Cyber Roundup: Week of September 28

Here are the main stories you missed last week.

1. Cisco: Catalyst SD-WAN Manager CVE-2026-76504 marks the eighth CISA KEV listing for the product this year

The headline: On October 1, 2026, CISA added CVE-2026-76504 to the Known Exploited Vulnerabilities catalog following Cisco’s confirmation of active exploitation. The flaw is a CVSS 9.8 hex encoding vulnerability in Catalyst SD-WAN Manager that allows an unauthenticated remote attacker to access affected systems with administrator-level API privileges. Cisco PSIRT learned of exploitation in September and has disclosed nothing about the activity itself: no victim count, no attribution, and no indication of when exploitation first began.

What we’re actually watching: This is the eighth Cisco SD-WAN CVE added to CISA KEV in 2026. Watchtowr’s head of threat intelligence Jake Knott noted that the product has become “an ever-present staple” of the catalog, which is the dry version of saying attackers have decided the platform is worth sustained investment.

The vector is improper handling of URI encoding in HTTP requests. An attacker who understands the encoding mismatch reaches administrative API functions without presenting any credential. Catalyst SD-WAN Manager is the control plane for the SD-WAN overlay, which means a successful intrusion grants administrative reach into every downstream router the manager controls. Access-control lists restricting management-plane traffic remain the main pre-patch defense, but convention is not enforcement.

The CISO question: When the same product family absorbs eight KEV listings in a single year, what internal threshold triggers a review of whether the product itself is still the right choice, or does the review never happen because migration cost always wins the argument?

2. Fortinet: FortiMail CVE-2026-104286 unauthenticated file write exploited before patches shipped

The headline: On October 1, 2026, CISA added CVE-2026-104286 to the KEV catalog with a three-day federal remediation deadline of October 4. The flaw is a CVSS 9.8 path traversal vulnerability in FortiMail that allows unauthenticated attackers to write arbitrary files to the underlying system through crafted HTTP or HTTPS requests. Fortinet confirmed active exploitation in its advisory. Affected versions span multiple FortiMail branches currently in support.

What we’re actually watching: FortiMail sits as the email security gateway for a large population of mid-market and enterprise organizations. A pre-authentication file write on the gateway produces persistent code execution with full access to the mail flow it inspects. The attackers reaching this flaw get both a durable foothold and the content of every message passing through.

The attack chain is direct. An attacker writes a web shell to a known filesystem path on the FortiMail appliance, then executes commands through it. From inside the appliance, outbound email can be inspected, inbound credentials harvested, and lateral movement follows the trust the gateway already holds. CISA’s three-day deadline reflects the urgency: by the time it arrived, exploitation had been running against unpatched instances for an unknown period.

The CISO question: If your FortiMail appliance was compromised two weeks ago and had full access to inbound and outbound mail during that window, what credentials and sensitive content would an attacker now hold, and how much of that could you still revoke?

3. DIVD: Autonomous AI agent chained two Zammad zero-days to reach root in seconds

The headline: On October 2, 2026, CISA added CVE-2026-102489 and CVE-2026-102490 to the KEV catalog with a federal deadline of October 5. The vulnerabilities affect Zammad, an open-source helpdesk and ticketing platform used by more than 2,000 organizations. The Dutch Institute for Vulnerability Disclosure (DIVD) discovered the chain after a September 21 breach of its own network. An autonomous AI agent used both flaws to hijack a session, execute code as the Zammad user, and escalate to root. The sequence took seconds.

What we’re actually watching: DIVD’s forensic reconstruction attributes the intrusion to an AI agent rather than a human. The agent left over-explanatory comments inside its own attack scripts, and DIVD described its behavior as “loud, messy, and disorganized.” The identification of agentic behavior came from the artifacts the agent left behind, not from a signature.

CVE-2026-102489 is a session fixation flaw in Zammad versions 6.3.0 through 6.5.4 enabling unauthenticated RCE, and Zammad has shipped version 7 to address it. CVE-2026-102490 is a privilege escalation flaw affecting every Zammad version including the latest alpha, with no patch as of October 1. Upgrading to version 7 closes the RCE path but leaves the root-escalation path open for anyone who reaches the Zammad user account by any other route.

