CISA stopped reliably sending KEV alerts.
We didn't.
CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.
KEV Intelligence Brief — October 5, 2026
Prepared for: Federal Contractors | DevOps & Platform Teams | Security Operations Leaders Classification: TLP:WHITE | Routine Distribution
Deadline Watch: Network Edge and Infrastructure Under Active Pressure
Three of the eight entries added this week target Citrix NetScaler ADC and Gateway — a pattern that warrants immediate command-level attention. CVE-2026-88771 and CVE-2026-88772, both added September 27 with a September 30 deadline that is now overdue, represent the most urgent exposure. CVE-2026-88771 allows an unauthenticated attacker to execute arbitrary commands via improper input validation — a near-worst-case posture for any internet-facing gateway. CVE-2026-88772 compounds this with a memory buffer vulnerability enabling remote code execution or denial of service from the same unauthenticated position. If your organization has not yet patched these, treat today as day zero: assume compromise, initiate forensic triage per CISA's published requirements under BOD 26-04, and isolate the appliance from internal network segments until attestation is complete.
The third NetScaler entry, CVE-2026-88779, was added October 4 with a tight October 7 deadline — two days from now. Its denial-of-service classification makes it lower severity than its siblings, but organizations running unpatched NetScaler infrastructure remain exposed to the full trilogy simultaneously. A threat actor who exploited CVE-2026-88771 for initial access last week can now trivially chain a DoS condition to disrupt incident response. Patch all three NetScaler CVEs in a single maintenance window. If your appliances are cloud-hosted or managed through Citrix's SaaS delivery model, validate your shared-responsibility posture under BOD 26-04's cloud services guidance — vendor patching SLAs do not satisfy federal remediation deadlines on your behalf.
Cisco's entry this week, CVE-2026-76504 in Catalyst SD-WAN Manager, carried a October 3 deadline now past. The mechanism — improper handling of URI hex encoding in HTTP requests — allowed unauthenticated remote access at admin-level privileges. This is not a subtle vulnerability; it's an authentication bypass dressed as an encoding quirk. SD-WAN Manager is a high-value lateral pivot point: full admin access translates directly to network topology visibility, policy manipulation, and potential traffic interception. Organizations relying on SD-WAN for hybrid or multi-site connectivity should immediately verify patch status, rotate all administrative credentials regardless of confirmed exploitation, and audit SD-WAN Manager access logs for anomalous API calls dating back to late September.
Arbitrary File Write and Session Hijacking: The Fortinet and Zammad Cluster
Two entries from early this week expose a shared theme: attackers reaching beyond application logic to write or execute content at the operating system level.
Fortinet's CVE-2026-104286 in FortiMail — deadline October 4, now overdue — combines a path traversal flaw with improper NULL byte neutralization to allow an unauthenticated attacker to write arbitrary files anywhere on the underlying filesystem via crafted HTTP/HTTPS requests. Arbitrary file write at the OS level, pre-authentication, is operationally equivalent to RCE in most deployment configurations: attackers can overwrite cron jobs, web shells, or configuration files without ever authenticating to the mail server itself. Internet-facing FortiMail deployments should be treated as potentially compromised until patched and forensically cleared. Inbound and outbound mail flow logging should be preserved for post-incident analysis, and any FortiMail instances sitting on network DMZs with admin interfaces reachable from untrusted networks should be immediately restricted at the firewall layer.
The Zammad entries — CVE-2026-102489 and CVE-2026-102490, deadline October 5, today — are notable for their explicit chaining relationship. CVE-2026-102489 is a session fixation vulnerability that enables remote code execution as the zammad service user. CVE-2026-102490 then allows that local zammad user to escalate privileges to root. Together, they form a clean two-step full-system compromise chain. Zammad is widely used as an open-source helpdesk and customer support platform, including in government contractor environments where it may receive sensitive case data or integrate with identity providers. Teams running self-hosted Zammad instances must patch immediately. Post-patch, invalidate all active sessions, rotate service account credentials, and audit sudo rules and SUID binaries on the host — CVE-2026-102490 specifically suggests the privilege escalation path is local, so host hardening matters as much as the application patch itself.
Consumer Platform Risk Spreading to Enterprise: Apple CoreGraphics
CVE-2026-86950 affecting Apple iOS, macOS, and iPadOS via an out-of-bounds write in CoreGraphics may appear to sit outside the traditional enterprise perimeter, but this framing is increasingly obsolete. macOS endpoints are standard issue across development, executive, and legal functions in contractor environments; iOS and iPadOS devices access VPNs, email, and MDM-managed enterprise applications daily. The October 2 deadline has passed. Arbitrary code execution via CoreGraphics — a graphics rendering library invoked by virtually every application on the platform — represents a broad, low-friction attack surface exploitable through malicious documents, web content, or image files.
