This brief covers security developments disclosed between October 1 and October 3, 2026. Every item below was checked against its primary source: the vendor advisory, the CISA KEV alert, or the original research.
Fortinet FortiMail zero-day lets unauthenticated attackers write arbitrary files (CVE-2026-104286)
Fortinet PSIRT · October 1, 2026
Fortinet disclosed CVE-2026-104286 (CVSS 9.8), a path traversal and NULL-byte handling flaw in FortiMail. An unauthenticated attacker can use crafted HTTP/HTTPS requests to write arbitrary files on the system, which can lead to code execution. FortiMail 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8 and 7.2.0–7.2.9 are affected. The bug is actively exploited and the fixed releases (8.0.2, 7.6.7, 7.4.9) are still listed as “upcoming.” Until they ship, Fortinet’s workaround is to disable IBE or keep the webmail interface off the internet. CISA added it to KEV on October 1 with an October 4 deadline for federal agencies. Fortinet also published IOCs, including the IPs 79.141.169[.]187 and 45.129.0[.]192.
“This has been reported to be exploited in the wild, customers are urged to apply the workaround below.” — Fortinet, FG-IR-26-175
Source: Fortinet FG-IR-26-175 · CISA KEV alert · The Hacker News
Zammad zero-days used in AI-agent breach of DIVD added to KEV (CVE-2026-102489, CVE-2026-102490)
DIVD CSIRT / CISA · October 2, 2026
CISA added two Zammad helpdesk flaws to KEV on October 2. Both were exploited as zero-days in the September 21 breach of the Dutch Institute for Vulnerability Disclosure (DIVD), which DIVD describes as an agentic-AI-driven attack. CVE-2026-102489 (CVSS 9.4) is a session fixation/hijack bug that leads to RCE as the zammad user. It affects Zammad 6.3.0–6.5.4. Versions 7.0.0–7.1.3 contain the bug, but it isn’t exploitable there because of environment conditions. CVE-2026-102490 (CVSS 9.4) is a local privilege escalation to root that affects all versions. Neither flaw had a fix at disclosure. DIVD has published an IOC log-check script.
“We advise all users of Zammad to upgrade to version 7 of Zammad or to take it offline.” — DIVD CSIRT
Source: DIVD-2026-00015 · CISA KEV alert · SecurityWeek
Fortra patches three critical BoKS flaws, including AD service-account auth bypass
Fortra · October 1, 2026
Fortra fixed eight vulnerabilities in Core Privileged Access Manager (BoKS). Three of them are critical:
- CVE-2026-79901 (CVSS 9.9): AD service-account passwords are generated from a predictable sequence seeded with the Unix timestamp, which allows an authentication bypass.
- CVE-2026-79898 (CVSS 9.1): command injection in crlserver that runs as root on the BoKS Master.
- CVE-2026-12627 (CVSS 9.8): a stack overflow in autoregistration.
Patches are available. Fortra has not reported in-the-wild exploitation, and none of the three is in KEV.
“An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline.” — Fortra
Source: Fortra product security advisories · SecurityWeek
Still developing
Cisco Catalyst SD-WAN Manager auth bypass exploited as zero-day (CVE-2026-76504)
Cisco PSIRT · September 30, 2026
CVE-2026-76504 (CVSS 9.8) is an API authentication bypass caused by improper URI-encoding handling. It gives unauthenticated attackers admin-level API access to Catalyst SD-WAN Manager. All deployments are affected regardless of configuration, and there is no workaround. Fixes are in 26.2.1, 26.1.2.1, 20.18.4.1, 20.15.6.1, 20.12.8.2 and 20.9.10.1. CVE-2026-76504 is actively exploited and in KEV, with a federal deadline of October 3. Cisco published IOCs for serviceproxy-access.log and vmanage-server.log.
“In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability.” — Cisco
Source: Cisco advisory · CISA KEV alert · SecurityWeek
Citrix NetScaler exploitation: post-exploitation payloads create superuser and hide web shells (CVE-2026-88771)
LevelBlue SpiderLabs · October 1, 2026
LevelBlue documented exploitation of CVE-2026-88771 (CVSS 9.5), a pre-auth command injection in NetScaler ADC and Gateway that is already in KEV, across multiple customer environments. In some cases a Perl payload added a “sec_monitor” superuser and exfiltrated /flash/nsconfig. Attackers also planted PHP web shells mapped to URLs that look like CSS resources. Separately, Mandiant/GTIG reported dozens of victims of the companion bug, CVE-2026-88772.
“Taken together, the observed commands demonstrate activity extending beyond basic vulnerability validation.” — LevelBlue
Source: LevelBlue · CISA alert · The Hacker News
Microsoft: Zimbra SNMP command injection was probed before public disclosure (CVE-2026-73570)
Microsoft Threat Intelligence · September 30, 2026
CVE-2026-73570 (CVSS 8.9) is an unauthenticated OS command injection in Zimbra Collaboration Suite. It can be triggered through crafted SMTP traffic when zimbra-snmp is installed and SNMP notifications are enabled. Microsoft says scanning of the vulnerable code path started between the July 20 patch (ZCS 10.1.20) and the August 13 public disclosure. Later attacks deployed JSP web shells, escalated to root and stole credentials. The fix is ZCS 10.1.20 or later.
Source: Microsoft Security Blog · SecurityWeek
This brief covers the trailing ~48 hours (October 1–3, 2026).
Primary sources: