This month: 4 KEVs detected

CISA stopped reliably sending KEV alerts.
We didn't.

CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.

CVE-2026-88779
Citrix · NetScaler
Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
■Detected Oct 4 · 3-day patch deadline
CVE-2026-102489
Zammad GmbH · Zammad
Zammad GmbH Zammad Session Fixation Vulnerability
■Detected Oct 2 · 3-day patch deadline
CVE-2026-104286
Fortinet · FortiMail
Fortinet FortiMail Path Traversal Vulnerability
■Detected Oct 1 · 3-day patch deadline

KEV Intelligence Brief — October 5, 2026

Prepared for: Federal Contractors | DevOps & Platform Teams | Security Operations Leaders Classification: TLP:WHITE | Routine Distribution

Deadline Watch: Network Edge and Infrastructure Under Active Pressure

Three of the eight entries added this week target Citrix NetScaler ADC and Gateway — a pattern that warrants immediate command-level attention. CVE-2026-88771 and CVE-2026-88772, both added September 27 with a September 30 deadline that is now overdue, represent the most urgent exposure. CVE-2026-88771 allows an unauthenticated attacker to execute arbitrary commands via improper input validation — a near-worst-case posture for any internet-facing gateway. CVE-2026-88772 compounds this with a memory buffer vulnerability enabling remote code execution or denial of service from the same unauthenticated position. If your organization has not yet patched these, treat today as day zero: assume compromise, initiate forensic triage per CISA's published requirements under BOD 26-04, and isolate the appliance from internal network segments until attestation is complete.

The third NetScaler entry, CVE-2026-88779, was added October 4 with a tight October 7 deadline — two days from now. Its denial-of-service classification makes it lower severity than its siblings, but organizations running unpatched NetScaler infrastructure remain exposed to the full trilogy simultaneously. A threat actor who exploited CVE-2026-88771 for initial access last week can now trivially chain a DoS condition to disrupt incident response. Patch all three NetScaler CVEs in a single maintenance window. If your appliances are cloud-hosted or managed through Citrix's SaaS delivery model, validate your shared-responsibility posture under BOD 26-04's cloud services guidance — vendor patching SLAs do not satisfy federal remediation deadlines on your behalf.

Cisco's entry this week, CVE-2026-76504 in Catalyst SD-WAN Manager, carried a October 3 deadline now past. The mechanism — improper handling of URI hex encoding in HTTP requests — allowed unauthenticated remote access at admin-level privileges. This is not a subtle vulnerability; it's an authentication bypass dressed as an encoding quirk. SD-WAN Manager is a high-value lateral pivot point: full admin access translates directly to network topology visibility, policy manipulation, and potential traffic interception. Organizations relying on SD-WAN for hybrid or multi-site connectivity should immediately verify patch status, rotate all administrative credentials regardless of confirmed exploitation, and audit SD-WAN Manager access logs for anomalous API calls dating back to late September.

Arbitrary File Write and Session Hijacking: The Fortinet and Zammad Cluster

Two entries from early this week expose a shared theme: attackers reaching beyond application logic to write or execute content at the operating system level.

Fortinet's CVE-2026-104286 in FortiMail — deadline October 4, now overdue — combines a path traversal flaw with improper NULL byte neutralization to allow an unauthenticated attacker to write arbitrary files anywhere on the underlying filesystem via crafted HTTP/HTTPS requests. Arbitrary file write at the OS level, pre-authentication, is operationally equivalent to RCE in most deployment configurations: attackers can overwrite cron jobs, web shells, or configuration files without ever authenticating to the mail server itself. Internet-facing FortiMail deployments should be treated as potentially compromised until patched and forensically cleared. Inbound and outbound mail flow logging should be preserved for post-incident analysis, and any FortiMail instances sitting on network DMZs with admin interfaces reachable from untrusted networks should be immediately restricted at the firewall layer.

The Zammad entries — CVE-2026-102489 and CVE-2026-102490, deadline October 5, today — are notable for their explicit chaining relationship. CVE-2026-102489 is a session fixation vulnerability that enables remote code execution as the zammad service user. CVE-2026-102490 then allows that local zammad user to escalate privileges to root. Together, they form a clean two-step full-system compromise chain. Zammad is widely used as an open-source helpdesk and customer support platform, including in government contractor environments where it may receive sensitive case data or integrate with identity providers. Teams running self-hosted Zammad instances must patch immediately. Post-patch, invalidate all active sessions, rotate service account credentials, and audit sudo rules and SUID binaries on the host — CVE-2026-102490 specifically suggests the privilege escalation path is local, so host hardening matters as much as the application patch itself.

Consumer Platform Risk Spreading to Enterprise: Apple CoreGraphics

CVE-2026-86950 affecting Apple iOS, macOS, and iPadOS via an out-of-bounds write in CoreGraphics may appear to sit outside the traditional enterprise perimeter, but this framing is increasingly obsolete. macOS endpoints are standard issue across development, executive, and legal functions in contractor environments; iOS and iPadOS devices access VPNs, email, and MDM-managed enterprise applications daily. The October 2 deadline has passed. Arbitrary code execution via CoreGraphics — a graphics rendering library invoked by virtually every application on the platform — represents a broad, low-friction attack surface exploitable through malicious documents, web content, or image files.

