Exploited CVEs Last Week: September 28-October 4, 2026

Six exploited CVEs reached CISA's KEV catalog between September 29 and October 4, covering Apple, Cisco, Fortinet, Zammad, and NetScaler. Each calls for a different first move, from a simple upgrade to a workaround because no patch exists.

Exploited CVEs Last Week: September 28-October 4, 2026

Six CVEs joined the CISA Known Exploited Vulnerabilities catalog between September 29 and October 4, 2026, spread across Apple, Cisco, Fortinet, Zammad, and NetScaler. Four score 9.8 critical and two land at 8.8 and 8.7 high. Every one of them was already being exploited when its vendor announced it, and the fix situation runs from a clean patch to no patch at all. Here is the week in order, followed by what the numbers on VulnTracker say about it.

The Week, Day by Day

September 29: Apple CoreGraphics (CVE-2026-86950)

Apple shipped iOS and iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1 on September 28 to fix an out-of-bounds write in CoreGraphics that a maliciously crafted file can trigger to run code. Apple said the flaw may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27, and credited Meta Product Security with the report. CISA listed it the next day with an October 2 federal deadline. VulnTracker scores it 8.8 high, and it is the only entry of the six that does not sit on a server or a network edge.

September 30: Cisco Catalyst SD-WAN Manager (CVE-2026-76504)

A URL-encoding trick against the j_security_check endpoint lets an unauthenticated attacker act as an admin on SD-WAN Manager, which is why the flaw scores 9.8. Cisco's own engineers found it while resolving a customer support case, and there is no workaround beyond restricting network access. Fixed releases exist for every supported branch, from 20.9.10.1 through 26.2.1, and CISA's deadline was October 3. Our dedicated post covers the mechanism, the viptela-reserved- username indicator, and the fixed-release table.

October 1: Fortinet FortiMail (CVE-2026-104286)

A path traversal combined with a NULL byte handling flaw in the FortiMail web interface lets an unauthenticated attacker write arbitrary files through crafted HTTP or HTTPS requests. Fortinet's own Product Security team found it, and the advisory went out with exploitation confirmed and no fixed release for any branch. The interim options are disabling the IBE feature or cutting internet access to the management interface. CISA set an October 4 deadline. The dedicated post lists the added and modified files Fortinet published as indicators.

October 2: Zammad (CVE-2026-102489 and CVE-2026-102490)

Two Zammad flaws arrived as a pair. CVE-2026-102489 is a session fixation bug that gives a remote attacker code execution as the Zammad user on versions 6.3.0 through 6.5.4, and CVE-2026-102490 lets that user escalate to root on every version from 1.5.0 through the 7.1.0 alpha. The Dutch Institute for Vulnerability Disclosure found both while investigating a breach of its own Zammad helpdesk on September 21, and describes the attack as agentic and AI-powered. On Zammad 7 and later the first flaw is not exploitable according to DIVD, while the root escalation has no fix in any version. Both entries carry an October 5 deadline, and the dedicated post walks through the full chain.

October 4: NetScaler ADC and Gateway (CVE-2026-88779)

A memory overflow in the SAML authentication path crashes NetScaler ADC and Gateway appliances, and Citrix classifies it as a denial of service with an 8.7 high score. Administrators and researchers have reported shell commands in SAML login requests and a malware binary on a patched honeypot, which Citrix has not confirmed as code execution. It arrived a week after the first pair of NetScaler zero-days, and appliances that took the earlier fixes need 14.1-73.41 or 13.1-64.28 on top of them. CISA's deadline is October 7, and the dedicated post has the configuration check and the full evidence.

Five Vendors, Five Different Patch Situations

Patch status is the sharpest difference between these six. Apple and Cisco shipped complete fixes, though Cisco offers no workaround for anyone who cannot upgrade right away. Fortinet disclosed an exploited FortiMail flaw with no fixed release on any branch, so the only defense is a workaround that costs functionality. Zammad's pair is half fixed, with the root escalation open on every version. NetScaler has a patch, yet customers who already updated for the previous round have to update again. That spread matters for triage. A patch queue sorted by CVSS puts the four critical entries first, but the first move differs for each: upgrade Cisco, work around FortiMail, contain Zammad, and re-upgrade NetScaler.

Reading the Week on VulnTracker

Sorted by KEV date, the six entries show a pattern the CVSS column hides. EPSS topped out at 2 percent across the set, with the lowest at 0.3 percent for NetScaler, even though every entry is confirmed exploited. For fresh CVEs the KEV listing carries the signal, and EPSS has not caught up yet. SSVC marks all six as Active. Four are automatable, namely Cisco, FortiMail, the Zammad RCE, and NetScaler, while the Zammad escalation and the Apple flaw are not. Total impact applies to everything except NetScaler, which is partial, and the NetScaler row is also the only one still at Received status, waiting on NVD analysis. Filter by Exploited and Added to KEV on VulnTracker to see the same view for any week.

What to Do This Week

Start by finding which of these vendors you run and where they sit, since SD-WAN Manager, FortiMail, Zammad, and SAML-enabled NetScaler appliances all face the internet by design or by habit. Then work the deadlines in order: Apple's October 2, Cisco's October 3, and FortiMail's October 4 have passed, Zammad's is October 5, and NetScaler's is October 7. Match the action to the vendor. Upgrade SD-WAN Manager and Apple devices, apply the IBE workaround or close management access on FortiMail until Fortinet ships fixes, treat Zammad as potentially compromised and contain it, and move SAML NetScalers to 14.1-73.41 or 13.1-64.28 even if they carry the earlier fix. Finally, hunt before you relax. Because each flaw was exploited when it was disclosed, a patched system can still hold an intruder.

Six more entries reached the KEV list in a single week, and no two of them called for the same response. Read the vendor guidance for each before you queue a patch, and treat the disclosure date as the start of your investigation. Track the vendors you run on VulnTracker to get an alert the moment one of them lands on the catalog.

References

CISA Known Exploited Vulnerabilities Catalog · Cisco advisory cisco-sa-sdwan-webauth-xr8beuuU · Fortinet advisory FG-IR-26-175 · DIVD case DIVD-2026-00015 · Citrix bulletin CTX697174 · NVD entry for CVE-2026-86950 · Apple coverage (The Hacker News)