FortiMail Path-Traversal Zero-Day, Zammad Zero-Days Hit KEV, and Critical Fortra BoKS Auth Bypass

This brief covers security developments disclosed between October 1 and October 3, 2026. Every item below was checked against its primary source: the vendor advisory, the CISA KEV alert, or the original research.

Fortinet FortiMail zero-day lets unauthenticated attackers write arbitrary files (CVE-2026-104286)

Fortinet PSIRT · October 1, 2026

Fortinet disclosed CVE-2026-104286 (CVSS 9.8), a path traversal and NULL-byte handling flaw in FortiMail. An unauthenticated attacker can use crafted HTTP/HTTPS requests to write arbitrary files on the system, which can lead to code execution. FortiMail 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8 and 7.2.0–7.2.9 are affected. The bug is actively exploited and the fixed releases (8.0.2, 7.6.7, 7.4.9) are still listed as “upcoming.” Until they ship, Fortinet’s workaround is to disable IBE or keep the webmail interface off the internet. CISA added it to KEV on October 1 with an October 4 deadline for federal agencies. Fortinet also published IOCs, including the IPs 79.141.169[.]187 and 45.129.0[.]192.

“This has been reported to be exploited in the wild, customers are urged to apply the workaround below.” — Fortinet, FG-IR-26-175

Source: Fortinet FG-IR-26-175 · CISA KEV alert · The Hacker News

Zammad zero-days used in AI-agent breach of DIVD added to KEV (CVE-2026-102489, CVE-2026-102490)

DIVD CSIRT / CISA · October 2, 2026

CISA added two Zammad helpdesk flaws to KEV on October 2. Both were exploited as zero-days in the September 21 breach of the Dutch Institute for Vulnerability Disclosure (DIVD), which DIVD describes as an agentic-AI-driven attack. CVE-2026-102489 (CVSS 9.4) is a session fixation/hijack bug that leads to RCE as the zammad user. It affects Zammad 6.3.0–6.5.4. Versions 7.0.0–7.1.3 contain the bug, but it isn’t exploitable there because of environment conditions. CVE-2026-102490 (CVSS 9.4) is a local privilege escalation to root that affects all versions. Neither flaw had a fix at disclosure. DIVD has published an IOC log-check script.

“We advise all users of Zammad to upgrade to version 7 of Zammad or to take it offline.” — DIVD CSIRT

Source: DIVD-2026-00015 · CISA KEV alert · SecurityWeek

Fortra patches three critical BoKS flaws, including AD service-account auth bypass

Fortra · October 1, 2026

Fortra fixed eight vulnerabilities in Core Privileged Access Manager (BoKS). Three of them are critical:

  • CVE-2026-79901 (CVSS 9.9): AD service-account passwords are generated from a predictable sequence seeded with the Unix timestamp, which allows an authentication bypass.
  • CVE-2026-79898 (CVSS 9.1): command injection in crlserver that runs as root on the BoKS Master.
  • CVE-2026-12627 (CVSS 9.8): a stack overflow in autoregistration.

Patches are available. Fortra has not reported in-the-wild exploitation, and none of the three is in KEV.

“An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline.” — Fortra

Source: Fortra product security advisories · SecurityWeek

Still developing

Cisco Catalyst SD-WAN Manager auth bypass exploited as zero-day (CVE-2026-76504)

Cisco PSIRT · September 30, 2026

CVE-2026-76504 (CVSS 9.8) is an API authentication bypass caused by improper URI-encoding handling. It gives unauthenticated attackers admin-level API access to Catalyst SD-WAN Manager. All deployments are affected regardless of configuration, and there is no workaround. Fixes are in 26.2.1, 26.1.2.1, 20.18.4.1, 20.15.6.1, 20.12.8.2 and 20.9.10.1. CVE-2026-76504 is actively exploited and in KEV, with a federal deadline of October 3. Cisco published IOCs for serviceproxy-access.log and vmanage-server.log.

