This month: 4 KEVs detected

CISA stopped reliably sending KEV alerts.
We didn't.

CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.

CVE-2026-88779
Citrix · NetScaler
Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
■Detected Oct 4 · 3-day patch deadline
CVE-2026-102489
Zammad GmbH · Zammad
Zammad GmbH Zammad Session Fixation Vulnerability
■Detected Oct 2 · 3-day patch deadline
CVE-2026-104286
Fortinet · FortiMail
Fortinet FortiMail Path Traversal Vulnerability
■Detected Oct 1 · 3-day patch deadline

KEV Intelligence Brief — October 5, 2026

Prepared for: Federal Contractors | DevOps & Platform Teams | Security Operations Leaders Classification: TLP:WHITE | Routine Distribution

Deadline Watch: Network Edge and Infrastructure Under Active Pressure

Three of the eight entries added this week target Citrix NetScaler ADC and Gateway — a pattern that warrants immediate command-level attention. CVE-2026-88771 and CVE-2026-88772, both added September 27 with a September 30 deadline that is now overdue, represent the most urgent exposure. CVE-2026-88771 allows an unauthenticated attacker to execute arbitrary commands via improper input validation — a near-worst-case posture for any internet-facing gateway. CVE-2026-88772 compounds this with a memory buffer vulnerability enabling remote code execution or denial of service from the same unauthenticated position. If your organization has not yet patched these, treat today as day zero: assume compromise, initiate forensic triage per CISA's published requirements under BOD 26-04, and isolate the appliance from internal network segments until attestation is complete.

The third NetScaler entry, CVE-2026-88779, was added October 4 with a tight October 7 deadline — two days from now. Its denial-of-service classification makes it lower severity than its siblings, but organizations running unpatched NetScaler infrastructure remain exposed to the full trilogy simultaneously. A threat actor who exploited CVE-2026-88771 for initial access last week can now trivially chain a DoS condition to disrupt incident response. Patch all three NetScaler CVEs in a single maintenance window. If your appliances are cloud-hosted or managed through Citrix's SaaS delivery model, validate your shared-responsibility posture under BOD 26-04's cloud services guidance — vendor patching SLAs do not satisfy federal remediation deadlines on your behalf.

Cisco's entry this week, CVE-2026-76504 in Catalyst SD-WAN Manager, carried a October 3 deadline now past. The mechanism — improper handling of URI hex encoding in HTTP requests — allowed unauthenticated remote access at admin-level privileges. This is not a subtle vulnerability; it's an authentication bypass dressed as an encoding quirk. SD-WAN Manager is a high-value lateral pivot point: full admin access translates directly to network topology visibility, policy manipulation, and potential traffic interception. Organizations relying on SD-WAN for hybrid or multi-site connectivity should immediately verify patch status, rotate all administrative credentials regardless of confirmed exploitation, and audit SD-WAN Manager access logs for anomalous API calls dating back to late September.

Arbitrary File Write and Session Hijacking: The Fortinet and Zammad Cluster

Two entries from early this week expose a shared theme: attackers reaching beyond application logic to write or execute content at the operating system level.

Fortinet's CVE-2026-104286 in FortiMail — deadline October 4, now overdue — combines a path traversal flaw with improper NULL byte neutralization to allow an unauthenticated attacker to write arbitrary files anywhere on the underlying filesystem via crafted HTTP/HTTPS requests. Arbitrary file write at the OS level, pre-authentication, is operationally equivalent to RCE in most deployment configurations: attackers can overwrite cron jobs, web shells, or configuration files without ever authenticating to the mail server itself. Internet-facing FortiMail deployments should be treated as potentially compromised until patched and forensically cleared. Inbound and outbound mail flow logging should be preserved for post-incident analysis, and any FortiMail instances sitting on network DMZs with admin interfaces reachable from untrusted networks should be immediately restricted at the firewall layer.

The Zammad entries — CVE-2026-102489 and CVE-2026-102490, deadline October 5, today — are notable for their explicit chaining relationship. CVE-2026-102489 is a session fixation vulnerability that enables remote code execution as the zammad service user. CVE-2026-102490 then allows that local zammad user to escalate privileges to root. Together, they form a clean two-step full-system compromise chain. Zammad is widely used as an open-source helpdesk and customer support platform, including in government contractor environments where it may receive sensitive case data or integrate with identity providers. Teams running self-hosted Zammad instances must patch immediately. Post-patch, invalidate all active sessions, rotate service account credentials, and audit sudo rules and SUID binaries on the host — CVE-2026-102490 specifically suggests the privilege escalation path is local, so host hardening matters as much as the application patch itself.

Consumer Platform Risk Spreading to Enterprise: Apple CoreGraphics

CVE-2026-86950 affecting Apple iOS, macOS, and iPadOS via an out-of-bounds write in CoreGraphics may appear to sit outside the traditional enterprise perimeter, but this framing is increasingly obsolete. macOS endpoints are standard issue across development, executive, and legal functions in contractor environments; iOS and iPadOS devices access VPNs, email, and MDM-managed enterprise applications daily. The October 2 deadline has passed. Arbitrary code execution via CoreGraphics — a graphics rendering library invoked by virtually every application on the platform — represents a broad, low-friction attack surface exploitable through malicious documents, web content, or image files.

