Back to Intelligence

CISA KEV Flash: 7 CVEs Added — Zammad, FortiMail, Cisco SD-WAN, Apple, Citrix NetScaler Under Active Attack

SA
Security Arsenal Team
October 2, 2026
13 min read

Between September 27 and October 2, 2026, CISA added seven CVEs to the Known Exploited Vulnerabilities catalog — each one confirmed to be under active exploitation in the wild. This batch is heavily weighted toward perimeter and identity-adjacent infrastructure: two Citrix NetScaler memory-safety and input-validation flaws, an unauthenticated remote access bug in Cisco Catalyst SD-WAN Manager, a path traversal / NULL byte injection in Fortinet FortiMail, an out-of-bounds write in Apple CoreGraphics, and a chained session-fixation-to-privilege-escalation pair in Zammad helpdesk. This is the exact vendor profile ransomware affiliates and initial access brokers farm for edge-device footholds.

Active Exploitation Intelligence

CVE-2026-102490 — Zammad Improper Privilege Management (LPE)

  • What it is: An improper privilege management flaw allowing the local zammad service user to escalate privileges to root on the host.
  • Exploitation method: Local privilege escalation (LPE). Almost certainly chained with CVE-2026-102489: session fixation grants code execution as the zammad user, and this flaw converts that into full root control of the helpdesk server — a system that typically holds customer PII, email credentials, and internal ticketing data.
  • Threat actors: Attribution unknown (Ransomware: Unknown), but helpdesk compromise is a classic precursor to social-engineering-driven ransomware intrusions and Bec-style pivots.
  • CVSS / PoC: Score pending at time of writing; no confirmed public PoC. CISA listing confirms real-world weaponization regardless.
  • CISA action: Apply vendor mitigations per BOD 22-01, or discontinue use if mitigations are unavailable. Federal agencies face a binding remediation deadline (typically ~3 weeks from listing).

CVE-2026-102489 — Zammad Session Fixation (RCE)

  • What it is: A session fixation vulnerability that can lead to remote code execution as the zammad user.
  • Exploitation method: Attacker fixes or pre-plants a session identifier, waits for a victim (typically an agent or admin) to authenticate into that session, then rides the authenticated context to execute code in the application tier. Entry point of the two-CVE Zammad chain.
  • Threat actors: Unknown; exploitation confirmed by CISA.
  • CVSS / PoC: Pending; no public PoC observed. Treat internet-facing Zammad portals as compromised until patched and session stores are invalidated.
  • CISA action: Vendor patch required; force global session invalidation post-patch to kill fixated sessions.

CVE-2026-104286 — Fortinet FortiMail Path Traversal + NULL Byte Injection

  • What it is: A path traversal combined with improper neutralization of NULL bytes, potentially allowing an unauthenticated attacker to read or write files outside intended directories.
  • Exploitation method: Crafted requests with %00 sequences bypass extension/path validation, enabling arbitrary file read (credential harvesting, config theft) or file write (webshell drop, config overwrite) on the mail gateway.
  • Threat actors: Fortinet edge flaws are historically exploited by both nation-state clusters (Volt Typhoon-style edge persistence) and ransomware initial access brokers. Mail gateways are prized because they sit inline with all inbound email.
  • CVSS / PoC: Pending; Fortinet's track record means PoC publication typically follows within days of KEV listing. Assume imminent.
  • CISA action: Apply Fortinet advisory updates immediately; restrict management interface exposure.

CVE-2026-76504 — Cisco Catalyst SD-WAN Manager Hex Encoding Flaw (Unauthenticated Access)

  • What it is: A hex encoding vulnerability allowing an unauthenticated, remote attacker to access an affected system.
  • Exploitation method: Authentication bypass via encoding confusion — requests crafted with hex-encoded path or parameter values slip past access controls that validate only the decoded (or only the encoded) form. SD-WAN Manager compromise hands an attacker the control plane for the entire WAN fabric: config push, credential extraction, lateral movement into every branch.
  • Threat actors: SD-WAN and network management planes are top-tier targets for pre-positioning actors (Volt Typhoon playbook) and ransomware operators seeking one-shot enterprise-wide reach.
  • CVSS / PoC: Pending; unauthenticated remote access to a management plane should be treated as critical-by-design.
  • CISA action: Patch per Cisco advisory; if patching is delayed, isolate the management interface from all untrusted networks immediately.

