Between September 27 and October 2, 2026, CISA added seven CVEs to the Known Exploited Vulnerabilities catalog — each one confirmed to be under active exploitation in the wild. This batch is heavily weighted toward perimeter and identity-adjacent infrastructure: two Citrix NetScaler memory-safety and input-validation flaws, an unauthenticated remote access bug in Cisco Catalyst SD-WAN Manager, a path traversal / NULL byte injection in Fortinet FortiMail, an out-of-bounds write in Apple CoreGraphics, and a chained session-fixation-to-privilege-escalation pair in Zammad helpdesk. This is the exact vendor profile ransomware affiliates and initial access brokers farm for edge-device footholds.
Active Exploitation Intelligence
CVE-2026-102490 — Zammad Improper Privilege Management (LPE)
- What it is: An improper privilege management flaw allowing the local
zammadservice user to escalate privileges to root on the host. - Exploitation method: Local privilege escalation (LPE). Almost certainly chained with CVE-2026-102489: session fixation grants code execution as the
zammaduser, and this flaw converts that into full root control of the helpdesk server — a system that typically holds customer PII, email credentials, and internal ticketing data. - Threat actors: Attribution unknown (Ransomware: Unknown), but helpdesk compromise is a classic precursor to social-engineering-driven ransomware intrusions and Bec-style pivots.
- CVSS / PoC: Score pending at time of writing; no confirmed public PoC. CISA listing confirms real-world weaponization regardless.
- CISA action: Apply vendor mitigations per BOD 22-01, or discontinue use if mitigations are unavailable. Federal agencies face a binding remediation deadline (typically ~3 weeks from listing).
CVE-2026-102489 — Zammad Session Fixation (RCE)
- What it is: A session fixation vulnerability that can lead to remote code execution as the
zammaduser. - Exploitation method: Attacker fixes or pre-plants a session identifier, waits for a victim (typically an agent or admin) to authenticate into that session, then rides the authenticated context to execute code in the application tier. Entry point of the two-CVE Zammad chain.
- Threat actors: Unknown; exploitation confirmed by CISA.
- CVSS / PoC: Pending; no public PoC observed. Treat internet-facing Zammad portals as compromised until patched and session stores are invalidated.
- CISA action: Vendor patch required; force global session invalidation post-patch to kill fixated sessions.
CVE-2026-104286 — Fortinet FortiMail Path Traversal + NULL Byte Injection
- What it is: A path traversal combined with improper neutralization of NULL bytes, potentially allowing an unauthenticated attacker to read or write files outside intended directories.
- Exploitation method: Crafted requests with
%00sequences bypass extension/path validation, enabling arbitrary file read (credential harvesting, config theft) or file write (webshell drop, config overwrite) on the mail gateway. - Threat actors: Fortinet edge flaws are historically exploited by both nation-state clusters (Volt Typhoon-style edge persistence) and ransomware initial access brokers. Mail gateways are prized because they sit inline with all inbound email.
- CVSS / PoC: Pending; Fortinet's track record means PoC publication typically follows within days of KEV listing. Assume imminent.
- CISA action: Apply Fortinet advisory updates immediately; restrict management interface exposure.
CVE-2026-76504 — Cisco Catalyst SD-WAN Manager Hex Encoding Flaw (Unauthenticated Access)
- What it is: A hex encoding vulnerability allowing an unauthenticated, remote attacker to access an affected system.
- Exploitation method: Authentication bypass via encoding confusion — requests crafted with hex-encoded path or parameter values slip past access controls that validate only the decoded (or only the encoded) form. SD-WAN Manager compromise hands an attacker the control plane for the entire WAN fabric: config push, credential extraction, lateral movement into every branch.
- Threat actors: SD-WAN and network management planes are top-tier targets for pre-positioning actors (Volt Typhoon playbook) and ransomware operators seeking one-shot enterprise-wide reach.
- CVSS / PoC: Pending; unauthenticated remote access to a management plane should be treated as critical-by-design.
- CISA action: Patch per Cisco advisory; if patching is delayed, isolate the management interface from all untrusted networks immediately.
CVE-2026-86950 — Apple CoreGraphics Out-of-Bounds Write (iOS/iPadOS/macOS)
- What it is: An out-of-bounds write in CoreGraphics that can lead to arbitrary code execution when processing maliciously crafted image/content.
