This month: 3 KEVs detected

CISA stopped reliably sending KEV alerts.
We didn't.

CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.

CVE-2026-102489
Zammad GmbH · Zammad
Zammad GmbH Zammad Session Fixation Vulnerability
■Detected Oct 2 · 3-day patch deadline
CVE-2026-104286
Fortinet · FortiMail
Fortinet FortiMail Path Traversal Vulnerability
■Detected Oct 1 · 3-day patch deadline
CVE-2026-76504
Cisco · Catalyst SD-WAN Manager
Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability
■Detected Sep 30 · 3-day patch deadline

KEV Intelligence Brief — October 2, 2026

Prepared for: Federal Contractors · DevOps Teams · Security Operations Leaders Classification: Unclassified // For Official Distribution Reporting Period: September 25 – October 2, 2026

Eight vulnerabilities added to CISA's Known Exploited Vulnerabilities catalog over the past eight days span some of the most consequential attack surfaces in enterprise and government environments: remote access infrastructure, collaboration platforms, endpoint operating systems, and IT service management tooling. Several patch deadlines have already passed. Others expire this weekend. Operations teams should treat this brief as an immediate action document.

Overdue and Expiring: Remote Access and Collaboration Infrastructure Under Active Exploitation

The oldest deadlines in this batch have already lapsed, and there is no grace period when exploitation is confirmed. Federal agencies and contractors running Citrix NetScaler ADC or NetScaler Gateway should assume these systems are being actively targeted. CVE-2026-88771 and CVE-2026-88772 — both added September 27 with a patch deadline of September 30 — represent a dangerous pairing. The first allows an unauthenticated attacker to execute arbitrary commands via improper input validation; the second permits remote code execution or denial of service through a memory buffer boundary violation. Together, they offer attackers a low-friction path to full system compromise on a product class that historically sits at the perimeter, directly terminating VPN and application delivery sessions. If your NetScaler fleet is not yet patched, treat those systems as potentially compromised and initiate forensic triage per CISA's BOD 26-04 requirements before restoring normal operations. Credential rotation for all accounts authenticating through these gateways is mandatory — not optional.

Microsoft SharePoint (CVE-2026-65660, deadline September 28) is similarly past due. This code injection flaw allows an authorized but potentially low-privilege user to execute code over the network — a profile consistent with insider threat scenarios and post-phishing lateral movement chains. SharePoint's deep integration with Microsoft 365, Active Directory, and document workflows makes it a high-value pivot point. On-premises SharePoint deployments require immediate patching. Hybrid and cloud-connected instances should be audited against BOD 26-04 cloud service guidance, and site collection administrator permissions should be reviewed for unexpected grants.

Apple iOS, macOS, and iPadOS (CVE-2026-86950, deadline October 2 — today) round out this cluster. The CoreGraphics out-of-bounds write vulnerability enabling arbitrary code execution affects the managed device fleets that feed credentials and session tokens into every enterprise system listed above. Mobile device management teams should confirm OS update compliance across the entire fleet today. Devices that cannot accept the patch should be quarantined from corporate resources pending a risk determination.

Network Infrastructure on the Knife's Edge: Fortinet and Cisco

Two critical infrastructure vulnerabilities with deadlines expiring this weekend demand immediate attention from network engineering and security operations teams.

Fortinet FortiMail (CVE-2026-104286, deadline October 4) contains a path traversal vulnerability compounded by improper NULL byte handling that allows an unauthenticated attacker to write arbitrary files to the underlying filesystem via crafted HTTP or HTTPS requests. Unauthenticated arbitrary file write on an internet-facing mail gateway is a near-certain vector for webshell implantation and persistent access. FortiMail deployments exposed to the internet should be isolated behind out-of-band management access until patching is confirmed. Log review should focus on unusual HTTP request patterns, unexpected file creation in web-accessible directories, and any new scheduled tasks or service modifications. Fortinet's PSIRT advisory cadence typically includes indicators of compromise — pull those and run them against SIEM data immediately.

Cisco Catalyst SD-WAN Manager (CVE-2026-76504, deadline October 3) presents an equally urgent threat. The hex encoding vulnerability — rooted in improper URI encoding handling — allows an unauthenticated remote attacker to access the system with full administrative privileges. SD-WAN Manager is a centralized control plane; administrative access to it translates to visibility and potential manipulation of routing policy, tunnel configurations, and connected branch infrastructure at scale. Organizations running Catalyst SD-WAN should restrict SD-WAN Manager access to management-plane-only networks immediately, confirm no public-facing exposure exists, and apply Cisco's patch ahead of tomorrow's deadline. Review access logs for anomalous authentication events or unexpected configuration changes dating back at least 30 days.

Deadline Watch: The Zammad Chain and Its Escalation Path

Added today, October 2, with a tight three-day deadline of October 5, CVE-2026-102489 and CVE-2026-102490 represent the most operationally acute chained exploitation risk in this batch. Zammad, an open-source helpdesk and ticketing platform, is deployed across a range of organizations — including federal contractors who use it for internal service management workflows.

