Vulnerabilities
Fortinet is warning customers about a critical zero-day in FortiMail that attackers are already exploiting. Tracked as CVE-2026-104286 with a CVSS score of 9.8 (Critical), the flaw lets unauthenticated attackers write arbitrary files to affected devices using crafted HTTP or HTTPS requests — no login required. Fortinet rates the impact as code execution.
CISA added the flaw to its Known Exploited Vulnerabilities catalog on October 1, the same day Fortinet published its advisory, and gave federal civilian agencies until October 4 to act. Four branches are affected: 8.0.0 to 8.0.1, 7.6.0 to 7.6.6, 7.4.0 to 7.4.8, and 7.2.0 to 7.2.9. None has a fixed build yet.
Fortinet lists 8.0.2, 7.6.7, and 7.4.9 as upcoming releases, and tells 7.2 users to move to branch 7.4 or later. Every 7.4 build shipped so far sits inside the affected range, so that route only helps once 7.4.9 arrives.
Until then, disable IBE support from the CLI, or cut the management interface off the internet. Then go hunting. Fortinet published hashes for seven added or modified files, including a planted ld.so.preload, two attacker IPs (79.141.169.187 and 45.129.0.192), and a log entry adding an archive account named archive234 that reports to the first. The IPs alone won't tell you whether a box is already compromised.
Source: Cybersecurity News
Fortinet is warning customers about a critical zero-day in FortiMail that attackers are already exploiting. Tracked as CVE-2026-104286 with a CVSS score of 9.8 (Critical), the flaw lets unauthenticated attackers write arbitrary files to affected devices using crafted HTTP or HTTPS requests — no login required. Fortinet rates the impact as code execution.
CISA added the flaw to its Known Exploited Vulnerabilities catalog on October 1, the same day Fortinet published its advisory, and gave federal civilian agencies until October 4 to act. Four branches are affected: 8.0.0 to 8.0.1, 7.6.0 to 7.6.6, 7.4.0 to 7.4.8, and 7.2.0 to 7.2.9. None has a fixed build yet.
Fortinet lists 8.0.2, 7.6.7, and 7.4.9 as upcoming releases, and tells 7.2 users to move to branch 7.4 or later. Every 7.4 build shipped so far sits inside the affected range, so that route only helps once 7.4.9 arrives.
Until then, disable IBE support from the CLI, or cut the management interface off the internet. Then go hunting. Fortinet published hashes for seven added or modified files, including a planted ld.so.preload, two attacker IPs (79.141.169.187 and 45.129.0.192), and a log entry adding an archive account named archive234 that reports to the first. The IPs alone won't tell you whether a box is already compromised.
Source: Cybersecurity News
The Dutch Institute for Vulnerability Disclosure was hacked on September 21 in what it calls an agentic AI-powered attack, a first for the organization. Attackers chained two Zammad zero-days — CVE-2026-102489, a session hijack giving remote code execution as the zammad user, and CVE-2026-102490, a local escalation to root — moving from one to the other in seconds.
The two flaws cover different ground. CVE-2026-102489 affects Zammad 6.3.0 through 6.5.4, and sits in 7.0.0 to 7.1.3 without being exploitable there. CVE-2026-102490 reaches every release from v1.5.0 to v7.1.0-alpha, so moving to version 7 closes the first flaw and not the second. DIVD still advises upgrading or taking instances offline.
Network segmentation stopped the attackers going deeper, though they pivoted to other services and exfiltrated data — The Register reports email addresses were taken. DIVD notes the agent left visible traces of its work, and warns that a more careful attacker using the same approach would be far harder to spot.
Source: SecurityWeek
The Dutch Institute for Vulnerability Disclosure was hacked on September 21 in what it calls an agentic AI-powered attack, a first for the organization. Attackers chained two Zammad zero-days — CVE-2026-102489, a session hijack giving remote code execution as the zammad user, and CVE-2026-102490, a local escalation to root — moving from one to the other in seconds.
