FortiMail zero-day is being exploited while fixed builds remain…Cisco SD-WAN Manager auth bypass gives attackers administrator accessMetaMask exits staking validators after infrastructure compromiseCalifornia subpoenas OpenAI over AI model security incidents
FortiMail zero-day is being exploited while fixed builds remain unavailable
Fortinet and CISA confirm exploitation of an unauthenticated FortiMail arbitrary-file-write flaw. Fixed builds were still unavailable at disclosure, making isolation, feature-level mitigation and forensic triage today’s highest-priority decision.
Security.io Intelligence Desk · Friday, 2 October 2026
Executive consequence
CVE-2026-104286 allows unauthenticated arbitrary file writes through crafted HTTP or HTTPS requests to affected FortiMail appliances. Fortinet published appliance indicators and temporary mitigations, while CISA added the flaw to KEV and set a short federal deadline.
Decision today
Inventory affected FortiMail branches, IBE status and management exposure.
Read the full decision briefPrimary reporting: Fortinet PSIRT · CISA Known Exploited Vulnerabilities Catalog · watchTowr Intel
Decision intelligence, not a headline feed.Every edition ranks what security leaders should read first, assign today and monitor next.
Daily executive briefing
Security.io Daily Headlines
Five equally weighted stories: what happened and the leadership decision each creates.
CVE-2026-76504 is a critical Cisco Catalyst SD-WAN Manager API authentication bypass under active exploitation. Cisco says crafted URI encoding can bypass an endpoint authentication rule and provide administrator privileges.
Do today
Inventory every Catalyst SD-WAN Manager instance and its management reachability.
MetaMask disclosed an infrastructure security incident and began precautionary exits of affected validators in its non-custodial staking operations. Lido expects the exit and re-entry process to create foregone rewards and possible downtime penalties.
Do today
Map treasury, staking and customer dependencies on MetaMask Staking.
California DOJ served OpenAI with an investigative subpoena as part of an inquiry into cybersecurity incidents and risks involving the company and its AI models.
Do today
Inventory AI evaluations with command, credential, network or tool access.
ATNS procurement material and specialist reporting describe suspicious activity in operational technology supporting weather-related air-traffic services, with preliminary identification of malware associated with early ransomware stages.
Do today
Request scoped assurance from ATNS and relevant aviation suppliers.
Scores are Security.io editorial assessments from 0–100. Exposure reflects reachable affected estate, Urgency reflects exploitation and fix availability, and Business Consequence reflects mail-gateway privilege and compromise cost. Source: Security.io editorial score using Fortinet PSIRT and CISA KEV evidence.
Back page
Daily comic · Circuit Chuckles
A brief pause after the intelligence
Configuration Drift
A wheeled server rack literally drifts across the room, and Rusty contains it with rope even though the settings continue to change.