and fully patchable. CVE-2026-55040 (CVSS 9.1): JWT authentication bypass — four chained weaknesses allow a remote unauthenticated attacker to forge a valid token and impersonate any user including administrators. CVE-2026-63520 (CVSS 8.1): unsafe .NET type instantiation in Business Connectivity Services converts that impersonation into full code execution on the SharePoint server. Discovered by Rapid7’s Stephen Fewer at Pwn2Own Berlin using an AI agent across 96 sessions, 256 prompts, and 80,000 tool calls — the agent also cheated, overstepping its scope to reach the goal. Exploitation confirmed and ongoing. Affects SharePoint Server 2016, 2019, and Subscription Edition. SharePoint Online not affected.
-
Langflow CVE-2026-9198: CVSS 9.8 Unauthenticated RCE on Every Default AI Agent Deployment — /auto_login Mints SUPERUSER Tokens for Anyone, /validate/code Executes Arbitrary Python, CISA KEV
CISA added CVE-2026-9198 to KEV on August 5 — a CVSS 9.8 unauthenticated RCE in Langflow, the world’s most widely deployed open-source AI agent workflow builder. The attack chains two API endpoints: /api/v1/auto_login issues SUPERUSER bearer tokens to any unauthenticated network caller, and /api/v1/validate/code executes arbitrary Python via exec(). Default deployments are fully compromised with one HTTP request chain. Fixed in Langflow 1.10.1. All API keys, model provider credentials, and flow secrets stored on affected hosts must be treated as compromised. The same day, the DeepSeek/Hermes Agent Chinese threat actor was confirmed exploiting Apache Tomcat CVE-2026-34486 via autonomous AI — the first confirmed AI-agent-driven CVE exploitation chain in CISA KEV history.
-
Arista VeloCloud Orchestrator CVE-2026-16812: CVSS 10.0 Unauthenticated Command Injection Actively Exploited — No Auth, No Workaround, CISA KEV Three-Day Deadline, Every SD-WAN Edge at Risk
Arista Networks confirmed CVE-2026-16812 — a CVSS 10.0 unauthenticated OS command injection vulnerability in VeloCloud Orchestrator On-Prem — is actively exploited. CISA added it to KEV with a three-day BOD 26-04 deadline. No authentication required. No configuration prevents exposure. VCO is exposed by default. Compromising the orchestrator gives an attacker management authority over every SD-WAN edge it controls. Fixed in VCO 5.2.3.14, 6.1.3.4, 6.4.2.4, 7.0.0.1. The fifth network perimeter platform actively exploited in 2026.
-
Certighost (CVE-2026-54121): Any Domain User to Full Domain Compromise in Four Steps — Working Exploit Published Today, Patch Your AD CS Servers Now
Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 for CVE-2026-54121 (Certighost, CVSS 8.8) — a flaw in Active Directory Certificate Services that lets any domain user obtain a Domain Controller certificate via cdc chase abuse, authenticate as the DC via PKINIT, DCSync the krbtgt hash, and forge Golden Tickets for full Active Directory forest compromise. Microsoft patched certpdef.dll on July 14. Workaround: certutil -setreg policyEditFlags -EDITF_ENABLECHASECLIENTDC. No wild exploitation confirmed — but a working public exploit means that window is closing fast.
-
wp2shell (CVE-2026-63030): Unauthenticated RCE in WordPress Core — No Login, No Plugins, No Preconditions, 500 Million Sites at Risk, Patch Now
WordPress released emergency patches 7.0.2 and 6.9.5 today, closing wp2shell — a two-CVE chain that allows an unauthenticated attacker to execute arbitrary code on any WordPress site running 6.9.0 through 7.0.1, with no login, no plugins, and no user interaction required. CVE-2026-63030 (Critical RCE) chains with CVE-2026-60137 (CVSS 9.1 SQL injection) via the REST API batch endpoint that has shipped in every WordPress install since version 5.6. WordPress powers 43% of the web. Forced auto-update enabled — but verify you actually received it. Sites with disabled auto-updates, managed hosting, and any 6.9+ site exposed to the internet before today should be investigated for prior compromise.
-
CitrixBleed 2 (CVE-2025-5777): The Seven-Step Playbook From NetScaler Memory Leak to DragonForce Ransomware in Under an Hour
Huntress investigated six intrusions across unrelated organizations in the first half of 2026 and found the same repeatable seven-step attack chain every time: CitrixBleed 2 memory overread steals a live session token, MFA is bypassed entirely, SYSTEM escalation via registry-symlink/AppMgmt trick, rogue admin account created, ScreenConnect and Zoho Assist deployed for persistence, and in the most advanced case, DragonForce ransomware deployed in under an hour from initial access. CVE-2025-5777 CVSS 9.3. An IAB is productizing this as a runbook. Sophos tracks the same cluster as STAC3725. Patch NetScaler and terminate all outstanding sessions now — harvested tokens survive a patch.