The two flaws cover different ground. CVE-2026-102489 affects Zammad 6.3.0 through 6.5.4, and sits in 7.0.0 to 7.1.3 without being exploitable there. CVE-2026-102490 reaches every release from v1.5.0 to v7.1.0-alpha, so moving to version 7 closes the first flaw and not the second. DIVD still advises upgrading or taking instances offline.
Network segmentation stopped the attackers going deeper, though they pivoted to other services and exfiltrated data — The Register reports email addresses were taken. DIVD notes the agent left visible traces of its work, and warns that a more careful attacker using the same approach would be far harder to spot.
Source: SecurityWeek
Apple shipped emergency updates on September 28, 2026 to fix CVE-2026-86950, an out-of-bounds write in CoreGraphics that lets a maliciously crafted file run arbitrary code on the device. The fixes landed in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1, covering iPhone 11 and later along with iPad models back to the third-generation iPad Air.
Apple says the issue "may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27." Meta Product Security reported the bug, and no CVSS score has been published. Update through Settings > General > Software Update.
Source: Cybersecurity News
Apple shipped emergency updates on September 28, 2026 to fix CVE-2026-86950, an out-of-bounds write in CoreGraphics that lets a maliciously crafted file run arbitrary code on the device. The fixes landed in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1, covering iPhone 11 and later along with iPad models back to the third-generation iPad Air.
Apple says the issue "may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27." Meta Product Security reported the bug, and no CVSS score has been published. Update through Settings > General > Software Update.
Source: Cybersecurity News
Citrix has patched two actively exploited flaws in NetScaler ADC and NetScaler Gateway, both rated CVSS 9.5 on the v4.0 scale and both exploitable without authentication. CVE-2026-88771 is an input validation flaw affecting every deployment by default, while CVE-2026-88772 is a memory overflow that hits systems with DTLS enabled, the default for VPN servers. Citrix found both while investigating incidents in customer environments.
CISA added both to its Known Exploited Vulnerabilities catalog on September 27, the day the patches shipped. Six further flaws were fixed alongside them, including an HTTP request smuggling bug rated 9.3. The fixed builds are 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, and 13.1-37.279 FIPS/NDcPP. Several national agencies, including the Dutch NCSC, told organisations to shut appliances down until they could patch.
Patching closes the holes but leaves any attacker persistence in place. Preserve logs and snapshots before updating, run Citrix's IOC scan, and rotate every password, secret, and certificate stored on or used through the appliance. watchTowr warns the IOCs do not cover every technique, so a clean scan is not proof an appliance is clean.
Source: Cyber Security News
Citrix has patched two actively exploited flaws in NetScaler ADC and NetScaler Gateway, both rated CVSS 9.5 on the v4.0 scale and both exploitable without authentication. CVE-2026-88771 is an input validation flaw affecting every deployment by default, while CVE-2026-88772 is a memory overflow that hits systems with DTLS enabled, the default for VPN servers. Citrix found both while investigating incidents in customer environments.
CISA added both to its Known Exploited Vulnerabilities catalog on September 27, the day the patches shipped. Six further flaws were fixed alongside them, including an HTTP request smuggling bug rated 9.3. The fixed builds are 14.1-73.37, 13.1-64.23, 14.1-73.37 FIPS, and 13.1-37.279 FIPS/NDcPP. Several national agencies, including the Dutch NCSC, told organisations to shut appliances down until they could patch.
Patching closes the holes but leaves any attacker persistence in place. Preserve logs and snapshots before updating, run Citrix's IOC scan, and rotate every password, secret, and certificate stored on or used through the appliance. watchTowr warns the IOCs do not cover every technique, so a clean scan is not proof an appliance is clean.
