Our Blog

Cybersecurity SOC dashboard comparing CVSS vulnerability severity with EPSS and CISA KEV exploitation signals, highlighting flawed vulnerability prioritisation models

Weekly CISA KEV Updates: 5 October 2026 - Six New Known Exploited Vulnerabilities Added

 

Audience: Vulnerability Managers, Security Operations, CISOs, DevSecOps Teams
Reading Time: Approximately 10 minutes

 

 

 

Subscribe to get these articles directly to your inbox when published

 

 

This Week's KEV Additions

CVE ID Vendor / Product CVSS Date Added CISA Due Date Exploitation Type EPSS Score Reachability
CVE-2026-88779 Citrix NetScaler ADC / Gateway 8.7 (High) 2026-10-04 2026-10-25 Denial of Service

0.592%

N (Network)
CVE-2026-102489 Zammad GmbH Zammad 9.8 (Critical) 2026-10-02 2026-10-23 Session Fixation / RCE

1.255%

N (Network)
CVE-2026-102490 Zammad GmbH Zammad 8.8 (High) 2026-10-02 2026-10-23 Privilege Escalation

0.579%

N (Network)
CVE-2026-104286 Fortinet FortiMail 9.8 (Critical) 2026-10-01 2026-10-22 Path Traversal / File Write

2.201%

N (Network)
CVE-2026-76504 Cisco Catalyst SD-WAN Manager 9.8 (Critical) 2026-09-30 2026-10-21 Authentication Bypass

1.819%

N (Network)
CVE-2026-86950 Apple iOS, macOS, iPadOS 8.8 (High) 2026-09-29 2026-10-20 Out-of-Bounds Write

1.242%

N (Network)

Note: EPSS scores are as published by FIRST.org at time of writing and are not updated after publication; scores change daily.

 

hackerstorm Dynamic Intelligence

Need live data on specific KEVs from this roundup?

Lookup scores, news, poc's, threat intel, vendor advisory status, and exploit vectors in real time.

 

Analysis

 

CVE-2026-88779 — Citrix NetScaler ADC / Gateway

  • What it is: An improper restriction of operations within memory bounds vulnerability in Citrix NetScaler ADC and Gateway configured as a SAML SP or IdP, leading to memory overflow and denial of service.

  • Affected versions: Customer-managed NetScaler ADC and NetScaler Gateway deployments utilizing SAML authentication flows.

  • Exploitation status: Active exploitation observed in the wild targeting unpatched enterprise deployments.

  • Patch available: Yes, security updates have been provided by Citrix.

  • CISA due date: 2026-10-25

  • Operational risk: Disruption of critical authentication services and remote access gateways, resulting in widespread user lockout or application availability failure.

 

CVE-2026-102489 — Zammad GmbH Zammad

  • What it is: A session fixation vulnerability in Zammad ticketing solutions that can be chained to achieve remote code execution as the zammad user.

  • Affected versions: Zammad versions 6.3.0 up to (not including) 6.5.4, and versions 7.0.0 through 7.1.3.

  • Exploitation status: Actively exploited in the wild, frequently chained with privilege escalation flaws.

  • Patch available: Yes, addressed in version 7.2.0.

  • CISA due date: 2026-10-23

  • Operational risk: Unauthorized session hijacking and remote code execution on helpdesk systems, exposing sensitive customer interactions and internal IT support workflows.

 

CVE-2026-102490 — Zammad GmbH Zammad

  • What it is: An improper privilege management vulnerability allowing local users to escalate privileges from zammad to root, typically chained with CVE-2026-102489.

  • Affected versions: Zammad versions from 1.5.0 up to (not including) 7.1.0, including 7.1.0-alpha.

  • Exploitation status: Actively exploited as part of a post-compromise privilege escalation vector.

  • Patch available: Yes, resolved in current stable releases.

  • CISA due date: 2026-10-23

  • Operational risk: Complete takeover of the underlying host operating system, giving threat actors root-level access to enterprise support infrastructures.

 

CVE-2026-104286 — Fortinet FortiMail

  • What it is: A path traversal and improper NULL byte neutralization vulnerability allowing unauthenticated remote attackers to write arbitrary files to the appliance.

