CISA stopped reliably sending KEV alerts.
We didn't.
CyberComply monitors the CISA Known Exploited Vulnerabilities catalog 24/7 and alerts you the moment a new KEV drops — before the deadline clock starts ticking without you knowing.
KEV Intelligence Brief: October 8, 2026
Audience: Federal Contractors · DevOps & Platform Teams · Security Operations Leaders Classification: TLP:CLEAR Reporting Period: September 27 – October 4, 2026
Eight vulnerabilities added to the CISA KEV catalog over the past twelve days reveal a consistent and urgent pattern: network perimeter infrastructure and session management layers are under sustained, active exploitation. Three thematic clusters demand immediate attention from operations teams managing federal and enterprise environments.
Citrix NetScaler Is Actively Targeted — Again
Citrix NetScaler ADC and NetScaler Gateway account for three of the eight new KEV entries, and that concentration is not accidental. Threat actors have demonstrated a persistent, methodical interest in NetScaler as a high-value chokepoint that, once compromised, yields access to downstream enterprise resources with minimal additional effort.
CVE-2026-88771 (added September 27, deadline September 30 — overdue) is the most severe of the three. An improper input validation flaw allows an unauthenticated remote attacker to execute arbitrary commands directly on the appliance. This is a full pre-auth RCE on a network edge device and should be treated with the same urgency as a confirmed breach on any exposed instance. CVE-2026-88772 (same add date and deadline — overdue) compounds the picture: a memory buffer mismanagement flaw enabling either remote code execution or denial of service. These two CVEs dropped simultaneously and likely represent a coordinated disclosure or a single campaign that surfaced multiple exploitation paths against the same codebase.
CVE-2026-88779 (added October 4, deadline October 7 — overdue as of today) affects the same product family with a buffer restriction flaw leading to denial-of-service. While denial-of-service carries lower immediate impact than RCE, on a gateway appliance it translates to complete session disruption for remote workforces and VPN-dependent operational technology environments.
Operational guidance: Any internet-facing NetScaler instance that has not been patched against all three CVEs should be treated as potentially compromised pending forensic triage. Per BOD 26-04 and CISA's Forensics Triage Requirements, patching alone is insufficient after the deadline window has passed — teams must conduct memory and log artifact review before returning appliances to production. Rotate all session tokens, certificates, and administrative credentials regardless of patch status. If a patch cannot be applied immediately, isolate the management interface from public routing and enforce IP allowlisting at the perimeter.
Unauthenticated Access to Network Management Planes: Cisco and Fortinet
Two entries target enterprise network management and mail security infrastructure with unauthenticated attack vectors — the most dangerous posture for any internet-facing system.
CVE-2026-76504 (added September 30, deadline October 3 — overdue) affects Cisco Catalyst SD-WAN Manager. Improper handling of hex-encoded URI characters allows a remote, unauthenticated attacker to gain admin-level access without credentials. SD-WAN Manager is the control plane for distributed WAN architectures; administrator access here means an adversary can reroute traffic, manipulate policy, and observe unencrypted network telemetry at scale. Organizations running SD-WAN at multiple sites should audit management plane logs for unusual API calls or configuration changes beginning as far back as late September.
CVE-2026-104286 (added October 1, deadline October 4 — overdue) affects Fortinet FortiMail. The vulnerability chains a path traversal with an improper NULL byte neutralization flaw, permitting an unauthenticated attacker to write arbitrary files to the underlying system via crafted HTTP or HTTPS requests. Arbitrary file write on a mail gateway is a stepping stone to persistent implants and credential harvesting at scale — particularly dangerous in environments where FortiMail handles government or regulated communications. Organizations should immediately verify whether unexpected files have appeared in web-accessible directories or system paths, and review HTTP access logs for anomalous request patterns involving percent-encoded null bytes or directory traversal sequences.
Operational guidance: Both systems manage or transit sensitive organizational data and should never be directly internet-exposed without strict ingress filtering. If patching is delayed beyond deadline, segment these management interfaces behind zero-trust access controls or take them offline. BOD 26-04 compliance for cloud-hosted instances requires escalation to the cloud service owner where direct patching is not available.
Session Hijacking Chains and Endpoint Exposure: Zammad and Apple
The remaining three entries address a chained software vulnerability and a cross-platform operating system flaw, together representing risk to both user endpoints and internal support infrastructure.
CVE-2026-102489 and CVE-2026-102490 (both added October 2, deadline October 5 — overdue) affect Zammad, an open-source ticketing and customer support platform used broadly in DevOps and IT service management contexts. The two CVEs are explicitly designed to be chained: CVE-2026-102489 is a session fixation flaw that enables remote code execution as the zammad application user, and CVE-2026-102490 is a privilege escalation vulnerability that elevates that foothold to root on the underlying host. In combination, an attacker who can reach the Zammad web interface can achieve full system compromise. Organizations running Zammad should apply vendor patches immediately, audit active sessions, rotate all API tokens and agent credentials, and review audit logs for session ID anomalies.
CVE-2026-86950 (added September 29, deadline October 2 — overdue) affects Apple iOS, macOS, and iPadOS via an out-of-bounds write flaw in CoreGraphics. This is a broad-surface endpoint vulnerability with arbitrary code execution potential. In federal and contractor environments where BYOD or unmanaged Apple devices access internal systems, this CVE represents a persistent risk until all endpoints in scope are confirmed patched. MDM-managed fleets should be verified through compliance reporting; unmanaged devices should be blocked from internal resource access until patch status is confirmed.
