Cyber Pulse · Week 40 · 28 Sep–4 Oct 2026
This week in 60 seconds
- Four vendors confirmed that new flaws were being exploited: Fortinet FortiMail, Cisco Catalyst SD-WAN Manager, Citrix NetScaler (SAML) and Apple CoreGraphics. CISA added six CVEs to its Known Exploited Vulnerabilities (KEV) catalog between 29 September and 4 October.
- If your NetScaler uses SAML, the builds you installed for Week 39 are not enough. Citrix shipped new fixed builds on 4 October. FortiMail has no fixed build yet, so the workaround is the only control.
- No UAE or GCC incident is in this week’s sources. That reflects what our sources covered, not proof that the region was quiet.
Patch now
| Severity | CVE | Product | Exploited? | Action |
|---|---|---|---|---|
| CRIT | CVE-2026-104286 | Fortinet FortiMail 7.2 to 8.0 (IBE feature) | Yes (Fortinet, KEV) | No fixed build yet: 8.0.2, 7.6.7 and 7.4.9 are listed as “upcoming”, and 7.2 must move to 7.4 or later. For now, disable IBE, or remove internet access to webmail, or block POST requests to /ibe containing “../” at the WAF. Hunt for the FG-IR-26-175 indicators, including unexpected remote “archive” accounts. |
| CRIT | CVE-2026-76504 | Cisco Catalyst SD-WAN Manager (all configurations) | Yes (Cisco, KEV) | Upgrade to 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 or 26.2.1 (releases before 20.9 must migrate). There is no workaround, so limit Manager access to trusted hosts. Check serviceproxy-access.log for an encoded j_security_check (e.g. /%6a_security_check) and vmanage-server.log for viptela-reserved-* logins from unknown IPs. |
| HIGH | CVE-2026-88779 | Citrix NetScaler ADC/Gateway configured as SAML SP or IdP | Yes (Citrix: targeted DoS; KEV) | Upgrade to 14.1-73.41, 13.1-64.28, 14.1-73.41 FIPS or 13.1-37.282 (FIPS/NDcPP). The Week 39 builds are still vulnerable. Check the config for add authentication samlAction or samlIdPProfile. Treat unexplained nsaaad crashes or reboots as an incident: researchers are still investigating reports of code execution. |
| HIGH | CVE-2026-86950 | Apple iOS, iPadOS, macOS (CoreGraphics) | Yes (Apple: targeted individuals; KEV) | Move to iOS/iPadOS 26.7.1, macOS Tahoe 26.7.1 or macOS Sequoia 15.8.1 (or the 27.0.1 releases). Enforce through MDM, executives’ and admins’ devices first. |
| HIGH | CVE-2026-102489 + CVE-2026-102490 | Zammad helpdesk (self-hosted) | KEV-listed; Zammad disputes the scope | Update to Zammad 7.2.0. Take any 6.5-or-older instance off the internet now. Follow Zammad’s GitHub security advisories for the privilege-escalation flaw, which Zammad says it cannot yet verify. |
Still open from Week 39: Citrix NetScaler (CVE-2026-88771, CVE-2026-88772), Check Point (CVE-2026-85102, CVE-2026-93616), F5 BIG-IP where APM is the OAuth authorization server (CVE-2026-94127), and on-prem Arista VeloCloud Orchestrator (CVE-2026-93952). Confirm the fixed build is installed.
Who is behind the NetScaler DTLS attacks: on 30 September, Mandiant’s CTO said “advanced and suspected state-sponsored threat actors” were likely behind the first intrusions. Exploitation has been under way since at least early September, and Mandiant and Google know of dozens of affected organisations across North America and Europe in government, finance, education, telecoms and legal services. A clean patch does not remove an earlier foothold. Source
KEV due dates are US federal deadlines under BOD 26-04. They do not bind UAE organisations, so use them as a signal of urgency and follow your own regulator’s and internal patch timelines.
