- Details
- 2026-09-28 10:26:04
Audience: Vulnerability Managers, Security Operations, CISOs, DevSecOps Teams
Reading Time: Approximately 10 minutes
Subscribe to get these articles directly to your inbox when published
| CVE ID | Vendor / Product | CVSS | Date Added | CISA Due Date | Exploitation Type | EPSS Score | Reachability |
| CVE-2026-88779 | Citrix NetScaler ADC / Gateway | 8.7 (High) | 2026-10-04 | 2026-10-25 | Denial of Service |
0.592% |
N (Network) |
| CVE-2026-102489 | Zammad GmbH Zammad | 9.8 (Critical) | 2026-10-02 | 2026-10-23 | Session Fixation / RCE |
1.255% |
N (Network) |
| CVE-2026-102490 | Zammad GmbH Zammad | 8.8 (High) | 2026-10-02 | 2026-10-23 | Privilege Escalation |
0.579% |
N (Network) |
| CVE-2026-104286 | Fortinet FortiMail | 9.8 (Critical) | 2026-10-01 | 2026-10-22 | Path Traversal / File Write |
2.201% |
N (Network) |
| CVE-2026-76504 | Cisco Catalyst SD-WAN Manager | 9.8 (Critical) | 2026-09-30 | 2026-10-21 | Authentication Bypass |
1.819% |
N (Network) |
| CVE-2026-86950 | Apple iOS, macOS, iPadOS | 8.8 (High) | 2026-09-29 | 2026-10-20 | Out-of-Bounds Write |
1.242% |
N (Network) |
Note: EPSS scores are as published by FIRST.org at time of writing and are not updated after publication; scores change daily.
Lookup scores, news, poc's, threat intel, vendor advisory status, and exploit vectors in real time.Need live data on specific KEVs from this roundup?
What it is: An improper restriction of operations within memory bounds vulnerability in Citrix NetScaler ADC and Gateway configured as a SAML SP or IdP, leading to memory overflow and denial of service.
Affected versions: Customer-managed NetScaler ADC and NetScaler Gateway deployments utilizing SAML authentication flows.
Exploitation status: Active exploitation observed in the wild targeting unpatched enterprise deployments.
Patch available: Yes, security updates have been provided by Citrix.
CISA due date: 2026-10-25
Operational risk: Disruption of critical authentication services and remote access gateways, resulting in widespread user lockout or application availability failure.
What it is: A session fixation vulnerability in Zammad ticketing solutions that can be chained to achieve remote code execution as the zammad user.
Affected versions: Zammad versions 6.3.0 up to (not including) 6.5.4, and versions 7.0.0 through 7.1.3.
Exploitation status: Actively exploited in the wild, frequently chained with privilege escalation flaws.
Patch available: Yes, addressed in version 7.2.0.
CISA due date: 2026-10-23
Operational risk: Unauthorized session hijacking and remote code execution on helpdesk systems, exposing sensitive customer interactions and internal IT support workflows.
What it is: An improper privilege management vulnerability allowing local users to escalate privileges from zammad to root, typically chained with CVE-2026-102489.
Affected versions: Zammad versions from 1.5.0 up to (not including) 7.1.0, including 7.1.0-alpha.
Exploitation status: Actively exploited as part of a post-compromise privilege escalation vector.
Patch available: Yes, resolved in current stable releases.
CISA due date: 2026-10-23
Operational risk: Complete takeover of the underlying host operating system, giving threat actors root-level access to enterprise support infrastructures.
What it is: A path traversal and improper NULL byte neutralization vulnerability allowing unauthenticated remote attackers to write arbitrary files to the appliance.
Affected versions: Vulnerable FortiMail software branches specified in Fortinet advisory FG-IR-26-175.
Exploitation status: Confirmed active exploitation in the wild with unauthorized file modifications observed.
Patch available: Yes, vendor patches are available.
