Skip to content
Sunday, 4 October 2026
Tenesys AI News
Subscribe

All News

TENESYS AI NEWS tracks the most important AI news and explains what changed, why it matters and whether a technology is worth testing.

“Exploited” — 4 articles ✕

Cyber Security· Important

CISA Flags Two Actively Exploited Zammad Vulnerabilities

CISA added two Zammad vulnerabilities to its Known Exploited Vulnerabilities catalog after confirming active exploitation. CVE-2026-102489 is a session fixation flaw and CVE-2026-102490 involves improper privilege management in the Zammad helpdesk/customer service platform. Federal agencies must remediate under Binding Operational Directive 26-04, and CISA urges all organizations to prioritize these fixes.

CISA Advisories
Cyber Security· Important

CISA adds actively exploited FortiMail path traversal flaw to KEV catalog

CISA added CVE-2026-104286, a path traversal vulnerability in Fortinet FortiMail, to its Known Exploited Vulnerabilities (KEV) Catalog after confirming active exploitation in the wild. Under Binding Operational Directive 26-04, federal civilian agencies must prioritize patching this vulnerability on internet-exposed assets, especially where it could grant full control of the system. CISA also recommends all organizations, not just federal agencies, prioritize remediation of KEV-listed flaws.

CISA Advisories

CERT-EU warns of actively exploited critical SharePoint RCE flaws

CERT-EU has updated its advisory on critical vulnerabilities in Microsoft SharePoint Server, confirming active exploitation of CVE-2026-50522 (CVSS 9.8), a deserialisation flaw allowing remote code execution. This is part of a wider series of recently patched critical bugs — CVE-2026-32201, CVE-2026-45659, CVE-2026-56164 and CVE-2026-58644 — affecting on-premise SharePoint Server instances, some exploitable without authentication.

CERT-EU

Critical Citrix NetScaler Vulnerabilities Actively Exploited

Citrix disclosed 8 vulnerabilities affecting customer-managed NetScaler ADC and NetScaler Gateway, including 2 critical unauthenticated RCE flaws with CVSS 9.5 that Citrix confirms are being actively exploited. CERT-EU urges immediate patching and compromise assessment for internet-facing appliances. Other flaws include HTTP request smuggling, memory overflow bugs leading to RCE/DoS, a policy bypass, and a TCP ISN prediction issue.

CERT-EU