Summary Deadline Status
| CVE | Vendor / Product | Deadline | Status | |---|---|---|---| | CVE-2026-88771 | Citrix NetScaler | Sep 30 | Overdue | | CVE-2026-88772 | Citrix NetScaler | Sep 30 | Overdue | | CVE-2026-86950 | Apple iOS/macOS/iPadOS | Oct 2 | Overdue | | CVE-2026-76504 | Cisco SD-WAN Manager | Oct 3 | Overdue | | CVE-2026-104286 | Fortinet FortiMail | Oct 4 | Overdue | | CVE-2026-102489 | Zammad | Oct 5 | Overdue | | CVE-2026-102490 | Zammad | Oct 5 | Overdue | | CVE-2026-88779 | Citrix NetScaler | Oct 7 | Overdue |
All eight entries have passed their BOD 26-04 patch deadlines. Federal agencies and contractors must treat non-compliant assets as requiring immediate escalation and documented exception handling. Forensic triage is mandatory for any system that was exposed and unpatched during the active exploitation window.
Sources: CISA KEV Catalog · CISA BOD 26-04 · Citrix Security Advisories · Cisco Security Advisory: SD-WAN Manager · Fortinet PSIRT Advisory · Apple Security Updates · Zammad Security Releases
Free KEV Alerts
- Real-time notification the moment a KEV drops
- Vendor and product details
- BOD 26-04 remediation deadline included
Pro Alerts Coming Soon
- Real-time notification the moment a KEV drops
- Filtered to your specific vendor watchlist
- Urgency scoring (Critical / Urgent / Standard)
- Direct patch links included
Stay ahead of CISA.
Search the KEV Catalog by Vendor or Product
Search for CVEs by vendor or product to identify known exploited vulnerabilities in your environment
Upcoming Patch Due Dates
via Binding Operational Directive 26-04
BOD 26-04 is CISA's current vulnerability remediation directive for Federal Civilian Executive Branch (FCEB) agencies, updating the KEV-driven framework introduced under BOD 22-01 with a more risk-based approach to prioritization. While binding only on FCEB agencies, its framework increasingly influences contractor expectations through procurement requirements, FedRAMP programs, and agency security clauses.
Loading...
Cyber Security News
You may have missed...
Hacking Editorial Brief — October 8, 2026
Atlassian Critical Flaw Under Active Exploitation Hours After PoC Release
A critical vulnerability in Atlassian's enterprise product suite (CVE-2026-21589) is seeing active exploitation within two hours of public proof-of-concept code release. The flaw affects multiple Atlassian product families including Jira, Confluence, and Bitbucket Data Center installations. Security researchers noted that exploitation attempts began immediately following the publication of technical details, with the subsequent release of a Nuclei scanning template expected to enable mass automated targeting. The rapid weaponization timeline underscores the compressed window between disclosure and active exploitation facing enterprise environments.
AI-Driven Attack Campaign Targets South Korean Banking Infrastructure
CrowdStrike attributed a series of breaches targeting South Korean financial institutions to a suspected Chinese-speaking threat actor using AI-powered penetration tools. The campaign exploited AI agents to conduct reconnaissance and initial access operations, with stolen data believed intended for sale. Security firm S2W separately reported that hundreds of global servers are now running AI-driven penetration testing tools capable of simultaneous multi-target operations, marking a tactical shift in automated offensive capability. One Claude Code session recovered during the investigation contained a request to generate a security researcher resume documenting results from the hacking activity, suggesting the operator may be a 26-year-old individual based in China.
Major Healthcare and Professional Services Breaches Disclosed
Oracle disclosed that hackers accessed legacy Cerner Corp servers, exposing personal and medical information including Social Security numbers and addresses of nearly 20 million individuals. Separately, Ernst & Young confirmed unauthorized access to its tax services platform between March 28 and April 12, 2026, resulting in the download of sensitive documents belonging to Goldman Sachs wealth management and Man Group clients. The incidents add to a continuing pattern of third-party service provider compromises affecting downstream client data.
Sources: Bleeping Computer · The Hacker News · Anadolu Agency · Chosun · Tech Story · GBHackers
*
Inside a cyberattack: How hackers steal data
The truth about cybersecurity is that it's almost impossible to keep hackers outside of an organization, particularly as the cybercrime industry ...
US Nabs Suspected China Spy for Surveilling Taiwan Leader's Son
The FBI arrested a woman suspected of spying for China by surveilling the Taiwanese president's son and his family at Los Angeles International Airpor...
UNC2814 suspected China-linked cyber espionage group compromises 50+ organisations across 42 countries
Google Threat Intelligence disrupted a China-linked espionage campaign where UNC2814 deployed GRIDTIDE backdoor malware controlled through Google Shee...
China-linked hackers posed as former US officials, Anthropic employee to target AI experts
Proofpoint identified phishing campaigns by China-linked TA419 that borrowed prominent figures' identities to approach U.S. AI policy researchers befo...
Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT
Multiple threat actors are exploiting Citrix NetScaler vulnerabilities CVE-2026-88771 and CVE-2026-88772 for mass exploitation with web shell and malw...
Hackers obtain counterfeit TLS certificates for Google and other large services
Compromise of 3 domain registries allows hackers to walk off with unauthorized certs.
South Korean officials believe AI agents were used to hack several banks
... hack the banks' systems ... The incidents, which first came to light on September 30, are the first known example of AI agents hacking the financi...
Hackers Use Chinese AI Tool to Hit South Korean Banks, Exposing New Risk - WSJ
Hackers used a Chinese artificial-intelligence agent to attack South Korea's biggest banks and steal the personal information of 68,000 people, ...
Chinese hackers pose as former White House official in AI espionage campaign
Chinese hackers posed as AI and statecraft experts, including Lynne Parker from the White House Office of Science and Technology Policy, in espionage ...
Updated daily