CISA due date: 2026-10-22
Operational risk: Full compromise of email security infrastructure, enabling potential message interception, tampering, or malicious persistence on gateway devices.
What it is: A hex encoding and URI handling vulnerability in the API session management layer permitting unauthenticated remote attackers to bypass authentication controls.
Affected versions: Cisco Catalyst SD-WAN Manager releases prior to fixed versions.
Exploitation status: Active exploitation detected in the wild.
Patch available: Yes, fixed releases have been issued by Cisco.
CISA due date: 2026-10-21
Operational risk: Complete administrative access to enterprise SD-WAN infrastructure, risking widespread network topology manipulation and routing disruption.
What it is: An out-of-bounds write vulnerability within the CoreGraphics rendering framework that can result in arbitrary code execution when processing malicious files.
Affected versions: Apple iOS, iPadOS, and macOS versions prior to security updates (such as iOS 26.7.1 / macOS Sequoia 15.8.1).
Exploitation status: Exploited in targeted, highly sophisticated attacks against specific individuals.
Patch available: Yes, patches released by Apple.
CISA due date: 2026-10-20
Operational risk: Device compromise via standard document or image rendering vectors, threatening executive mobile fleets and endpoint security.
This week's CISA KEV additions highlight an aggressive focus by threat actors on perimeter network infrastructure, edge appliances, and enterprise collaboration tooling. Critical vulnerabilities targeting core administrative components—such as Cisco Catalyst SD-WAN Manager and Fortinet FortiMail—demonstrate that unauthenticated remote entry points remain prime targets for gaining initial foothold access into corporate environments. Concurrently, composite attack chains involving helpdesk platforms like Zammad underscore how adversaries leverage session management flaws to pivot seamlessly into privilege escalation scenarios.
In addition to enterprise edge and server vectors, client-side risks persist with sophisticated spear-pocket exploitation observed against Apple's core graphics processing pipeline. The diversity of active exploits spanning network routing, email security, identity authentication flows, and client devices emphasizes the critical need for continuous boundary defense, rapid patch implementation, and forensic verification across both infrastructure and endpoint layers.
| Priority | CVE ID | Recommended Action | Timeline |
| 1 | CVE-2026-76504 | Immediately apply vendor-supplied software upgrades to Cisco Catalyst SD-WAN Manager. | Within 24 hours |
| 2 | CVE-2026-104286 | Apply Fortinet security patches to FortiMail and audit appliance file systems for unauthorized changes. | Within 24 hours |
| 3 | CVE-2026-102489 | Upgrade Zammad instances to version 7.2.0 or higher; conduct forensic triage for session abuse. | Within 72 hours |
| 4 | CVE-2026-102490 | Ensure Zammad is patched past vulnerable range to prevent local root privilege escalation. | Within 72 hours |
| 5 | CVE-2026-88779 | Update Citrix NetScaler ADC and Gateway appliances configured for SAML authentication. | Within 72 hours |
| 6 | CVE-2026-86950 | Deploy Apple OS updates (iOS, iPadOS, macOS) across organizational endpoints. | By CISA due date |
CVE-2026-88779 (Citrix):
Log Sources: NetScaler authentication and HTTP access logs, system crash dumps.
Behavioral Indicators: Sudden daemon crashes or restarts associated with SAML assertion processing.
Monitoring Gap / Detection Artifacts: High volume of malformed SAML requests targeting authentication endpoints.
CVE-2026-102489 / CVE-2026-102490 (Zammad):
Log Sources: Zammad application logs, web server access logs, auth logs, system execution logs.
Behavioral Indicators: Unusual session persistence patterns followed by unexpected local root command execution.
Monitoring Gap / Detection Artifacts: Presence of unexpected helper scripts or modified files within application directories.
CVE-2026-104286 (Fortinet):
Log Sources: FortiMail web server logs, system integrity monitoring logs.
Behavioral Indicators: Unauthenticated HTTP/HTTPS requests containing directory traversal sequences or null bytes.