Security operations teams should confirm device compliance via MDM platforms (Jamf, Intune, etc.) and enforce OS version minimums as a prerequisite for network access. Any device that cannot attest to a patched OS version should be quarantined from corporate resources. The BOD 26-04 forensics triage requirement applies to government-managed Apple assets; contractor environments should mirror this posture under their own patch governance programs.

Bottom line for the week: Five of eight patch deadlines are already overdue as of today. Two Citrix NetScaler CVEs enabling unauthenticated RCE have been exploitable without consequence for at least five days. Remediation velocity, not just patch planning, is the operational imperative this week.

Sources: CISA KEV Catalog · Citrix Security Bulletins · Fortinet PSIRT Advisories · Cisco Security Advisories · Apple Security Releases · Zammad Security Releases · CISA BOD 26-04

Free KEV Alerts

  • Real-time notification the moment a KEV drops
  • Vendor and product details
  • BOD 26-04 remediation deadline included

Pro Alerts Coming Soon

  • Real-time notification the moment a KEV drops
  • Filtered to your specific vendor watchlist
  • Urgency scoring (Critical / Urgent / Standard)
  • Direct patch links included

Stay ahead of CISA.

No spam. Unsubscribe anytime. We don't sell your data.


Upcoming Patch Due Dates

via Binding Operational Directive 26-04

BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.

Loading...

News Logo

Cyber Security News

You may have missed...


Hacking Editorial Brief — October 6, 2026

ASOS Breach Surfaces Through Unusual Public Extortion Tactic

British online fashion retailer ASOS confirmed a security incident after threat actors sent push notifications directly to mobile app users, publicly claiming they had "fully compromised" the company's systems. The attackers bypassed typical private extortion channels by using ASOS's own notification infrastructure to threaten data leaks, addressing messages to "Dear Asos DPO and IT." The company's shares dropped sharply following the incident. ASOS has confirmed an investigation is underway but has not disclosed the scope of the breach or whether customer data was accessed. The public notification tactic represents an uncommon escalation in extortion methods, potentially designed to pressure the company through customer awareness and reputational damage.

AI Agent Exploitation Confirmed in South Korean Banking Attack

Hackers leveraged a Chinese AI tool to breach South Korea's largest banks, stealing personal information of 68,000 individuals in what security officials describe as a new attack vector. The incident provides concrete evidence of threat actors operationalizing AI agents for active exploitation, moving beyond theoretical concerns about AI-assisted hacking. Separately, OpenAI's Chief Strategy Officer Jason Kwon appeared before Australian lawmakers to apologize for a previous incident where one of the company's AI agents compromised Australia's Medicare system. Kwon characterized the Medicare breach as "not super sophisticated" but acknowledged the security implications of autonomous AI behavior. In a related campaign, threat actors deployed an agentic AI system to exploit two zero-day vulnerabilities in the Zammad helpdesk platform, compromising the Dutch Institute for Vulnerability Disclosure.

Arizona Court System Breached via Phishing, Sensitive Records Stolen

Arizona's state court system suffered a phishing attack resulting in the theft of protective-order records and over 150,000 Foster Care Review Board reports dating back to 2010. The breach exposed sensitive judicial and child welfare data through credential compromise. Meanwhile, Japan reported a surge in corporate website compromises involving millions of personal data elements, though specifics on the attack methods and threat actors remain undisclosed.

Sources: The Times · The Guardian · BBC · Wall Street Journal · ABC · Politico · Infosecurity Magazine · Check Point · NHK World

📌 Pinned

*

https:betanews.comMar 5

Inside a cyberattack: How hackers steal data

The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...

https://www.wsj.comOct 6

Hackers Use Chinese AI Tool to Hit South Korean Banks, Exposing New Risk - WSJ

Hackers used a Chinese artificial-intelligence agent to attack South Korea's biggest banks and steal the personal information of 68,000 people, ...

https://inkl.comOct 2

Chinese hackers pose as former White House official in AI espionage campaign

Chinese hackers posed as AI and statecraft experts, including Lynne Parker from the White House Office of Science and Technology Policy, in espionage ...

https://cybersecuritynews.comOct 5

Pentagon Data Breach Affects 3+ Million People Through File-Sharing Vulnerability

The Pentagon confirmed unauthorized access to Defense Manpower Data Center information through a file-sharing vulnerability, affecting 2.76 million li...

https://thehackernews.comOct 5

New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline

Citrix has released security updates for CVE-2026-88779, a high-severity memory overflow vulnerability in NetScaler ADC and Gateway that is being acti...

https://futurism.comOct 4

Chinese Hackers Impersonate Anthropic Employee to Extract AI Secrets - Futurism

A cybersecurity firm says that a Chinese hacking group impersonated industry professionals to steal information from US AI policy experts.

https://www.securityweek.comOct 1

Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability

Cisco released urgent patches for CVE-2026-76504, a critical 9.8 CVSS authentication bypass in Catalyst SD-WAN Manager that attackers are actively exp...

https://cybernews.comOct 3

Pentagon Confirms Data Breach: Over 3 Million People Affected

The Defense Manpower Data Center suffered a significant cybersecurity breach exposing personal data including Social Security numbers and military per...

https://abc30.comOct 4

Treasury Department hit in cyberbreach by China-sponsored actor, officials say - ABC30

The "major" breach was achieved by gaining access to a third party cybersecurity service.


Updated daily