- Exploitation method: Drive-by RCE via weaponized images — delivered through iMessage, email, web content, or document previews. This class of bug is the workhorse of mercenary spyware (NSO Group / Predator-style chains) and is increasingly used for initial access against high-value executives and journalists.
- Threat actors: Apple 0-day CoreGraphics/WebKit flaws correlate strongly with commercial surveillance vendors; once n-days leak, criminal adoption follows.
- CVSS / PoC: Pending; no public PoC, but weaponized samples exist in the wild per CISA confirmation.
- CISA action: Enforce rapid OS updates across the mobile fleet; enable Lockdown Mode for at-risk users.
CVE-2026-88772 — Citrix NetScaler ADC/Gateway Buffer Bounds Violation
- What it is: Improper restriction of operations within the bounds of a memory buffer in NetScaler ADC and Gateway.
- Exploitation method: Memory corruption reachable remotely — consistent with unauthenticated RCE or denial-of-service against the gateway. NetScaler memory-safety bugs (CitrixBleed lineage) have repeatedly produced session-token theft and full appliance compromise.
- Threat actors: NetScaler flaws are among the fastest-weaponized bugs in the ransomware ecosystem — LockBit, ALPHV/BlackCat, and Medusa affiliates all have prior NetScaler tradecraft, as do Chinese state clusters.
- CVSS / PoC: Pending; expect scanning within hours and PoC within days. Assume any internet-facing, unpatched NetScaler is already being probed.
- CISA action: Patch immediately per Citrix bulletin, then kill all active/persistent sessions (
kill icaconnection -alland reboot) — patching alone does not evict stolen sessions.
CVE-2026-88771 — Citrix NetScaler Improper Input Validation
- What it is: Improper input validation allowing an unauthenticated attacker to impact the appliance (disclosed alongside CVE-2026-88772).
- Exploitation method: Crafted unauthenticated requests against gateway virtual servers; can be chained with CVE-2026-88772 for pre-auth impact or used standalone for service disruption.
- Threat actors: Same NetScaler-hungry ecosystem as above.
- CVSS / PoC: Pending; no public PoC at publication.
- CISA action: Same Citrix remediation cycle; treat the pair as a single emergency change.
Affected Organizations Assessment
- Exposed environments: Any organization running internet-facing NetScaler Gateway (VPN/VDI access), FortiMail gateways inline with inbound email, Cisco SD-WAN Manager controlling distributed sites, Zammad helpdesk portals exposed to customers, and Apple device fleets (especially BYOD and executive devices lagging on updates).
- Exposure scale: NetScaler ADC/Gateway is deployed at tens of thousands of enterprises globally, and NetScaler patch adoption historically lags — post-CitrixBleed telemetry showed weeks-long windows of mass exposure. FortiMail and SD-WAN Manager are frequently left reachable from untrusted networks despite vendor guidance. Zammad self-hosted instances are common in SMBs and MSPs, which patch slower than enterprises. Apple fleet compliance varies wildly; anything not on the latest iOS/iPadOS/macOS point release is exposed.
- Fastest-exploited sectors: Managed service providers and telecoms (SD-WAN control planes), healthcare and finance (NetScaler remote access), legal and government-adjacent organizations (helpdesk compromise for phishing infrastructure), and executive/journalist targets (Apple spyware-class bugs). Ransomware affiliates historically move on edge-device CVEs within 24–72 hours of disclosure.
Detection Engineering
The following Sigma rules target observable exploitation behaviors for the highest-risk CVEs in this batch: NetScaler pre-auth request anomalies (CVE-2026-88771/88772), FortiMail NULL-byte path traversal (CVE-2026-104286), and Zammad session-fixation-to-root chaining (CVE-2026-102489/102490).
---
title: Citrix NetScaler Gateway Pre-Auth Exploitation Attempt - CVE-2026-88771/88772
id: 4f2c9a10-7e6b-4c21-9a55-0b1f8d3e2a01
status: experimental
description: Detects suspicious unauthenticated request patterns against NetScaler ADC/Gateway virtual servers consistent with input-validation and memory-corruption probing added to CISA KEV on 2026/09/27.
author: Security Arsenal Threat Intel
logsource:
category: webserver
product: citrix
service: netscaler
detection:
selection_uri:
cs-uri-stem|contains:
- '/vpn/'
- '/logon/LogonPoint/'
- '/cgi/'
- '/oauth/'
selection_anomalies:
cs-uri-query|contains:
- '%00'
- '..'