  • Affected versions: Vulnerable FortiMail software branches specified in Fortinet advisory FG-IR-26-175.

  • Exploitation status: Confirmed active exploitation in the wild with unauthorized file modifications observed.

  • Patch available: Yes, vendor patches are available.

  • CISA due date: 2026-10-22

  • Operational risk: Full compromise of email security infrastructure, enabling potential message interception, tampering, or malicious persistence on gateway devices.

 

CVE-2026-76504 — Cisco Catalyst SD-WAN Manager

  • What it is: A hex encoding and URI handling vulnerability in the API session management layer permitting unauthenticated remote attackers to bypass authentication controls.

  • Affected versions: Cisco Catalyst SD-WAN Manager releases prior to fixed versions.

  • Exploitation status: Active exploitation detected in the wild.

  • Patch available: Yes, fixed releases have been issued by Cisco.

  • CISA due date: 2026-10-21

  • Operational risk: Complete administrative access to enterprise SD-WAN infrastructure, risking widespread network topology manipulation and routing disruption.

 

CVE-2026-86950 — Apple iOS, macOS, and iPadOS

  • What it is: An out-of-bounds write vulnerability within the CoreGraphics rendering framework that can result in arbitrary code execution when processing malicious files.

  • Affected versions: Apple iOS, iPadOS, and macOS versions prior to security updates (such as iOS 26.7.1 / macOS Sequoia 15.8.1).

  • Exploitation status: Exploited in targeted, highly sophisticated attacks against specific individuals.

  • Patch available: Yes, patches released by Apple.

  • CISA due date: 2026-10-20

  • Operational risk: Device compromise via standard document or image rendering vectors, threatening executive mobile fleets and endpoint security.

 

Exploitation Context

This week's CISA KEV additions highlight an aggressive focus by threat actors on perimeter network infrastructure, edge appliances, and enterprise collaboration tooling. Critical vulnerabilities targeting core administrative components—such as Cisco Catalyst SD-WAN Manager and Fortinet FortiMail—demonstrate that unauthenticated remote entry points remain prime targets for gaining initial foothold access into corporate environments. Concurrently, composite attack chains involving helpdesk platforms like Zammad underscore how adversaries leverage session management flaws to pivot seamlessly into privilege escalation scenarios.

 

In addition to enterprise edge and server vectors, client-side risks persist with sophisticated spear-pocket exploitation observed against Apple's core graphics processing pipeline. The diversity of active exploits spanning network routing, email security, identity authentication flows, and client devices emphasizes the critical need for continuous boundary defense, rapid patch implementation, and forensic verification across both infrastructure and endpoint layers.

 

 

Remediation Priorities

 

Priority CVE ID Recommended Action Timeline
1 CVE-2026-76504 Immediately apply vendor-supplied software upgrades to Cisco Catalyst SD-WAN Manager. Within 24 hours
2 CVE-2026-104286 Apply Fortinet security patches to FortiMail and audit appliance file systems for unauthorized changes. Within 24 hours
3 CVE-2026-102489 Upgrade Zammad instances to version 7.2.0 or higher; conduct forensic triage for session abuse. Within 72 hours
4 CVE-2026-102490 Ensure Zammad is patched past vulnerable range to prevent local root privilege escalation. Within 72 hours
5 CVE-2026-88779 Update Citrix NetScaler ADC and Gateway appliances configured for SAML authentication. Within 72 hours
6 CVE-2026-86950 Deploy Apple OS updates (iOS, iPadOS, macOS) across organizational endpoints. By CISA due date

 

 

Detection and Monitoring Guidance

 

  • CVE-2026-88779 (Citrix):

    • Log Sources: NetScaler authentication and HTTP access logs, system crash dumps.

    • Behavioral Indicators: Sudden daemon crashes or restarts associated with SAML assertion processing.

    • Monitoring Gap / Detection Artifacts: High volume of malformed SAML requests targeting authentication endpoints.

 

  • CVE-2026-102489 / CVE-2026-102490 (Zammad):

    • Log Sources: Zammad application logs, web server access logs, auth logs, system execution logs.