CVE-2026-86950 — Apple CoreGraphics Out-of-Bounds Write (iOS/iPadOS/macOS)

  • What it is: An out-of-bounds write in CoreGraphics that can lead to arbitrary code execution when processing maliciously crafted image/content.
  • Exploitation method: Drive-by RCE via weaponized images — delivered through iMessage, email, web content, or document previews. This class of bug is the workhorse of mercenary spyware (NSO Group / Predator-style chains) and is increasingly used for initial access against high-value executives and journalists.
  • Threat actors: Apple 0-day CoreGraphics/WebKit flaws correlate strongly with commercial surveillance vendors; once n-days leak, criminal adoption follows.
  • CVSS / PoC: Pending; no public PoC, but weaponized samples exist in the wild per CISA confirmation.
  • CISA action: Enforce rapid OS updates across the mobile fleet; enable Lockdown Mode for at-risk users.

CVE-2026-88772 — Citrix NetScaler ADC/Gateway Buffer Bounds Violation

  • What it is: Improper restriction of operations within the bounds of a memory buffer in NetScaler ADC and Gateway.
  • Exploitation method: Memory corruption reachable remotely — consistent with unauthenticated RCE or denial-of-service against the gateway. NetScaler memory-safety bugs (CitrixBleed lineage) have repeatedly produced session-token theft and full appliance compromise.
  • Threat actors: NetScaler flaws are among the fastest-weaponized bugs in the ransomware ecosystem — LockBit, ALPHV/BlackCat, and Medusa affiliates all have prior NetScaler tradecraft, as do Chinese state clusters.
  • CVSS / PoC: Pending; expect scanning within hours and PoC within days. Assume any internet-facing, unpatched NetScaler is already being probed.
  • CISA action: Patch immediately per Citrix bulletin, then kill all active/persistent sessions (kill icaconnection -all and reboot) — patching alone does not evict stolen sessions.

CVE-2026-88771 — Citrix NetScaler Improper Input Validation

  • What it is: Improper input validation allowing an unauthenticated attacker to impact the appliance (disclosed alongside CVE-2026-88772).
  • Exploitation method: Crafted unauthenticated requests against gateway virtual servers; can be chained with CVE-2026-88772 for pre-auth impact or used standalone for service disruption.
  • Threat actors: Same NetScaler-hungry ecosystem as above.
  • CVSS / PoC: Pending; no public PoC at publication.
  • CISA action: Same Citrix remediation cycle; treat the pair as a single emergency change.

Affected Organizations Assessment

  • Exposed environments: Any organization running internet-facing NetScaler Gateway (VPN/VDI access), FortiMail gateways inline with inbound email, Cisco SD-WAN Manager controlling distributed sites, Zammad helpdesk portals exposed to customers, and Apple device fleets (especially BYOD and executive devices lagging on updates).
  • Exposure scale: NetScaler ADC/Gateway is deployed at tens of thousands of enterprises globally, and NetScaler patch adoption historically lags — post-CitrixBleed telemetry showed weeks-long windows of mass exposure. FortiMail and SD-WAN Manager are frequently left reachable from untrusted networks despite vendor guidance. Zammad self-hosted instances are common in SMBs and MSPs, which patch slower than enterprises. Apple fleet compliance varies wildly; anything not on the latest iOS/iPadOS/macOS point release is exposed.
  • Fastest-exploited sectors: Managed service providers and telecoms (SD-WAN control planes), healthcare and finance (NetScaler remote access), legal and government-adjacent organizations (helpdesk compromise for phishing infrastructure), and executive/journalist targets (Apple spyware-class bugs). Ransomware affiliates historically move on edge-device CVEs within 24–72 hours of disclosure.

Detection Engineering

The following Sigma rules target observable exploitation behaviors for the highest-risk CVEs in this batch: NetScaler pre-auth request anomalies (CVE-2026-88771/88772), FortiMail NULL-byte path traversal (CVE-2026-104286), and Zammad session-fixation-to-root chaining (CVE-2026-102489/102490).