- '%2e%2e'
- '\x'
cs-method:
- 'POST'
- 'PUT'
condition: selection_uri and selection_anomalies
falsepositives:
- Legitimate scanner or WAF health checks (validate source IP)
level: high
tags:
- attack.initial_access
- attack.t1190
- cve.2026.88771
- cve.2026.88772
date: 2026/10/02
---
title: FortiMail NULL Byte Path Traversal - CVE-2026-104286
id: 8b1d3e55-2a90-4f77-b6c4-9c0e1a7d5f02
status: experimental
description: Detects NULL byte injection and path traversal sequences in requests to FortiMail web interfaces, consistent with actively exploited CVE-2026-104286.
author: Security Arsenal Threat Intel
logsource:
category: webserver
product: fortinet
service: fortimail
detection:
selection:
cs-uri|contains:
- '%00'
- '%2500'
- '\x00'
selection_traversal:
cs-uri|contains:
- '/../'
- '%2e%2e%2f'
- '..%2f'
condition: selection or selection_traversal
falsepositives:
- Rare; encoded traversal in legitimate requests is uncommon on mail gateways
level: critical
tags:
- attack.initial_access
- attack.t1190
- attack.t1006
- cve.2026.104286
date: 2026/10/02
---
title: Zammad Service User Privilege Escalation to Root - CVE-2026-102490
id: 61c7aa92-3d4e-4b88-9e10-5f2b6c8a9d03
status: experimental
description: Detects the zammad service account spawning root-owned processes or executing privilege escalation utilities, consistent with post-exploitation chaining of CVE-2026-102489 and CVE-2026-102490.
author: Security Arsenal Threat Intel
logsource:
category: process_creation
product: linux
detection:
selection_user:
User|contains: 'zammad'
selection_suspicious:
Image|endswith:
- '/sudo'
- '/su'
- '/pkexec'
- '/bash'
- '/sh'
- '/python'
- '/python3'
- '/curl'
- '/wget'
filter_parent:
ParentImage|endswith:
- '/passenger'
- '/nginx'
condition: selection_user and selection_suspicious and not filter_parent
falsepositives:
- Zammad maintenance scripts run by administrators (tune by command line)
level: critical
tags:
- attack.privilege_escalation
- attack.t1068
- attack.execution
- cve.2026.102490
date: 2026/10/02
The KQL query below hunts across proxy/firewall telemetry for NetScaler and FortiMail exploitation indicators, plus endpoint process telemetry for the Zammad escalation chain, in Microsoft Sentinel.
// CISA KEV 2026-09-27..10-02: Hunt for exploitation of NetScaler, FortiMail, and Zammad CVEs
let KevWindow = ago(14d);
union isfuzzy=true
// NetScaler pre-auth probing: CVE-2026-88771 / CVE-2026-88772
(CommonSecurityLog
| where TimeGenerated > KevWindow
| where DeviceVendor =~ "Citrix"
| where RequestURL has_any ("/vpn/", "/logon/LogonPoint/", "/cgi/", "/oauth/")
| where RequestURL has_any ("%00", "..", "%2e%2e") or RequestMethod in ("POST","PUT")
| extend Indicator = "NetScaler pre-auth anomaly (CVE-2026-88771/88772)"
| project TimeGenerated, Indicator, SourceIP, DestinationHostName, RequestURL, RequestMethod),
// FortiMail NULL byte / traversal: CVE-2026-104286
(CommonSecurityLog
| where TimeGenerated > KevWindow
| where DeviceProduct has "FortiMail"
| where RequestURL has_any ("%00", "%2500", "/../", "%2e%2e%2f")
| extend Indicator = "FortiMail NULL-byte traversal (CVE-2026-104286)"
| project TimeGenerated, Indicator, SourceIP, DestinationHostName, RequestURL, RequestMethod),
// Zammad LPE chain: zammad user spawning shells or escalation tools: CVE-2026-102490
(DeviceProcessEvents
| where TimeGenerated > KevWindow
| where InitiatingProcessAccountName =~ "zammad"
| where FileName in~ ("sudo","su","pkexec","bash","sh","python","python3","curl","wget")
| extend Indicator = "Zammad service user escalation (CVE-2026-102490)"
| project TimeGenerated, Indicator, DeviceName, FileName, ProcessCommandLine, InitiatingProcessCommandLine)
| order by TimeGenerated desc
The following PowerShell script inventories exposed Zammad, FortiMail-adjacent hosts, and NetScaler appliances on the network, checks versions against the KEV-affected set, and validates remediation status. Run from a management host with network access to the target infrastructure.