The CISO question: If your organization runs Zammad or any self-hosted helpdesk product, does your detection catch the forensic signature of an AI agent (iterative decision-making artifacts, over-explanatory comments in attacker scripts), or is that pattern invisible to tooling built around human adversary playbooks?

4. Apple: CoreGraphics CVE-2026-86950 PoC emerges for flaw used against targeted individuals

The headline: On October 1, 2026, researchers published the first public proof-of-concept for CVE-2026-86950, a flaw in Apple’s CoreGraphics image rendering library. Apple has said the flaw “may have been used in attacks against specific targeted individuals” but offered no details on the targets, the success of the attempts, or when exploitation began. Apple patched the flaw the preceding week. The PoC causes a crash rather than code execution on its own.

What we’re actually watching: The “specific targeted individuals” framing is the language Apple uses when its investigation points at mercenary spyware vendors, journalists, dissidents, or NGO targets. The vulnerability class (image parsing in CoreGraphics) is also the delivery path that most recent iOS mercenary spyware campaigns have exploited.

The practical risk for enterprise organizations is low. CoreGraphics flaws of this class have historically been reserved for commercial spyware deployed against high-value targets. The risk for employees who match that profile (executives at sensitive organizations, security researchers, legal counsel on politically exposed matters) is high and immediate. WhatsApp introduced PDF content checks last week, which researchers assess as a possible defensive response to a related delivery path.

The CISO question: Do you know which employees at your organization match the profile mercenary spyware operators target, and does your mobile security program treat their devices with controls proportionate to that threat model rather than the enterprise default?

5. Bitget: $387.5 million crypto theft traced to zero-days in two third-party security appliances

The headline: On October 1, 2026, cryptocurrency exchange Bitget confirmed that the $387.5 million stolen from its hot and warm wallets on September 24 was enabled by a zero-day in a third-party security product. Investigations by SlowMist and Mandiant trace the earliest malicious activity to August 31, 2026, when a service running on a node of “Product A” was first affected by the zero-day. The attacker established persistent access on a second security appliance (“Product B”) and moved laterally to Bitget’s production wallet job server. Theft spanned 11 blockchains including Ethereum, XRP Ledger, TRON, and BNB Smart Chain. Bitget and the investigators have attributed the operation to North Korean threat actors.

What we’re actually watching: The attackers never stole a private key. They compromised two security appliances deployed inside Bitget’s network, then used the privileged position those appliances held to call Bitget’s own withdrawal process with forged parameters. The product category meant to protect the wallet environment was the exact category that provided the attacker’s entry and privilege.

SlowMist recovered a custom theft tool tailored to Bitget’s specific wallet withdrawal logic, indicating weeks of preparation inside the environment before the September 24 theft. The gap between first intrusion (August 31) and theft (September 24) is 24 days, during which the attackers had administrative reach into Bitget’s internal security products with no detection signal from either product.

The CISO question: For every security product deployed to protect privileged workloads, do you monitor that product’s behavior as a potential adversary, or does its defender role grant a trust level your detection does not revisit?

The pattern across all five stories

Every attack this week moved through the exact layer the organization believed was protecting it. Cisco Catalyst SD-WAN Manager is the control plane for the network. FortiMail is the gateway that inspects the mail flow. Zammad is the helpdesk that handles the trust between users and support. Apple CoreGraphics is the component that renders untrusted content safely. The two security appliances Bitget relied on were sold as the layer that would catch exactly the attack that reached them.

The attackers did not bypass the defender. They used the defender. When the asset guarding something privileged becomes the asset granting access to it, every downstream control inherits the compromise. CybelAngel maps your external perimeter the way an attacker sees it, and surfaces the exposed credentials, forgotten management planes, and the leaked artifacts that turn a trusted product into the attacker’s first move.

Über den Autor