YAML
---
title: Citrix NetScaler Gateway Pre-Auth Exploitation Attempt - CVE-2026-88771/88772
id: 4f2c9a10-7e6b-4c21-9a55-0b1f8d3e2a01
status: experimental
description: Detects suspicious unauthenticated request patterns against NetScaler ADC/Gateway virtual servers consistent with input-validation and memory-corruption probing added to CISA KEV on 2026/09/27.
author: Security Arsenal Threat Intel
logsource:
    category: webserver
    product: citrix
    service: netscaler
detection:
    selection_uri:
        cs-uri-stem|contains:
            - '/vpn/'
            - '/logon/LogonPoint/'
            - '/cgi/'
            - '/oauth/'
    selection_anomalies:
        cs-uri-query|contains:
            - '%00'
            - '..'
            - '%2e%2e'
            - '\x'
        cs-method:
            - 'POST'
            - 'PUT'
    condition: selection_uri and selection_anomalies
falsepositives:
    - Legitimate scanner or WAF health checks (validate source IP)
level: high
tags:
    - attack.initial_access
    - attack.t1190
    - cve.2026.88771
    - cve.2026.88772
date: 2026/10/02
---
title: FortiMail NULL Byte Path Traversal - CVE-2026-104286
id: 8b1d3e55-2a90-4f77-b6c4-9c0e1a7d5f02
status: experimental
description: Detects NULL byte injection and path traversal sequences in requests to FortiMail web interfaces, consistent with actively exploited CVE-2026-104286.
author: Security Arsenal Threat Intel
logsource:
    category: webserver
    product: fortinet
    service: fortimail
detection:
    selection:
        cs-uri|contains:
            - '%00'
            - '%2500'
            - '\x00'
    selection_traversal:
        cs-uri|contains:
            - '/../'
            - '%2e%2e%2f'
            - '..%2f'
    condition: selection or selection_traversal
falsepositives:
    - Rare; encoded traversal in legitimate requests is uncommon on mail gateways
level: critical
tags:
    - attack.initial_access
    - attack.t1190
    - attack.t1006
    - cve.2026.104286
date: 2026/10/02
---
title: Zammad Service User Privilege Escalation to Root - CVE-2026-102490
id: 61c7aa92-3d4e-4b88-9e10-5f2b6c8a9d03
status: experimental
description: Detects the zammad service account spawning root-owned processes or executing privilege escalation utilities, consistent with post-exploitation chaining of CVE-2026-102489 and CVE-2026-102490.
author: Security Arsenal Threat Intel
logsource:
    category: process_creation
    product: linux
detection:
    selection_user:
        User|contains: 'zammad'
    selection_suspicious:
        Image|endswith:
            - '/sudo'
            - '/su'
            - '/pkexec'
            - '/bash'
            - '/sh'
            - '/python'
            - '/python3'
            - '/curl'
            - '/wget'
    filter_parent:
        ParentImage|endswith:
            - '/passenger'
            - '/nginx'
    condition: selection_user and selection_suspicious and not filter_parent
falsepositives:
    - Zammad maintenance scripts run by administrators (tune by command line)
level: critical
tags:
    - attack.privilege_escalation
    - attack.t1068
    - attack.execution
    - cve.2026.102490
date: 2026/10/02

The KQL query below hunts across proxy/firewall telemetry for NetScaler and FortiMail exploitation indicators, plus endpoint process telemetry for the Zammad escalation chain, in Microsoft Sentinel.

KQL — Microsoft Sentinel / Defender
// CISA KEV 2026-09-27..10-02: Hunt for exploitation of NetScaler, FortiMail, and Zammad CVEs
let KevWindow = ago(14d);
union isfuzzy=true
    // NetScaler pre-auth probing: CVE-2026-88771 / CVE-2026-88772
    (CommonSecurityLog
    | where TimeGenerated > KevWindow
    | where DeviceVendor =~ "Citrix"
    | where RequestURL has_any ("/vpn/", "/logon/LogonPoint/", "/cgi/", "/oauth/")
    | where RequestURL has_any ("%00", "..", "%2e%2e") or RequestMethod in ("POST","PUT")
    | extend Indicator = "NetScaler pre-auth anomaly (CVE-2026-88771/88772)"
    | project TimeGenerated, Indicator, SourceIP, DestinationHostName, RequestURL, RequestMethod),
    // FortiMail NULL byte / traversal: CVE-2026-104286
    (CommonSecurityLog
    | where TimeGenerated > KevWindow
    | where DeviceProduct has "FortiMail"
    | where RequestURL has_any ("%00", "%2500", "/../", "%2e%2e%2f")
    | extend Indicator = "FortiMail NULL-byte traversal (CVE-2026-104286)"
    | project TimeGenerated, Indicator, SourceIP, DestinationHostName, RequestURL, RequestMethod),
    // Zammad LPE chain: zammad user spawning shells or escalation tools: CVE-2026-102490
    (DeviceProcessEvents
    | where TimeGenerated > KevWindow
    | where InitiatingProcessAccountName =~ "zammad"
    | where FileName in~ ("sudo","su","pkexec","bash","sh","python","python3","curl","wget")
    | extend Indicator = "Zammad service user escalation (CVE-2026-102490)"
    | project TimeGenerated, Indicator, DeviceName, FileName, ProcessCommandLine, InitiatingProcessCommandLine)
| order by TimeGenerated desc

The following PowerShell script inventories exposed Zammad, FortiMail-adjacent hosts, and NetScaler appliances on the network, checks versions against the KEV-affected set, and validates remediation status. Run from a management host with network access to the target infrastructure.