#Requires -RunAsAdministrator
<#
.SYNOPSIS
CISA KEV 2026-10-02 inventory & remediation validation script.
Covers: Zammad (CVE-2026-102489/102490), FortiMail (CVE-2026-104286),
NetScaler (CVE-2026-88771/88772), Apple fleet spot-check (CVE-2026-86950).
#>
$ErrorActionPreference = 'Continue'
$ReportPath = ".\KEV_Inventory_$(Get-Date -Format 'yyyyMMdd_HHmmss').csv"
$Results = @()
function Add-Finding($Asset, $Product, $Version, $Status, $CVE, $Notes) {
$script:Results += [PSCustomObject]@{
Asset = $Asset; Product = $Product; DetectedVersion = $Version
Status = $Status; CVE = $CVE; Notes = $Notes; Timestamp = (Get-Date)
}
}
# ---------- 1. Zammad hosts (CVE-2026-102489 / CVE-2026-102490) ----------
Write-Host "[*] Scanning for Zammad installations..." -ForegroundColor Cyan
$ZammadHosts = @() # Populate from CMDB, or discover via package query over WinRM/SSH jump
foreach ($h in $ZammadHosts) {
$pkg = Invoke-Command -ComputerName $h -ScriptBlock {
(dpkg -l zammad 2>$null | Select-String '^ii') -replace '\s+',' '
}
if ($pkg) {
$ver = ($pkg -split ' ')[2]
$patched = [version]($ver -replace '[^0-9.].*$','') -ge [version]'6.5.2' # vendor fixed version
Add-Finding $h 'Zammad' $ver ($patched ? 'PATCHED' : 'VULNERABLE') 'CVE-2026-102489/102490' `
'If vulnerable: apt update && apt install --only-upgrade zammad; then: zammad run rails r "ActiveRecord::SessionStore::Session.delete_all" && systemctl restart zammad'
}
}
# ---------- 2. NetScaler appliances (CVE-2026-88771 / CVE-2026-88772) ----------
Write-Host "[*] Querying NetScaler appliances via NITRO API..." -ForegroundColor Cyan
$NetScalers = @('ns1.corp.example.com','ns2.corp.example.com') # Replace with real hosts
$NSCreds = Get-Credential -Message 'NetScaler nsroot credentials'
foreach ($ns in $NetScalers) {
try {
$login = Invoke-RestMethod -Method Post -Uri "https://$ns/nitro/v1/config/login" `
-Body (@{login=@{username=$NSCreds.UserName; password=$NSCreds.GetNetworkCredential().Password}} | ConvertTo-Json) `
-ContentType 'application/json' -SkipCertificateCheck
$token = $login.sessionid
$ver = (Invoke-RestMethod -Uri "https://$ns/nitro/v1/config/nsversion" `
-Headers @{Cookie="NITRO_AUTH_TOKEN=$token"} -SkipCertificateCheck).nsversion.version
# Consult Citrix advisory for exact fixed builds per train; flag anything older than advisory date
$patched = $ver -match '14\.1-5[0-9]\.|13\.1-6[0-9]\.' # placeholder for fixed builds — verify against Citrix bulletin
Add-Finding $ns 'Citrix NetScaler ADC/Gateway' $ver ($patched ? 'PATCHED' : 'VULNERABLE') 'CVE-2026-88771/88772' `
'After patching, MUST kill sessions: shell > nsconmsg -K /var/nslog/newnslog -d event | grep -i session; and reboot appliance to evict stolen session tokens.'