Security operations teams should confirm device compliance via MDM platforms (Jamf, Intune, etc.) and enforce OS version minimums as a prerequisite for network access. Any device that cannot attest to a patched OS version should be quarantined from corporate resources. The BOD 26-04 forensics triage requirement applies to government-managed Apple assets; contractor environments should mirror this posture under their own patch governance programs.
Bottom line for the week: Five of eight patch deadlines are already overdue as of today. Two Citrix NetScaler CVEs enabling unauthenticated RCE have been exploitable without consequence for at least five days. Remediation velocity, not just patch planning, is the operational imperative this week.
Sources: CISA KEV Catalog · Citrix Security Bulletins · Fortinet PSIRT Advisories · Cisco Security Advisories · Apple Security Releases · Zammad Security Releases · CISA BOD 26-04
Free KEV Alerts
- Real-time notification the moment a KEV drops
- Vendor and product details
- BOD 26-04 remediation deadline included
Pro Alerts Coming Soon
- Real-time notification the moment a KEV drops
- Filtered to your specific vendor watchlist
- Urgency scoring (Critical / Urgent / Standard)
- Direct patch links included
Stay ahead of CISA.
Search the KEV Catalog by Vendor or Product
Search for CVEs by vendor or product to identify known exploited vulnerabilities in your environment
Upcoming Patch Due Dates
via Binding Operational Directive 26-04
BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.
Loading...
Cyber Security News
You may have missed...
Hacking Editorial Brief — October 5, 2026
Denmark Suffers Massive National Registry Breach
Threat actors compromised Denmark's national population registry, exposing personal data of approximately 8.8 million people—exceeding the country's population of 5.9 million due to historical records. According to government statements, attackers breached the registry by first compromising a Danish company with legitimate access to the system. The exposed data includes names, addresses, and CPR social security numbers. Danish authorities characterized the incident as "extremely serious," though they have not attributed the attack or disclosed the compromised company's identity. The breach represents one of the largest government data exposures in European history relative to population size.
AI-Assisted Attacks Escalate Across South Korean Financial Sector
A coordinated hacking campaign against South Korean financial institutions has expanded from commercial banks to nonbank lenders, with investigators identifying connections to the same IP addresses across multiple incidents. Security researchers flagged the probable use of AI agents to probe for vulnerabilities in the attacks, which have impacted Shinhan Bank, savings banks, and capital companies. South Korea has recorded over 2,189 financial sector security incidents in the past five years, with AI-enabled attacks showing increased sophistication. Separately, Seoul authorities attributed a $30 million cryptocurrency theft from Upbit exchange to the North Korean Lazarus Group, highlighting continued DPRK-sponsored targeting of the region's financial infrastructure. In North Korea-related activity, the WaterPlum group is conducting ongoing social engineering campaigns posing as recruiters to deliver malware to software developers through fake job interviews.
Active Exploitation of Citrix and Kiteworks Zero-Days Targets Critical Infrastructure
Critical zero-day vulnerabilities in Citrix NetScaler ADC, NetScaler Gateway, and Kiteworks file transfer appliances are under active exploitation targeting government, financial, healthcare, and IT sectors. Separate from this campaign, researchers disclosed critical flaws in Dell Container Storage Modules that allow unauthenticated attackers to gain full administrative control of Kubernetes environments. The China-linked Warlock ransomware group has been observed exploiting SharePoint vulnerabilities to breach water utilities and telecommunications providers.
Sources: Euronews · Channel Television · KED Global · KBS World · VOA · Bleeping Computer · Rescana
*
Inside a cyberattack: How hackers steal data
The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...
Chinese Hackers Impersonate Anthropic Employee to Extract AI Secrets - Futurism
A cybersecurity firm says that a Chinese hacking group impersonated industry professionals to steal information from US AI policy experts.
Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability
Cisco released urgent patches for CVE-2026-76504, a critical 9.8 CVSS authentication bypass in Catalyst SD-WAN Manager that attackers are actively exp...
Pentagon Confirms Data Breach: Over 3 Million People Affected
The Defense Manpower Data Center suffered a significant cybersecurity breach exposing personal data including Social Security numbers and military per...
Treasury Department hit in cyberbreach by China-sponsored actor, officials say - ABC30
The "major" breach was achieved by gaining access to a third party cybersecurity service.
In Rare Move, Alleged Iranian State Hacker Extradited to US
Iranian national Amir Barati, an alleged member of the Mabna Institute charged with hacking universities and private organizations, was extradited fro...
Pentagon Data Breach Exposes Highly Sensitive Data of 3 Million People
The Pentagon's Defense Manpower Data Center was accessed by unauthorized users, exposing data of civilian and active-duty Department of Defense employ...
GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
Cybersecurity. The advisory does not say whether the flaw has been used in attacks. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ....
Pentagon Data Breach Exposes Personal Information of 3 Million Service Members
The Pentagon's Defense Manpower Data Center (DMDC) is notifying millions of military personnel of a data breach affecting 2.76 million living individu...
Updated daily