Source: Cyber Security News
CISA added CVE-2026-5430 to its Known Exploited Vulnerabilities catalog on September 24, with a September 27 federal deadline that has now passed. WSO2 describes the flaw as a JWT authentication bypass: a token signed with an unsupported algorithm is accepted, granting unauthorised account access up to administrator level. It is rated CVSS 10.0, or 9.8 on single-tenant deployments, and needs no credentials.
watchTowr caught forged JWT tokens aimed at the flaw on September 13, eleven days before the KEV listing and more than four months after WSO2 disclosed it on May 3. Affected are API Control Plane, Traffic Manager, and Universal Gateway on 4.5.0 and 4.6.0, plus API Manager from 4.1.0 through 4.6.0. No workaround exists, so apply the updates in advisory WSO2-2026-5328 and review authentication logs back to September 13 for unexpected administrative accounts.
Source: Cybersecurity News
CISA added CVE-2026-5430 to its Known Exploited Vulnerabilities catalog on September 24, with a September 27 federal deadline that has now passed. WSO2 describes the flaw as a JWT authentication bypass: a token signed with an unsupported algorithm is accepted, granting unauthorised account access up to administrator level. It is rated CVSS 10.0, or 9.8 on single-tenant deployments, and needs no credentials.
watchTowr caught forged JWT tokens aimed at the flaw on September 13, eleven days before the KEV listing and more than four months after WSO2 disclosed it on May 3. Affected are API Control Plane, Traffic Manager, and Universal Gateway on 4.5.0 and 4.6.0, plus API Manager from 4.1.0 through 4.6.0. No workaround exists, so apply the updates in advisory WSO2-2026-5328 and review authentication logs back to September 13 for unexpected administrative accounts.
Source: Cybersecurity News
A WordPress core vulnerability, CVE-2026-87902, came under active attack within hours of its patch. Patchstack saw exploitation begin on September 22, 2026, the same day WordPress 7.1.2 shipped, quickly escalating from reconnaissance to attempts at remote code execution. The flaw affects versions 4.7.0 through 7.1.1 and carries a CVSS 4.0 score of 9.2 (Critical). No account or user interaction is needed.
Attackers exploit a path traversal bug in WordPress's page-template function to load local PHP files, then abuse PEAR's pearcmd.php to write malicious scripts to server temp directories. The inclusion needs an active theme with a top-level directory starting with "page-". Code execution also needs PEAR with PHP's register_argc_argv setting on, which is the default in official PHP Docker images and cPanel below PHP 8.5.
Automated scanning tools are now accelerating attacks at scale. Update immediately to WordPress 7.1.2 or your branch's patched release. Fixes run from 7.0.6, 6.9.9, and 6.8.10 back to 4.7.37.
If you can't patch yet, block traversal sequences in the pagename parameter, since no real page slug contains one. Unexpected PHP files in /tmp or /var/tmp mean an attempt succeeded, so treat the host as compromised.
Source: Cybersecurity News
A WordPress core vulnerability, CVE-2026-87902, came under active attack within hours of its patch. Patchstack saw exploitation begin on September 22, 2026, the same day WordPress 7.1.2 shipped, quickly escalating from reconnaissance to attempts at remote code execution. The flaw affects versions 4.7.0 through 7.1.1 and carries a CVSS 4.0 score of 9.2 (Critical). No account or user interaction is needed.
Attackers exploit a path traversal bug in WordPress's page-template function to load local PHP files, then abuse PEAR's pearcmd.php to write malicious scripts to server temp directories. The inclusion needs an active theme with a top-level directory starting with "page-". Code execution also needs PEAR with PHP's register_argc_argv setting on, which is the default in official PHP Docker images and cPanel below PHP 8.5.
Automated scanning tools are now accelerating attacks at scale. Update immediately to WordPress 7.1.2 or your branch's patched release. Fixes run from 7.0.6, 6.9.9, and 6.8.10 back to 4.7.37.
If you can't patch yet, block traversal sequences in the pagename parameter, since no real page slug contains one. Unexpected PHP files in /tmp or /var/tmp mean an attempt succeeded, so treat the host as compromised.
