Daily briefing: Friday, October 2, 2026

Fortinet warns that attackers are exploiting a critical zero-day vulnerability in its FortiMail email security gateway that allows unauthenticated arbitrary file writes. GitLab urged customers to patch a critical 9.9 CVSS vulnerability in its AI Gateway service that could let attackers execute arbitrary commands on self-hosted servers. Dell has released fixes for maximum severity vulnerabilities in its Container Storage Modules connecting enterprise storage arrays to Kubernetes environments.

Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes

Fortinet says attackers are exploiting a critical path traversal zero-day vulnerability in FortiMail that allows unauthenticated users to write arbitrary files via crafted HTTP requests. Successful exploitation of the flaw, tracked as CVE-2026-104286, could potentially lead to arbitrary code execution. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog after Fortinet reported the flaw was being actively exploited in the wild.

GitLab warns of critical RCE vulnerability in AI Gateway service

GitLab warned customers to immediately patch a critical AI Gateway vulnerability, tracked as CVE-2026-90970, which could allow attackers to run arbitrary commands. The 9.9 CVSS flaw could let logged-in Duo Agent Platform users execute commands on self-hosted gateways.

Dell asks admins to patch max severity CSM flaws as soon as possible

The vulnerabilities enable unauthenticated admin access, authentication bypass, and storage credential access, while potentially allowing root access on Kubernetes nodes. CISA added CVE-2026-22769, a CVSS 10.0 vulnerability involving hard-coded credentials in Dell RecoverPoint for Virtual Machines, to its Known Exploited Vulnerabilities catalog.

Multiple vulnerabilities in Moxa products

Multiple vulnerabilities discovered in the Moxa MGate 3000 Series could allow attackers to cause data confidentiality and integrity breaches. The flaws include CVE-2026-86325, with a critical CVSS score of 9.4, and CVE-2026-86326, which is rated as high severity.

Microsoft’s X account hacked in crypto pump-and-dump scheme

Unknown attackers hijacked the official Microsoft account on X to promote a pump-and-dump scheme involving a Clippy-themed cryptocurrency token. The compromised account has more than 13 million followers.

Written by a language model from the linked articles only. Each sentence cites its sources and was checked against them, mechanically and by a model; sentences that failed either check were removed.