Security operations teams should confirm device compliance via MDM platforms (Jamf, Intune, etc.) and enforce OS version minimums as a prerequisite for network access. Any device that cannot attest to a patched OS version should be quarantined from corporate resources. The BOD 26-04 forensics triage requirement applies to government-managed Apple assets; contractor environments should mirror this posture under their own patch governance programs.

Bottom line for the week: Five of eight patch deadlines are already overdue as of today. Two Citrix NetScaler CVEs enabling unauthenticated RCE have been exploitable without consequence for at least five days. Remediation velocity, not just patch planning, is the operational imperative this week.

Sources: CISA KEV Catalog · Citrix Security Bulletins · Fortinet PSIRT Advisories · Cisco Security Advisories · Apple Security Releases · Zammad Security Releases · CISA BOD 26-04

Free KEV Alerts

  • Real-time notification the moment a KEV drops
  • Vendor and product details
  • BOD 26-04 remediation deadline included

Pro Alerts Coming Soon

  • Real-time notification the moment a KEV drops
  • Filtered to your specific vendor watchlist
  • Urgency scoring (Critical / Urgent / Standard)
  • Direct patch links included

Stay ahead of CISA.

No spam. Unsubscribe anytime. We don't sell your data.


Upcoming Patch Due Dates

via Binding Operational Directive 26-04

BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.

Loading...

News Logo

Cyber Security News

You may have missed...


Hacking Editorial Brief — October 7, 2026

ASOS Breach Attribution Emerges; Snowflake Repository Compromised

The ASOS security incident that surfaced yesterday through push notification extortion now has an attribution claim. A group identifying itself as "Xuanye group" claimed responsibility for compromising ASOS's Snowflake cloud data repository, according to messages sent to app users. The Snowflake platform detail provides the first technical specificity about the breach vector, following yesterday's unusual public notification tactic that bypassed traditional extortion channels. ASOS shares continued sliding as the incident develops, though the company has not confirmed the attackers' claims or disclosed what data may have been accessed from the repository.

Critical Flaw in Progress AI Gateway Enables Command Injection

Progress Software disclosed CVE-2026-91140, a critical command injection vulnerability in its DataDirect GenAI gateway product that allows malicious OpenAPI or Swagger documents to execute arbitrary operating system commands through AI agents. The flaw represents a new class of supply chain risk where document parsing by AI-integrated systems creates execution pathways. Separately, the BYOD ransomware group claimed to have breached Trump Mobile, leaking 3,615 customer records including names, email addresses, phone numbers, and home addresses. A former infrastructure engineer was sentenced to 32 months in prison for deploying ransomware-style malware that locked over 3,000 devices on his employer's network, marking one of the more significant insider threat prosecutions this year.

Japan's business community reported a 50 percent year-over-year increase in AI-assisted corporate hacking attempts, adding regional context to the broader surge in AI-enabled attack campaigns documented across multiple jurisdictions.

Sources: NHK World · Mighty 790 KFGO · TechRadar · Cybersecurity News · BleepingComputer

📌 Pinned

*

https:betanews.comMar 5

Inside a cyberattack: How hackers steal data

The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...

https://www.bloomberg.comOct 5

US Nabs Suspected China Spy for Surveilling Taiwan Leader's Son

The FBI arrested a woman suspected of spying for China by surveilling the Taiwanese president's son and his family at Los Angeles International Airpor...

https://dig.watchOct 6

UNC2814 suspected China-linked cyber espionage group compromises 50+ organisations across 42 countries

Google Threat Intelligence disrupted a China-linked espionage campaign where UNC2814 deployed GRIDTIDE backdoor malware controlled through Google Shee...

https://www.defenseone.comOct 1

China-linked hackers posed as former US officials, Anthropic employee to target AI experts

Proofpoint identified phishing campaigns by China-linked TA419 that borrowed prominent figures' identities to approach U.S. AI policy researchers befo...

https://thehackernews.comOct 6

Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT

Multiple threat actors are exploiting Citrix NetScaler vulnerabilities CVE-2026-88771 and CVE-2026-88772 for mass exploitation with web shell and malw...

https://arstechnica.comOct 7

Hackers obtain counterfeit TLS certificates for Google and other large services

Compromise of 3 domain registries allows hackers to walk off with unauthorized certs.

https://therecord.mediaOct 7

South Korean officials believe AI agents were used to hack several banks

... hack the banks' systems ... The incidents, which first came to light on September 30, are the first known example of AI agents hacking the financi...

https://www.wsj.comOct 6

Hackers Use Chinese AI Tool to Hit South Korean Banks, Exposing New Risk - WSJ

Hackers used a Chinese artificial-intelligence agent to attack South Korea's biggest banks and steal the personal information of 68,000 people, ...

https://inkl.comOct 2

Chinese hackers pose as former White House official in AI espionage campaign

Chinese hackers posed as AI and statecraft experts, including Lynne Parker from the White House Office of Science and Technology Policy, in espionage ...


Updated daily