The chain is straightforward and devastating: CVE-2026-102489 enables session fixation leading to remote code execution as the zammad service user. CVE-2026-102490 then allows local privilege escalation from that service account to root. An attacker who chains these two vulnerabilities gains full root access to the Zammad host — and everything reachable from it — with no prior authentication required at the entry point. Any Zammad instance exposed to the internet, even partially, should be considered a critical priority. If patching cannot be completed before October 5, the system should be taken offline and access restricted to internal networks only. Post-patch, assume the zammad user and all associated service credentials have been compromised and rotate accordingly.

Summary Patch Deadline Table

| CVE | Product | Deadline | Status | |---|---|---|---| | CVE-2026-65660 | Microsoft SharePoint | Sep 28 | OVERDUE | | CVE-2026-88771/88772 | Citrix NetScaler | Sep 30 | OVERDUE | | CVE-2026-86950 | Apple iOS/macOS/iPadOS | Oct 2 | Due Today | | CVE-2026-76504 | Cisco Catalyst SD-WAN Manager | Oct 3 | 48 hrs | | CVE-2026-104286 | Fortinet FortiMail | Oct 4 | 72 hrs | | CVE-2026-102489/102490 | Zammad | Oct 5 | ~96 hrs |

Sources: CISA KEV Catalog · CISA BOD 26-04 · Fortinet PSIRT Advisories · Cisco Security Advisories · Citrix Security Bulletins · Apple Security Releases · Microsoft Security Update Guide · Zammad Security Notices

Free KEV Alerts

  • Real-time notification the moment a KEV drops
  • Vendor and product details
  • BOD 26-04 remediation deadline included

Pro Alerts Coming Soon

  • Real-time notification the moment a KEV drops
  • Filtered to your specific vendor watchlist
  • Urgency scoring (Critical / Urgent / Standard)
  • Direct patch links included

Stay ahead of CISA.

No spam. Unsubscribe anytime. We don't sell your data.


Upcoming Patch Due Dates

via Binding Operational Directive 26-04

BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.

Loading...

News Logo

Cyber Security News

You may have missed...


Hacking Editorial Brief — October 2, 2026

Law Enforcement Develops iPhone Reboot Bypass as ShinyHunters Resurfaces

Security researchers have disclosed that forensic device manufacturer Grayshift claims to have developed a workaround for Apple's automatic inactivity reboot feature, which locks iPhones after 72 hours of inactivity. A leaked video allegedly demonstrates the technique freezing iPhones in a "Before First Unlock" state, allowing investigators extended access windows for phone exploitation tools. The disclosure comes as the ShinyHunters threat group reappeared after reports suggested their infrastructure had been disrupted. The group told Dutch media their website had merely migrated to a new address rather than being shut down, contradicting earlier speculation about law enforcement action. ShinyHunters recently claimed responsibility for a massive data breach targeting Dutch telecommunications provider Odido.

Pentagon Breach Exposed 3 Million Personnel Records Through File-Sharing Flaw

The Pentagon's Defense Manpower Data Center disclosed a security vulnerability in its file-sharing system that allowed unauthorized access to unencrypted personnel records belonging to over three million individuals. The vulnerability was discovered on July 16, 2026, after remaining exploitable since October 2025. Meanwhile, Microsoft's 2026 Digital Defense Report concluded that threat actors currently hold an advantage over defenders in weaponizing artificial intelligence, with attackers using AI to accelerate vulnerability discovery and malware development. The assessment highlights the growing gap between offensive and defensive AI applications in active cyber operations. Bitget cryptocurrency exchange confirmed it has frozen only a minimal portion of the $387.5 million stolen in last week's zero-day attack and does not expect significant recovery of the stolen funds.

Sources: 404 Media · NL Times · Help Net Security · Bleeping Computer

📌 Pinned

*

https:betanews.comMar 5

Inside a cyberattack: How hackers steal data

The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...

https://helpnetsecurity.comOct 1

Pentagon Data Breach Exposes Personal Information of 3 Million Service Members

The Pentagon's Defense Manpower Data Center (DMDC) is notifying millions of military personnel of a data breach affecting 2.76 million living individu...

https://techcrunch.comOct 1

Hackers stole millions of US military personnel records during months-long data breach

The Department of Defense notified millions of current and former U.S. military personnel that their personal information had been stolen in a ...

https://npr.orgSep 30

FBI Job Portal Data Breach - Hackers Access Agents and Staffers Information

The FBI addresses a massive data breach of its job portal where hackers stole personal information of most FBI agents and staffers including applicant...

https://theconversation.comSep 30

The 'War Games' problem: Computer science has long understood what it takes to keep AI ...

bots going rogue and independently spearheading a cyberattack.” Name-brand artificial intelligence agents have been on a hacking spree in 2026.

https://thehackernews.comSep 30

Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution

Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that ...

https://www.foxbusiness.comSep 29

Nvidia launches security platform to keep AI agents from going rogue - Fox Business

Nvidia released open source AI security tools it says could have stopped the Hugging Face hack by rogue OpenAI agents, offering sandbox and ...

https://wjactv.comSep 29

Feds: Two former Penn State students plead guilty in nationwide hacking, fraud scheme

Prosecutors say a second former Penn State student has admitted to his involvement in a federal investigation into nationwide computer hacking.

https://www.theguardian.comSep 29

OpenAI 'sorry and working to do better' after hack of Medicare and other Australian ...

Artificial intelligence firm to front parliament as it apologises to Australians for agent attack.


Updated daily