Monitoring Gap / Detection Artifacts: Unauthorized creation or modification of system files on the appliance.
CVE-2026-76504 (Cisco):
Log Sources: Cisco SD-WAN Manager API access logs, authentication service logs.
Behavioral Indicators: Requests featuring anomalous hex-encoded URIs bypassing standard login endpoint validation.
Monitoring Gap / Detection Artifacts: Administrative actions performed by unverified external IP sessions lacking valid historical login handshakes.
CVE-2026-86950 (Apple):
Log Sources: Endpoint detection and response (EDR) telemetry, system diagnostic logs.
Behavioral Indicators: Unexpected application termination or anomalous process spawning following file rendering tasks.
Monitoring Gap / Detection Artifacts: Malformed graphic files delivered via email attachments or messaging vectors targeting CoreGraphics.
The inclusion of these critical infrastructure and application flaws highlights an ongoing threat trend where perimeter controls are systematically bypassed to achieve immediate high-privilege access. Organizations must prioritize automated asset discovery and threat hunting to ensure unpatched management interfaces and support portals are fully secured before exploitation scales.
Ensure you understand the latest KEV additions to cover off any potential gaps in your remediation activities. View all weekly reports here
The following resources offer technical analysis to help integrate CISA KEV data into operational triage workflows and stay aligned with updated mitigation guidance.
Lookup scores, news, poc's, threat intel, vendor advisory status, and exploit vectors in real time.Need live data on specific KEVs from this roundup?
This analysis is based on publicly available reporting and security research summaries. Some technical details may change as additional information becomes available.
Timur Mehmet | Founder & Lead Editor
Timur is a veteran Information Security professional with a career spanning over three decades. Since the 1990s, he has led security initiatives across high-stakes sectors, including Finance, Telecommunications, Media, and Energy. Professional qualifications over the years have included CISSP, ISO27000 Auditor, ITIL and technologies such as Networking, Operating Systems, PKI, Firewalls. For more information including independent citations and credentials, visit our About page.
Contact:
This article adheres to Hackerstorm.com's commitment to accuracy, independence, and transparency:
Editorial Policy: Ethics, Non-Bias, Fact Checking and Corrections
Learn More: About Hackerstorm.com | FAQs
CVE-2026-88779:
CISA KEV Catalog (CISA KEV catalog) — https://www.cisa.gov/known-exploited-vulnerabilities-catalog
NVD (NVD record) — https://nvd.nist.gov/vuln/detail/CVE-2026-88779
CVE-2026-102489:
CISA KEV Catalog (CISA KEV catalog) — https://www.cisa.gov/known-exploited-vulnerabilities-catalog
NVD (NVD record) — https://nvd.nist.gov/vuln/detail/CVE-2026-102489
CVE-2026-102490:
CISA KEV Catalog (CISA KEV catalog) — https://www.cisa.gov/known-exploited-vulnerabilities-catalog
NVD (NVD record) — https://nvd.nist.gov/vuln/detail/CVE-2026-102490
CVE-2026-104286:
CISA KEV Catalog (CISA KEV catalog) — https://www.cisa.gov/known-exploited-vulnerabilities-catalog
NVD (NVD record) — https://nvd.nist.gov/vuln/detail/CVE-2026-104286
CVE-2026-76504:
CISA KEV Catalog (CISA KEV catalog) — https://www.cisa.gov/known-exploited-vulnerabilities-catalog
NVD (NVD record) — https://nvd.nist.gov/vuln/detail/CVE-2026-76504
CVE-2026-86950:
CISA KEV Catalog (CISA KEV catalog) — https://www.cisa.gov/known-exploited-vulnerabilities-catalog
NVD (NVD record) — https://nvd.nist.gov/vuln/detail/CVE-2026-86950
COOKIE / PRIVACY POLICY: This website uses essential cookies required for basic site functionality. We also use analytics cookies to understand how the website is used. We do not use cookies for marketing or personalization, and we do not sell or share any personal data with third parties.