    • Behavioral Indicators: Unusual session persistence patterns followed by unexpected local root command execution.

    • Monitoring Gap / Detection Artifacts: Presence of unexpected helper scripts or modified files within application directories.

 

  • CVE-2026-104286 (Fortinet):

    • Log Sources: FortiMail web server logs, system integrity monitoring logs.

    • Behavioral Indicators: Unauthenticated HTTP/HTTPS requests containing directory traversal sequences or null bytes.

    • Monitoring Gap / Detection Artifacts: Unauthorized creation or modification of system files on the appliance.

 

  • CVE-2026-76504 (Cisco):

    • Log Sources: Cisco SD-WAN Manager API access logs, authentication service logs.

    • Behavioral Indicators: Requests featuring anomalous hex-encoded URIs bypassing standard login endpoint validation.

    • Monitoring Gap / Detection Artifacts: Administrative actions performed by unverified external IP sessions lacking valid historical login handshakes.

 

  • CVE-2026-86950 (Apple):

    • Log Sources: Endpoint detection and response (EDR) telemetry, system diagnostic logs.

    • Behavioral Indicators: Unexpected application termination or anomalous process spawning following file rendering tasks.

    • Monitoring Gap / Detection Artifacts: Malformed graphic files delivered via email attachments or messaging vectors targeting CoreGraphics.

 

 

Hackerstorm Analysis

The inclusion of these critical infrastructure and application flaws highlights an ongoing threat trend where perimeter controls are systematically bypassed to achieve immediate high-privilege access. Organizations must prioritize automated asset discovery and threat hunting to ensure unpatched management interfaces and support portals are fully secured before exploitation scales.

 

 

What you should do next

Ensure you understand the latest KEV additions to cover off any potential gaps in your remediation activities.  View all weekly reports here

 

 

 

 

Further Reading

The following resources offer technical analysis to help integrate CISA KEV data into operational triage workflows and stay aligned with updated mitigation guidance.

 

 

hackerstorm Dynamic Intelligence

Need live data on specific KEVs from this roundup?

Lookup scores, news, poc's, threat intel, vendor advisory status, and exploit vectors in real time.

 

 

 

 


About This Report

 

Attribution Note

This analysis is based on publicly available reporting and security research summaries. Some technical details may change as additional information becomes available. 

 

Author Information

Timur Mehmet | Founder & Lead Editor

Timur is a veteran Information Security professional with a career spanning over three decades. Since the 1990s, he has led security initiatives across high-stakes sectors, including Finance, Telecommunications, Media, and Energy. Professional qualifications over the years have included CISSP, ISO27000 Auditor, ITIL and technologies such as Networking, Operating Systems, PKI, Firewalls. For more information including independent citations and credentials, visit our About page.

Contact: This email address is being protected from spambots. You need JavaScript enabled to view it.

 

Editorial Standards

This article adheres to Hackerstorm.com's commitment to accuracy, independence, and transparency:

  • Fact-Checking: All statistics and claims are verified against primary sources and authoritative reports
  • Source Transparency: Original research sources and citations are provided in the References section below
  • No Conflicts of Interest: This analysis is independent and not sponsored by any vendor or organization
  • Corrections Policy: We correct errors promptly and transparently. Report inaccuracies to This email address is being protected from spambots. You need JavaScript enabled to view it.

Editorial Policy: Ethics, Non-Bias, Fact Checking and Corrections


Learn More: About Hackerstorm.com | FAQs

 

Source Transparency

 

 

 

 

 

 

 

 

 

 


 

Analyst Notes

  • No ransomware attribution was publicly associated with this week's KEV additions at the time of publication.
  • No confirmed threat actor attribution was available beyond CISA's confirmation of active exploitation for the majority of entries.
  • Where vendor advisory details or EPSS values were unavailable at publication time, placeholders were retained pending analyst validation and vendor updates prior to final publication.

 

 

 

 

 

By using this site, you agree to our Terms & Conditions.

COOKIE / PRIVACY POLICY: This website uses essential cookies required for basic site functionality. We also use analytics cookies to understand how the website is used. We do not use cookies for marketing or personalization, and we do not sell or share any personal data with third parties.

Terms & Privacy Policy