FortiMail Path-Traversal Zero-Day, Zammad Zero-Days Hit KEV, and Critical Fortra BoKS Auth Bypass

This brief covers security developments disclosed between October 1 and October 3, 2026. Every item below was checked against its primary source: the vendor advisory, the CISA KEV alert, or the original research.

Fortinet FortiMail zero-day lets unauthenticated attackers write arbitrary files (CVE-2026-104286)

Fortinet PSIRT · October 1, 2026

Fortinet disclosed CVE-2026-104286 (CVSS 9.8), a path traversal and NULL-byte handling flaw in FortiMail. An unauthenticated attacker can use crafted HTTP/HTTPS requests to write arbitrary files on the system, which can lead to code execution. FortiMail 8.0.0–8.0.1, 7.6.0–7.6.6, 7.4.0–7.4.8 and 7.2.0–7.2.9 are affected. The bug is actively exploited and the fixed releases (8.0.2, 7.6.7, 7.4.9) are still listed as “upcoming.” Until they ship, Fortinet’s workaround is to disable IBE or keep the webmail interface off the internet. CISA added it to KEV on October 1 with an October 4 deadline for federal agencies. Fortinet also published IOCs, including the IPs 79.141.169[.]187 and 45.129.0[.]192.

“This has been reported to be exploited in the wild, customers are urged to apply the workaround below.” — Fortinet, FG-IR-26-175

Source: Fortinet FG-IR-26-175 · CISA KEV alert · The Hacker News

Zammad zero-days used in AI-agent breach of DIVD added to KEV (CVE-2026-102489, CVE-2026-102490)

DIVD CSIRT / CISA · October 2, 2026

CISA added two Zammad helpdesk flaws to KEV on October 2. Both were exploited as zero-days in the September 21 breach of the Dutch Institute for Vulnerability Disclosure (DIVD), which DIVD describes as an agentic-AI-driven attack. CVE-2026-102489 (CVSS 9.4) is a session fixation/hijack bug that leads to RCE as the zammad user. It affects Zammad 6.3.0–6.5.4. Versions 7.0.0–7.1.3 contain the bug, but it isn’t exploitable there because of environment conditions. CVE-2026-102490 (CVSS 9.4) is a local privilege escalation to root that affects all versions. Neither flaw had a fix at disclosure. DIVD has published an IOC log-check script.

“We advise all users of Zammad to upgrade to version 7 of Zammad or to take it offline.” — DIVD CSIRT

Source: DIVD-2026-00015 · CISA KEV alert · SecurityWeek

Fortra patches three critical BoKS flaws, including AD service-account auth bypass

Fortra · October 1, 2026

Fortra fixed eight vulnerabilities in Core Privileged Access Manager (BoKS). Three of them are critical:

  • CVE-2026-79901 (CVSS 9.9): AD service-account passwords are generated from a predictable sequence seeded with the Unix timestamp, which allows an authentication bypass.
  • CVE-2026-79898 (CVSS 9.1): command injection in crlserver that runs as root on the BoKS Master.
  • CVE-2026-12627 (CVSS 9.8): a stack overflow in autoregistration.

Patches are available. Fortra has not reported in-the-wild exploitation, and none of the three is in KEV.

“An attacker who knows the service principal and can estimate the password-change time can reproduce a limited candidate set and verify candidates offline.” — Fortra

Source: Fortra product security advisories · SecurityWeek

Still developing

Cisco Catalyst SD-WAN Manager auth bypass exploited as zero-day (CVE-2026-76504)

Cisco PSIRT · September 30, 2026

CVE-2026-76504 (CVSS 9.8) is an API authentication bypass caused by improper URI-encoding handling. It gives unauthenticated attackers admin-level API access to Catalyst SD-WAN Manager. All deployments are affected regardless of configuration, and there is no workaround. Fixes are in 26.2.1, 26.1.2.1, 20.18.4.1, 20.15.6.1, 20.12.8.2 and 20.9.10.1. CVE-2026-76504 is actively exploited and in KEV, with a federal deadline of October 3. Cisco published IOCs for serviceproxy-access.log and vmanage-server.log.

“In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability.” — Cisco

Source: Cisco advisory · CISA KEV alert · SecurityWeek

Citrix NetScaler exploitation: post-exploitation payloads create superuser and hide web shells (CVE-2026-88771)

LevelBlue SpiderLabs · October 1, 2026

LevelBlue documented exploitation of CVE-2026-88771 (CVSS 9.5), a pre-auth command injection in NetScaler ADC and Gateway that is already in KEV, across multiple customer environments. In some cases a Perl payload added a “sec_monitor” superuser and exfiltrated /flash/nsconfig. Attackers also planted PHP web shells mapped to URLs that look like CSS resources. Separately, Mandiant/GTIG reported dozens of victims of the companion bug, CVE-2026-88772.

“Taken together, the observed commands demonstrate activity extending beyond basic vulnerability validation.” — LevelBlue

Source: LevelBlue · CISA alert · The Hacker News

Microsoft: Zimbra SNMP command injection was probed before public disclosure (CVE-2026-73570)

Microsoft Threat Intelligence · September 30, 2026

CVE-2026-73570 (CVSS 8.9) is an unauthenticated OS command injection in Zimbra Collaboration Suite. It can be triggered through crafted SMTP traffic when zimbra-snmp is installed and SNMP notifications are enabled. Microsoft says scanning of the vulnerable code path started between the July 20 patch (ZCS 10.1.20) and the August 13 public disclosure. Later attacks deployed JSP web shells, escalated to root and stole credentials. The fix is ZCS 10.1.20 or later.

Source: Microsoft Security Blog · SecurityWeek


This brief covers the trailing ~48 hours (October 1–3, 2026).

Primary sources:

Leave a Reply