Cybersecurity: Key Vulnerabilities Discovered Between September 29 and October 2, 2026

Written by: Adel Khelifi on October 2, 2026

The National Cybersecurity Agency (ANCS) announced this Friday the discovery during the period September 28, 2026 to October 2, 2026 of a set of vulnerabilities classified as dangerous and very dangerous.

List of vulnerabilities :

October 2: Fortinet FortiMail (very dangerous)

Discovered in Fortinet FortiMail. Exploitation of this flaw could allow a remote attacker to execute arbitrary code. Its impact includes: denial of service, arbitrary code execution, loss of integrity and loss of confidentiality.

The fix for this vulnerability is achieved by updating FortiMail to versions 8.0.2 and later, 7.6.7 and later, 7.4.9 and later, 7.4 and later.

October 2: Mozilla Thunderbird (dangerous)

The exploitation of these flaws could enable a remote attacker to execute arbitrary code and cause a data confidentiality breach. Its impact includes a denial of service, arbitrary code execution, loss of integrity and loss of confidentiality. The fix for this vulnerability is achieved by updating Mozilla Thunderbird.

October 1: GitLab (very dangerous)

The exploitation of these flaws could allow a remote attacker to cause a data confidentiality breach. Its impact includes a denial of service, arbitrary code execution, loss of integrity and loss of confidentiality. The fix for this vulnerability is achieved by updating GitLab.

October 1: Cisco Catalyst SD-WAN Manager (very dangerous)

The exploitation of this flaw could allow a remote attacker to cause a privilege escalation. The fix for this vulnerability is achieved by updating Cisco Catalyst SD-WAN.

September 30: Mozilla Firefox (dangerous)

The exploitation of these flaws could allow a remote attacker to execute arbitrary code. The fix for this vulnerability is achieved by updating Mozilla Firefox products to version 157, Firefox ESR to versions 115.42 -140.17 – 153.4.

September 30: OpenSSL (dangerous)

The exploitation of this flaw could allow a remote attacker to cause a denial of service. The fix for this vulnerability is achieved by updating OpenSSL.

September 30: Google Chrome (dangerous)

The exploitation of these flaws could allow a remote attacker, by convincing the victim to visit a specifically crafted webpage published on the Internet, to execute arbitrary code.

The fix for this vulnerability is achieved by updating Chrome to version 154.0.8037.92/.93 for Windows and Mac and 154.0.8037.92 for Linux.

September 29: Zimbra Collaboration (dangerous)

The exploitation of these flaws could allow a remote attacker to execute arbitrary code and cause a confidentiality breach. The fix for this vulnerability is achieved by updating Zimbra to version 10.1.21.

September 29: GLPI products (dangerous)

The exploitation of these flaws could allow a remote attacker to execute arbitrary code and cause a confidentiality breach. The fix for this vulnerability is achieved by updating GLPI to version 10.0.26 or 11.0.8.

September 29: Apple products (very dangerous)

The exploitation of this flaw could allow a remote attacker to execute arbitrary code and compromise data confidentiality. This flaw is actively exploited. The fix for this vulnerability is achieved by updating Apple products (iPhone, iPad).

September 29: WordPress: Elementor Website Builder plugin (dangerous)

It was discovered in the WordPress Elementor Website Builder plugin. Exploitation of this flaw could allow a remote attacker to cause a data confidentiality breach.

The fix for this vulnerability is achieved by updating the Elementor Website Builder plugin to version 4.3.2.

September 28: Citrix products (very dangerous)

The exploitation of these flaws could allow a remote attacker to execute arbitrary code and cause a denial of service. The CVEs CVE-2026-88771 and CVE-2026-88772 are actively being exploited. The fix for this vulnerability is achieved by updating Citrix NetScaler ADC and Citrix NetScaler Gateway.

September 28: PHP (dangerous)

The exploitation of these flaws could allow a remote attacker to execute arbitrary code and cause a confidentiality breach. The fix for this vulnerability is achieved by updating PHP.

September 28: Elastic products (dangerous)

The exploitation of this flaw could allow a remote attacker to execute arbitrary code. The affected products are:

  • Microsoft Office LTSC 2024 for 64-bit editions
  • Microsoft Office LTSC 2021 for 64-bit editions
  • Microsoft Office LTSC 2024 for 32-bit editions
  • Microsoft Office LTSC 2021 for 32-bit editions
  • Microsoft 365 Apps for Enterprise for 64-bit Systems
  • Microsoft 365 Apps for Enterprise for 32-bit Systems

The fix for this vulnerability is achieved by updating Microsoft products.




Adel Khelifi

Adel Khelifi

My name is Adel Khelifi, and I’m a journalist based in Tunis with a passion for telling local stories to a global audience. I cover current affairs, culture, and social issues with a focus on clarity and context. I believe journalism should connect people, not just inform them.