PowerShell
#Requires -RunAsAdministrator
<#
.SYNOPSIS
    CISA KEV 2026-10-02 inventory & remediation validation script.
    Covers: Zammad (CVE-2026-102489/102490), FortiMail (CVE-2026-104286),
            NetScaler (CVE-2026-88771/88772), Apple fleet spot-check (CVE-2026-86950).
#>

$ErrorActionPreference = 'Continue'
$ReportPath = ".\KEV_Inventory_$(Get-Date -Format 'yyyyMMdd_HHmmss').csv"
$Results = @()

function Add-Finding($Asset, $Product, $Version, $Status, $CVE, $Notes) {
    $script:Results += [PSCustomObject]@{
        Asset = $Asset; Product = $Product; DetectedVersion = $Version
        Status = $Status; CVE = $CVE; Notes = $Notes; Timestamp = (Get-Date)
    }
}

# ---------- 1. Zammad hosts (CVE-2026-102489 / CVE-2026-102490) ----------
Write-Host "[*] Scanning for Zammad installations..." -ForegroundColor Cyan
$ZammadHosts = @()  # Populate from CMDB, or discover via package query over WinRM/SSH jump
foreach ($h in $ZammadHosts) {
    $pkg = Invoke-Command -ComputerName $h -ScriptBlock {
        (dpkg -l zammad 2>$null | Select-String '^ii') -replace '\s+',' '
    }
    if ($pkg) {
        $ver = ($pkg -split ' ')[2]
        $patched = [version]($ver -replace '[^0-9.].*$','') -ge [version]'6.5.2'  # vendor fixed version
        Add-Finding $h 'Zammad' $ver ($patched ? 'PATCHED' : 'VULNERABLE') 'CVE-2026-102489/102490' `
            'If vulnerable: apt update && apt install --only-upgrade zammad; then: zammad run rails r "ActiveRecord::SessionStore::Session.delete_all" && systemctl restart zammad'
    }
}

# ---------- 2. NetScaler appliances (CVE-2026-88771 / CVE-2026-88772) ----------
Write-Host "[*] Querying NetScaler appliances via NITRO API..." -ForegroundColor Cyan
$NetScalers = @('ns1.corp.example.com','ns2.corp.example.com')  # Replace with real hosts
$NSCreds = Get-Credential -Message 'NetScaler nsroot credentials'
foreach ($ns in $NetScalers) {
    try {
        $login = Invoke-RestMethod -Method Post -Uri "https://$ns/nitro/v1/config/login" `
            -Body (@{login=@{username=$NSCreds.UserName; password=$NSCreds.GetNetworkCredential().Password}} | ConvertTo-Json) `
            -ContentType 'application/json' -SkipCertificateCheck
        $token = $login.sessionid
        $ver = (Invoke-RestMethod -Uri "https://$ns/nitro/v1/config/nsversion" `
                -Headers @{Cookie="NITRO_AUTH_TOKEN=$token"} -SkipCertificateCheck).nsversion.version
        # Consult Citrix advisory for exact fixed builds per train; flag anything older than advisory date
        $patched = $ver -match '14\.1-5[0-9]\.|13\.1-6[0-9]\.'  # placeholder for fixed builds — verify against Citrix bulletin
        Add-Finding $ns 'Citrix NetScaler ADC/Gateway' $ver ($patched ? 'PATCHED' : 'VULNERABLE') 'CVE-2026-88771/88772' `
            'After patching, MUST kill sessions: shell > nsconmsg -K /var/nslog/newnslog -d event | grep -i session; and reboot appliance to evict stolen session tokens.'
    } catch { Add-Finding $ns 'Citrix NetScaler ADC/Gateway' 'UNKNOWN' 'QUERY-FAILED' 'CVE-2026-88771/88772' $_.Exception.Message }
}

