top of page

Cybersecurity Weekly Roundup : 28 September – 5 October 2026

Writer: SOC Team
SOC Team
11 minutes ago
4 min read

1. Citrix NetScaler Zero-Days Actively Exploited in the Wild


Two critical zero-day vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway were actively exploited in attacks. Citrix confirmed the vulnerabilities after researchers observed attacks targeting vulnerable appliances. Attackers were reported deploying web shells and other malicious payloads following successful exploitation.

The vulnerabilities are tracked as CVE-2026-88771 and CVE-2026-88772. The vulnerabilities affect NetScaler appliances and can allow attackers to execute malicious code or cause denial-of-service conditions. CISA added both vulnerabilities to its Known Exploited Vulnerabilities catalogue.


CVE ID: CVE-2026-88771 and CVE-2026-88772 (CVSS 9.5)

Why It Matters: NetScaler appliances frequently sit at the network perimeter and provide remote access and application delivery services. Successful exploitation could provide attackers with access to infrastructure handling external connections into corporate environments, potentially creating a pathway to internal systems and sensitive resources.

Actions: Apply the latest Citrix security updates immediately. Review internet-facing NetScaler appliances for indicators of compromise before and after patching. Review appliance and network logs for suspicious command execution, unusual administrative activity, unexpected outbound connections and other anomalous behaviour. Where immediate patching is not possible, restrict access to trusted networks and follow Citrix's emergency mitigation guidance.


2. Fortinet FortiMail Zero-Day Exploited in the Wild


Fortinet warned that attackers were actively exploiting a critical FortiMail vulnerability. The flaw allows an unauthenticated attacker to write arbitrary files to an affected email security appliance by sending specially crafted HTTP or HTTPS requests.

Tracked as CVE-2026-104286, the vulnerability is a path-traversal flaw involving improper handling of NULL characters. Fortinet disclosed the vulnerability on 1 October 2026 and warned that exploitation was already occurring in the wild. CISA subsequently added the vulnerability to its Known Exploited Vulnerabilities catalogue.


CVE ID: CVE-2026-104286 (CVSS 9.8)

Why It Matters: FortiMail appliances sit at the email-security perimeter and process potentially sensitive communications. Successful exploitation could allow attackers to place malicious files on the appliance and potentially establish a foothold within an organisation's security infrastructure.

Actions: Apply Fortinet's security updates as soon as available. Follow Fortinet's recommended mitigation guidance if immediate patching is not possible. Review FortiMail logs and filesystem activity for suspicious files and requests. Monitor for unexpected outbound connections and investigate unusual administrative activity originating from affected appliances.


3. Cisco Catalyst SD-WAN Zero-Day Exploited in the Wild

Cisco disclosed a critical vulnerability in Catalyst SD-WAN Manager that was being actively exploited. The vulnerability allows a remote, unauthenticated attacker to bypass authentication and obtain administrative privileges on affected SD-WAN Manager systems.

Tracked as CVE-2026-76504, the vulnerability exists in the API session-based authentication mechanism and is caused by improper handling of URI encoding in HTTP requests. Cisco confirmed exploitation in September, with security reporting highlighting the vulnerability as a zero-day affecting enterprise network-management infrastructure.


CVE ID: CVE-2026-76504 (CVSS 9.8)

Why It Matters: Catalyst SD-WAN Manager provides centralised management of enterprise network infrastructure. Compromise of the management platform could give attackers administrative control over network devices and expose configurations, credentials and connected systems.

Actions: Upgrade affected Catalyst SD-WAN Manager deployments to a fixed release immediately. Restrict management access to trusted networks and authorised administrators. Review SD-WAN logs for suspicious API requests, authentication anomalies and unexpected configuration changes. Investigate unusual administrative sessions and monitor for changes to managed network devices.


4. Zammad Zero-Days Exploited in AI-Powered Attack


Two zero-day vulnerabilities in Zammad, an open-source customer-support and ticketing platform, were exploited in an attack against the Dutch Institute for Vulnerability Disclosure (DIVD). The attack demonstrated the ability of an autonomous AI agent to chain multiple vulnerabilities together without human direction at each stage.

The vulnerabilities are tracked as CVE-2026-102489 and CVE-2026-102490. The vulnerabilities allowed attackers to hijack sessions, execute commands remotely and escalate privileges to root on the affected Zammad environment.


CVE ID: CVE-2026-102489 and CVE-2026-102490 (CVSS 9.4)

Why It Matters: Ticketing and support platforms can contain sensitive information, authentication data and access to internal systems. The incident also highlights the increasing potential for AI-assisted attacks to automate vulnerability exploitation and chain multiple weaknesses together.

Actions: Upgrade affected Zammad deployments to the latest fixed release immediately. Review application and authentication logs for suspicious sessions, unexpected administrative activity and command execution. Investigate newly created files, processes and outbound connections. Where compromise is suspected, rotate credentials and secrets accessible from the affected Zammad environment.


Key Recommendations

  • Prioritise actively exploited vulnerabilities: Review exposure to CVE-2026-88771, CVE-2026-88772, CVE-2026-104286, CVE-2026-76504, CVE-2026-102489 and CVE-2026-102490 and apply available security updates as a priority.

  • Secure internet-facing infrastructure: Pay particular attention to Citrix NetScaler, FortiMail and Cisco SD-WAN Manager, as these platforms provide access to critical network and security infrastructure.

  • Hunt for post-exploitation activity: Monitor SIEM, endpoint and network telemetry for web shells, suspicious command execution, authentication anomalies, unexpected administrative activity, new files and unusual outbound connections.

  • Investigate before closing incidents: Patching removes the vulnerability but does not necessarily remove persistence established during earlier exploitation. Conduct a compromise assessment and rotate potentially exposed credentials where exploitation is suspected.

 
 
bottom of page