“In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability.” — Cisco

Source: Cisco advisory · CISA KEV alert · SecurityWeek

Citrix NetScaler exploitation: post-exploitation payloads create superuser and hide web shells (CVE-2026-88771)

LevelBlue SpiderLabs · October 1, 2026

LevelBlue documented exploitation of CVE-2026-88771 (CVSS 9.5), a pre-auth command injection in NetScaler ADC and Gateway that is already in KEV, across multiple customer environments. In some cases a Perl payload added a “sec_monitor” superuser and exfiltrated /flash/nsconfig. Attackers also planted PHP web shells mapped to URLs that look like CSS resources. Separately, Mandiant/GTIG reported dozens of victims of the companion bug, CVE-2026-88772.

“Taken together, the observed commands demonstrate activity extending beyond basic vulnerability validation.” — LevelBlue

Source: LevelBlue · CISA alert · The Hacker News

Microsoft: Zimbra SNMP command injection was probed before public disclosure (CVE-2026-73570)

Microsoft Threat Intelligence · September 30, 2026

CVE-2026-73570 (CVSS 8.9) is an unauthenticated OS command injection in Zimbra Collaboration Suite. It can be triggered through crafted SMTP traffic when zimbra-snmp is installed and SNMP notifications are enabled. Microsoft says scanning of the vulnerable code path started between the July 20 patch (ZCS 10.1.20) and the August 13 public disclosure. Later attacks deployed JSP web shells, escalated to root and stole credentials. The fix is ZCS 10.1.20 or later.

Source: Microsoft Security Blog · SecurityWeek


This brief covers the trailing ~48 hours (October 1–3, 2026).

Primary sources:

Google Unveils Gemini 4 Argon, OpenAI Ties a Distillation Campaign to Moonshot AI, and Anthropic Commits $100M to Train 10,000 Engineers

This brief covers the trailing ~72 hours (September 30–October 3, 2026). Every item below was confirmed on the originating organization’s own page, with a published date inside the window. Google announced Gemini 4 Argon, its new frontier model, with access initially limited to trusted cyber defenders. OpenAI disclosed that it disrupted a large campaign to extract protected model reasoning and attributed a core cluster to individuals associated with Moonshot AI. Anthropic launched a $100 million academy to train enterprise AI engineers, expanded its partnership with Barclays, and published a guest essay on “Claude-shaped” science.

Google announces Gemini 4 Argon, starting with trusted cyber defenders

Google · September 30, 2026

Gemini 4 Argon is Google’s new frontier model for long-horizon coding, enterprise knowledge work such as legal and finance, and cyber defense. Google reports a state-of-the-art 77.9% on DeepSWE v1.1, the top spot on the Vals Index, 51.3% on Zapier’s AutomationBench, and 91.7% on LVBench. The output token limit rises to 1 million, up from 64K. Argon is rolling out first to defenders in Google’s Fairwind Program, without cyber guardrails for those vetted users, while Google takes part in the U.S. government’s voluntary pre-release access process. Broader availability will start with paid API customers and Google AI Ultra subscribers. The introductory price is $2/$10 per million input/output tokens, rising to $4/$20 after the introductory period.

“Built to sustain deep reasoning across complex, long-horizon workflows, Argon is fundamentally changing the way we work and build at Google.” — Koray Kavukcuoglu, SVP, Google DeepMind

Source: Gemini 4 Argon: our next era of frontier intelligence

OpenAI disrupts a coordinated model-distillation campaign and attributes a core cluster to Moonshot AI

OpenAI · September 30, 2026

OpenAI says operators manipulated model interactions to get protected reasoning reproduced in visible form. One technique was copying encrypted reasoning from one conversation and asking a model in another to decrypt it. The activity began July 1 and spiked on July 24–25 with 16,000 attempted extraction requests from more than 4,000 users. A related cluster of more than 15,000 users was fully disrupted by July 28. OpenAI says no encryption or databases were breached. It closed the reasoning-replay pathway, banned accounts, and shared findings through the Frontier Model Forum and government channels.