# ---------- 3. FortiMail gateways (CVE-2026-104286) ----------
Write-Host "[*] Querying FortiMail gateways..." -ForegroundColor Cyan
$FortiMails = @('fm1.corp.example.com')  # Replace with real hosts
$FmToken = 'YOUR_FORTIMAIL_API_TOKEN'
foreach ($fm in $FortiMails) {
    try {
        $status = Invoke-RestMethod -Uri "https://$fm/api/v1/SysStatus" `
                  -Headers @{Authorization="Bearer $FmToken"} -SkipCertificateCheck
        $ver = $status.Version
        $patched = [version]($ver -replace '[^0-9.].*$','') -ge [version]'7.6.3'  # placeholder — verify against Fortinet PSIRT advisory FG-IR reference
        Add-Finding $fm 'Fortinet FortiMail' $ver ($patched ? 'PATCHED' : 'VULNERABLE') 'CVE-2026-104286' `
            'If unpatched: disable admin/web access from untrusted interfaces immediately as interim workaround.'
    } catch { Add-Finding $fm 'Fortinet FortiMail' 'UNKNOWN' 'QUERY-FAILED' 'CVE-2026-104286' $_.Exception.Message }
}

# ---------- 4. Validation pass ----------
Write-Host "[*] Validation: confirming no VULNERABLE assets remain exposed..." -ForegroundColor Cyan
$Results | Export-Csv -Path $ReportPath -NoTypeInformation
$Results | Format-Table Asset, Product, DetectedVersion, Status, CVE -AutoSize
$vulnCount = ($Results | Where-Object Status -eq 'VULNERABLE').Count
if ($vulnCount -gt 0) {
    Write-Host "[!] $vulnCount asset(s) still VULNERABLE. Escalate per emergency change policy. Report: $ReportPath" -ForegroundColor Red
    exit 1
} else {
    Write-Host "[+] All inventoried assets patched or not present. Report: $ReportPath" -ForegroundColor Green
    exit 0
}

Patch & Remediation Priorities

  1. Citrix NetScaler ADC/Gateway (CVE-2026-88772, CVE-2026-88771) — PATCH FIRST. Unauthenticated, internet-facing, memory-safety class, with a proven ransomware-affiliate pipeline. Apply the fixed builds from the Citrix security bulletin at https://support.citrix.com/article/CTX (check the advisory for your train: 14.1 / 13.1 / 13.0 / 12.1-FNDM). After patching, terminate all ICA/VPN sessions and reboot — patching does not invalidate previously stolen session tokens. Workaround if patching is delayed: none adequate for pre-auth memory corruption; restrict Gateway vServers behind an ACL/WAF as a partial measure only.
  2. Cisco Catalyst SD-WAN Manager (CVE-2026-76504). Unauthenticated remote access to the WAN control plane. Apply the Cisco fixed release per https://sec.cloudapps.cisco.com/security/center/publicationListing.x. Immediate workaround: restrict Manager access to a dedicated management VRF/jump host only; block all untrusted reachability at the edge.
  3. Fortinet FortiMail (CVE-2026-104286). Upgrade per the Fortinet PSIRT advisory at https://www.fortiguard.com/psirt. Interim: disable HTTP/HTTPS admin and webmail interfaces on untrusted interfaces; place behind an authenticated management VLAN.
  4. Zammad (CVE-2026-102489, CVE-2026-102490). Upgrade to the fixed release per https://zammad.com/en/releases / https://github.com/zammad/zammad security advisories, then purge the session store (zammad run rails r "ActiveRecord::SessionStore::Session.delete_all") and restart services — otherwise fixated sessions survive the patch. Audit for root-level artifacts created by the zammad user.
  5. Apple iOS/iPadOS/macOS (CVE-2026-86950). Push the latest point releases via MDM with enforced update deadlines (Apple advisories at https://support.apple.com/en-us/100100). Enable Lockdown Mode for executives and high-risk users; enforce Rapid Security Responses.

CISA compliance: All seven CVEs carry binding remediation deadlines for federal civilian agencies under BOD 22-01 (typically three weeks from catalog addition — deadlines fall between 2026-10-18 and 2026-10-23 for this batch). CISA's required action for each: apply vendor mitigations per the linked advisory, or discontinue use of the product if mitigations are unavailable. Every private-sector organization should hold itself to the same clock — KEV listing means the exploit is already working against someone.

Related Resources

Security Arsenal Penetration Testing Managed SOC & MDR AlertMonitor Platform From The Dark Side Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.