Follow the latest coverage, related explainers and connected technology stories.
Fortinet warns of a critical vulnerability in the FortiMail management interface that is actively being exploited as a zero-day attack and could allow an unauthenticated attacker to write files and execute commands on affected devices. The company has issued temporary workarounds and indicators of compromise, while CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog.
Check Point confirmed that two vulnerabilities in Security Gateway are being actively exploited, one enabling remote command execution before authentication, while the other has been exploited as a zero-day since July 23, 2026. CISA added both vulnerabilities to its Known Exploited Vulnerabilities catalog, giving U.S. federal agencies until September 25 to apply fixes or mitigation measures.