} catch { Add-Finding $ns 'Citrix NetScaler ADC/Gateway' 'UNKNOWN' 'QUERY-FAILED' 'CVE-2026-88771/88772' $_.Exception.Message }
}
# ---------- 3. FortiMail gateways (CVE-2026-104286) ----------
Write-Host "[*] Querying FortiMail gateways..." -ForegroundColor Cyan
$FortiMails = @('fm1.corp.example.com') # Replace with real hosts
$FmToken = 'YOUR_FORTIMAIL_API_TOKEN'
foreach ($fm in $FortiMails) {
try {
$status = Invoke-RestMethod -Uri "https://$fm/api/v1/SysStatus" `
-Headers @{Authorization="Bearer $FmToken"} -SkipCertificateCheck
$ver = $status.Version
$patched = [version]($ver -replace '[^0-9.].*$','') -ge [version]'7.6.3' # placeholder — verify against Fortinet PSIRT advisory FG-IR reference
Add-Finding $fm 'Fortinet FortiMail' $ver ($patched ? 'PATCHED' : 'VULNERABLE') 'CVE-2026-104286' `
'If unpatched: disable admin/web access from untrusted interfaces immediately as interim workaround.'
} catch { Add-Finding $fm 'Fortinet FortiMail' 'UNKNOWN' 'QUERY-FAILED' 'CVE-2026-104286' $_.Exception.Message }
}
# ---------- 4. Validation pass ----------
Write-Host "[*] Validation: confirming no VULNERABLE assets remain exposed..." -ForegroundColor Cyan
$Results | Export-Csv -Path $ReportPath -NoTypeInformation
$Results | Format-Table Asset, Product, DetectedVersion, Status, CVE -AutoSize
$vulnCount = ($Results | Where-Object Status -eq 'VULNERABLE').Count
if ($vulnCount -gt 0) {
Write-Host "[!] $vulnCount asset(s) still VULNERABLE. Escalate per emergency change policy. Report: $ReportPath" -ForegroundColor Red
exit 1
} else {
Write-Host "[+] All inventoried assets patched or not present. Report: $ReportPath" -ForegroundColor Green
exit 0
}
Patch & Remediation Priorities
- Citrix NetScaler ADC/Gateway (CVE-2026-88772, CVE-2026-88771) — PATCH FIRST. Unauthenticated, internet-facing, memory-safety class, with a proven ransomware-affiliate pipeline. Apply the fixed builds from the Citrix security bulletin at https://support.citrix.com/article/CTX (check the advisory for your train: 14.1 / 13.1 / 13.0 / 12.1-FNDM). After patching, terminate all ICA/VPN sessions and reboot — patching does not invalidate previously stolen session tokens. Workaround if patching is delayed: none adequate for pre-auth memory corruption; restrict Gateway vServers behind an ACL/WAF as a partial measure only.
- Cisco Catalyst SD-WAN Manager (CVE-2026-76504). Unauthenticated remote access to the WAN control plane. Apply the Cisco fixed release per https://sec.cloudapps.cisco.com/security/center/publicationListing.x. Immediate workaround: restrict Manager access to a dedicated management VRF/jump host only; block all untrusted reachability at the edge.
- Fortinet FortiMail (CVE-2026-104286). Upgrade per the Fortinet PSIRT advisory at https://www.fortiguard.com/psirt. Interim: disable HTTP/HTTPS admin and webmail interfaces on untrusted interfaces; place behind an authenticated management VLAN.
- Zammad (CVE-2026-102489, CVE-2026-102490). Upgrade to the fixed release per https://zammad.com/en/releases / https://github.com/zammad/zammad security advisories, then purge the session store (
zammad run rails r "ActiveRecord::SessionStore::Session.delete_all") and restart services — otherwise fixated sessions survive the patch. Audit for root-level artifacts created by thezammaduser. - Apple iOS/iPadOS/macOS (CVE-2026-86950). Push the latest point releases via MDM with enforced update deadlines (Apple advisories at https://support.apple.com/en-us/100100). Enable Lockdown Mode for executives and high-risk users; enforce Rapid Security Responses.
CISA compliance: All seven CVEs carry binding remediation deadlines for federal civilian agencies under BOD 22-01 (typically three weeks from catalog addition — deadlines fall between 2026-10-18 and 2026-10-23 for this batch). CISA's required action for each: apply vendor mitigations per the linked advisory, or discontinue use of the product if mitigations are unavailable. Every private-sector organization should hold itself to the same clock — KEV listing means the exploit is already working against someone.
Related Resources
Security Arsenal Penetration Testing Managed SOC & MDR AlertMonitor Platform From The Dark Side Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.