Top stories
1. Warlock ransomware still gets in through on-prem SharePoint, now at water and telecom operators
Symantec reported on 1 October that Longlegs (Storm-2603), the China-nexus group behind Warlock ransomware, hit at least four organisations in two months: a water utility, a telecoms provider, a regional government body and a university, all in Portuguese- and Spanish-speaking countries. The group got in through unpatched on-premises SharePoint, using the 2025 ToolShell chain and newer SharePoint flaws that CISA flagged in July 2026. It then stole ASP.NET machine keys, disabled EDR with a signed vulnerable driver, tunnelled out through VS Code, and pushed ransomware from SYSVOL to at least 33 hosts in one intrusion. Action: confirm every on-prem SharePoint server is fully patched, and rotate machine keys on any server that was ever exposed unpatched. Alert on new executables in SYSVOL and on VS Code tunnel services (code-insiders.exe) appearing on servers. Source
2. An AI agent chained two helpdesk flaws to breach a vulnerability-disclosure non-profit
The Dutch Institute for Vulnerability Disclosure (DIVD) says its 21 September intrusion was run by an autonomous agent. The agent chained the two Zammad flaws in the table above to hijack a session, run code and become root within seconds, then reached other services and took data. DIVD says network segmentation limited the damage. Zammad disputes parts of the disclosure and says it has received no technical details of the privilege-escalation flaw, so the scope is unsettled. The lesson holds anyway: internet-facing helpdesk and ticketing systems hold credentials and customer data, and attackers are now working them at machine speed. Source · Zammad statement
3. Pentagon DMDC breach: unencrypted personal data on a file-sharing server, accessed for nine months
The US Defense Manpower Data Center is notifying 2.76 million living people, plus records of 294,000 deceased individuals. Unauthorised users accessed files on a file-sharing system from October 2025 until the flaw was discovered on 16 July 2026. The exposed data includes Social Security numbers paired with names and birth dates. DMDC says it has no indication the data has been misused. Action: list the file-sharing servers that hold personal data, encrypt that data at rest, and check that your access logs go back far enough to show months of quiet access. Source
4. More than 543,000 working secrets are sitting in public GitHub repositories
Truffle Security found 543,699 unique credentials in public GitHub repositories that still worked in July. The median credential had been public for 784 days. GitHub Push Protection blocks new leaks but does not revoke secrets that are already exposed. Action: scan your organisation’s public repositories and forks, then revoke and rotate anything you find. Deleting the commit does not fix the leak; revoking the credential does. Source
Threat radar
- TA419: harmless first emails, then an adversary-in-the-middle phish — Proofpoint reported on 1 October that this China-aligned espionage group impersonated a former White House science-policy official and a prominent economist in July. The emails invited AI-policy experts at US think tanks, universities and law firms to join a fake advisory committee. Only after a target replied did the group send a shortened link to a fake OneDrive page that relays and steals Microsoft 365 sign-ins (a Browser-in-the-Browser kit with an Evilginx phishlet). Action: brief executives, advisers and government-relations staff that a harmless first email can be the setup for a later phishing link. Put these users on phishing-resistant MFA (FIDO2 or passkeys) with conditional access. Source
UAE & GCC watch
- No UAE or GCC incident is in this week’s sources (absence is not knowledge of the region). Ransomware leak-site listings naming Gulf companies were not independently confirmed, so they are not included.
- Saudi Arabia’s National Cybersecurity Authority (CERT) issued a Critical Fortinet alert (2026-7895, 1 October) and a High Citrix alert (2026-7896, 4 October), both urging customers to apply the vendors’ updates. Source Earlier regional items stay on Previous Cyber Pulse.
One thing to do this week
Check every internet-facing NetScaler for add authentication samlAction or add authentication samlIdPProfile. Where either exists, upgrade again this week to 14.1-73.41 or 13.1-64.28 (or 14.1-73.41 FIPS or 13.1-37.282 for FIPS/NDcPP). The builds many teams installed for Week 39 do not fix this week’s SAML flaw.
Compiled from public vendor advisories, CISA KEV and threat-intelligence reporting dated 28 September to 4 October 2026. For awareness only — check vendor guidance before acting. Get this in your inbox every Monday: subscribe to the Monday Brief.