Source: Cybersecurity News
A maximum-severity GitLab vulnerability (CVE-2026-85706, CVSS 10.0 Critical) was being actively exploited within a day of its September 10 disclosure. The flaw lets unauthenticated attackers read arbitrary files from self-managed GitLab CE/EE servers — including credentials, CI/CD secrets, and SSH configurations — on any instance hosting at least one public project.
watchTowr saw probing on September 11 escalate the same day to full file exfiltration, and public proof-of-concept code is now circulating. CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 11, giving federal agencies until September 14 to patch.
Self-managed instances on 19.1 through 19.3 should update to 19.1.8, 19.2.6, or 19.3.2; anyone on 18.7 through 19.0 should check GitLab's advisory for their branch. If patching isn't possible, remove all public project access now, then review repository commits API logs for unauthenticated requests.
Source: Dark Reading
A maximum-severity GitLab vulnerability (CVE-2026-85706, CVSS 10.0 Critical) was being actively exploited within a day of its September 10 disclosure. The flaw lets unauthenticated attackers read arbitrary files from self-managed GitLab CE/EE servers — including credentials, CI/CD secrets, and SSH configurations — on any instance hosting at least one public project.
watchTowr saw probing on September 11 escalate the same day to full file exfiltration, and public proof-of-concept code is now circulating. CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 11, giving federal agencies until September 14 to patch.
Self-managed instances on 19.1 through 19.3 should update to 19.1.8, 19.2.6, or 19.3.2; anyone on 18.7 through 19.0 should check GitLab's advisory for their branch. If patching isn't possible, remove all public project access now, then review repository commits API logs for unauthenticated requests.
Source: Dark Reading
Patrick Wardle, founder of Objective-See, disclosed a zero-day in Meta's Muse, a macOS AI assistant Meta markets around a dedicated secure VM, protected credential storage, and user-controlled permissions. An undocumented preference called endo_voyager_dictation_endpoint can be rewritten by any process running as the logged-in user, redirecting Muse's dictation traffic to an attacker-controlled server.
From there an attacker reads dictated prompts and audio, injects instructions Muse trusts and acts on, and lifts the Muse session token. Wardle's proof-of-concept, not-a-mused, used a stolen token to make the Muse app on his iPhone report precise location, run Bluetooth scans, and list smart-home commands. No CVE or CVSS has been assigned, and no in-the-wild exploitation has been reported.
Exploitation needs code execution as the user first, so existing malware is the delivery route rather than a remote attack. Meta shipped a hot-fix roughly 16 hours after Wardle went public on September 21, and he confirmed it the next day. If you ran Muse before the fix, update it, revoke unnecessary permissions, and treat connected accounts as exposed.
Source: Cybersecurity News
Patrick Wardle, founder of Objective-See, disclosed a zero-day in Meta's Muse, a macOS AI assistant Meta markets around a dedicated secure VM, protected credential storage, and user-controlled permissions. An undocumented preference called endo_voyager_dictation_endpoint can be rewritten by any process running as the logged-in user, redirecting Muse's dictation traffic to an attacker-controlled server.
From there an attacker reads dictated prompts and audio, injects instructions Muse trusts and acts on, and lifts the Muse session token. Wardle's proof-of-concept, not-a-mused, used a stolen token to make the Muse app on his iPhone report precise location, run Bluetooth scans, and list smart-home commands. No CVE or CVSS has been assigned, and no in-the-wild exploitation has been reported.
Exploitation needs code execution as the user first, so existing malware is the delivery route rather than a remote attack. Meta shipped a hot-fix roughly 16 hours after Wardle went public on September 21, and he confirmed it the next day. If you ran Muse before the fix, update it, revoke unnecessary permissions, and treat connected accounts as exposed.
Source: Cybersecurity News
Cisco has patched CVE-2026-76460, an authentication bypass in Identity Services Engine rated CVSS 10.0 that attackers were already exploiting. Insufficient authentication control on an API endpoint lets a remote attacker send a crafted request, reach the web management interface, and run commands as root with no credentials and no user interaction. Cisco ISE and ISE-PIC are both affected, regardless of configuration.
CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 16 and gave federal agencies until September 19 to remediate, a deadline that has now passed. Fixed builds differ by branch: Patch 12 for 3.1, Patch 11 for 3.2, Patch 12 for 3.3, Patch 7 for 3.4, and Patch 4 for 3.5. Version 3.0 is unsupported and receives no fix.
A compromised ISE can impersonate devices, disable access controls, and open the rest of the network. Cisco says no workaround addresses the flaw, though infrastructure access control lists restricting management and control plane traffic limit remote exploitation until you patch. Check the ISE access.log for suspicious usernames, and treat a clean result carefully — root access lets an attacker remove the traces.
Source: Dark Reading
Cisco has patched CVE-2026-76460, an authentication bypass in Identity Services Engine rated CVSS 10.0 that attackers were already exploiting. Insufficient authentication control on an API endpoint lets a remote attacker send a crafted request, reach the web management interface, and run commands as root with no credentials and no user interaction. Cisco ISE and ISE-PIC are both affected, regardless of configuration.
CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 16 and gave federal agencies until September 19 to remediate, a deadline that has now passed. Fixed builds differ by branch: Patch 12 for 3.1, Patch 11 for 3.2, Patch 12 for 3.3, Patch 7 for 3.4, and Patch 4 for 3.5. Version 3.0 is unsupported and receives no fix.
A compromised ISE can impersonate devices, disable access controls, and open the rest of the network. Cisco says no workaround addresses the flaw, though infrastructure access control lists restricting management and control plane traffic limit remote exploitation until you patch. Check the ISE access.log for suspicious usernames, and treat a clean result carefully — root access lets an attacker remove the traces.
Source: Dark Reading
A newly disclosed flaw in Steam's Windows Client Service lets a standard local user escalate to full NT AUTHORITY\SYSTEM privileges with no admin credentials, no UAC prompt, and no game running. Exploitation needs code execution as an ordinary user and a running Steam client, which counts even when Steam sits idle at the login screen.
Researcher KillaBoi published a proof-of-concept called BrokenPipe on September 14, targeting steamservice.exe. Steam's service accepts a caller-controlled installation root that Valve's signed install script does not cover, so an attacker relocates a launcher to an unprotected path and has the privileged service execute it. No signature is forged or modified.
KillaBoi reportedly notified Valve in March 2026 and says the HackerOne report was marked a duplicate, which prompted the public release. No CVE, CVSS score, or Valve advisory exists, and Valve has not responded to press enquiries. The exploit was validated against Steam 10.96.30.42 on 64-bit Windows 10 and 11.
With no patch available, mitigation is all you have. Inventory Steam installations, remove the client where it isn't needed, and alert on unusual steamservice.exe child processes and on executables running as SYSTEM from user-writable directories.
Source: Cybersecurity News
A newly disclosed flaw in Steam's Windows Client Service lets a standard local user escalate to full NT AUTHORITY\SYSTEM privileges with no admin credentials, no UAC prompt, and no game running. Exploitation needs code execution as an ordinary user and a running Steam client, which counts even when Steam sits idle at the login screen.
Researcher KillaBoi published a proof-of-concept called BrokenPipe on September 14, targeting steamservice.exe. Steam's service accepts a caller-controlled installation root that Valve's signed install script does not cover, so an attacker relocates a launcher to an unprotected path and has the privileged service execute it. No signature is forged or modified.
KillaBoi reportedly notified Valve in March 2026 and says the HackerOne report was marked a duplicate, which prompted the public release. No CVE, CVSS score, or Valve advisory exists, and Valve has not responded to press enquiries. The exploit was validated against Steam 10.96.30.42 on 64-bit Windows 10 and 11.
With no patch available, mitigation is all you have. Inventory Steam installations, remove the client where it isn't needed, and alert on unusual steamservice.exe child processes and on executables running as SYSTEM from user-writable directories.
Source: Cybersecurity News