“we attribute a core cluster of the activity to individuals associated with Moonshot AI, the developer of Kimi.” — OpenAI

Source: Disrupting a coordinated model-distillation campaign

Anthropic launches Claude Frontier Academy with $100M to train 10,000 deployed engineers

Anthropic · October 2, 2026

The Academy’s first program, the Frontier Deployed Engineer Residency, starts with a multi-day in-person program that ends in a graded practical. A 12-week residency follows, in which each engineer leads a real Claude project at their own organization. The goal is 10,000 certified engineers by the end of 2027. First cohorts are running in San Francisco, New York, and London, with engineers from Accenture, Bain, Capgemini, Commonwealth Bank of Australia, Deloitte, McKinsey, Morgan Stanley, and Novo Nordisk. Participation is by nomination.

“Claude Frontier Academy trains people the way our own engineers learn” — Steve Corfield, Global Head of Business Development and Partnerships, Anthropic

Source: Anthropic invests $100 million to train 10,000 engineers and tackle the enterprise AI talent gap

Barclays scales Claude across the bank, targeting 50% Claude Code adoption among developers this year

Anthropic · October 1, 2026

Barclays is extending its collaboration with Anthropic to speed up software development and modernize legacy systems. It expects Claude Code to reach half of its developers by the end of 2026 and most of its software engineers in 2027. Existing deployments include a Claude-powered Colleague Knowledge Assistant used by more than 16,000 Barclays UK staff, with over one million searches. In Global Markets, Claude helps classify and route about 120,000 client emails a day.

“Claude now helps 16,000 Barclays’ colleagues find answers for customers, sorts 120,000 emails a day, and will be in the hands of most Barclays engineers by 2027.” — Paul Smith, Chief Commercial Officer, Anthropic

Source: Barclays scales Claude to upgrade operations and improve client experience

“Claude-shaped science”: physicist Matthew Schwartz open-sources BootLoops after 36 manuscripts across 18 fields

Anthropic · October 1, 2026

In a guest post, physicist Matthew Schwartz describes picking problems suited to what current models do well instead of treating Claude like a human scientist. That approach produced BootLoops, an open-source harness for exact calculations in quantitative science. Starting from scattering amplitudes, where it computed 15 previously uncomputed elliptic Feynman integrals, the work spread to ecology, population genetics, economics, linguistics, and other fields with domain experts steering. Schwartz says Claude’s first findings in other fields were often technically correct but scientifically unremarkable until experts redirected them. He also lists failure modes such as declaring victory too early. Schwartz is a visiting researcher at Anthropic; BootLoops is his own project.

“Claude and GPT are good at science, but they are not scientists” — Matthew Schwartz

Source: Claude-shaped science

Still developing

Anthropic releases Claude Sonnet 5.5 (September 28, 2026). This is the second model in the Claude 5.5 family. Anthropic reports 70.6% on Terminal-Bench 4.0 and a GDPval-AA score within two points of Opus 5.5, at unchanged pricing of $2/$10 per million tokens. It is the first Sonnet to launch with cyber safeguards and classifiers that block reasoning extraction. Haiku 5.5 is due in the coming weeks. “It’s a clear upgrade over Claude Sonnet 5, runs 30%+ faster, and costs up to 30% less for most work.” — Anthropic. Source: Introducing Claude Sonnet 5.5

OpenAI ships GPT-6.1 Sol (September 29, 2026). OpenAI says this upgrade to GPT-6 Sol matches GPT-6 Astra on DeepSWE v1.1 at roughly one-fifth the cost. Prices are $2/$10 per million tokens, with cached input cut to $0.10. It is available in ChatGPT Work, Codex, and the API as gpt-6.1-sol. OpenAI says it “nearly matches GPT-6 Astra’s intelligence on agentic coding, computer use, and professional work at one-fifth of Astra’s standard input and output token prices.” Source: Introducing GPT-6.1 Sol


This brief covers the trailing ~72 hours (September 30–October 3, 2026).

Primary sources: