Cybersecurity & Threat Defense Bulletins
Welcome to the Cybersecurity & Threat Defense Bulletins stream. This live chronological journal tracks emergency CVE disclosures, actively exploited zero-days added to the CISA Known Exploited Vulnerabilities (KEV) catalog, exploit forensics, and verified mitigation procedures.
All bulletins include official source attribution, publication timestamps, and actionable remediation steps.
π Published: October 01, 2026
π¨ Fortinet FortiMail Critical Path Traversal & Null Byte Injection Zero-Day (CVE-2026-104286)
On October 1, 2026, CISA issued an emergency addition of CVE-2026-104286 (CVSS 9.8) to the Known Exploited Vulnerabilities catalog. The vulnerability affects Fortinet FortiMail secure email gateway appliances and combines path traversal (../) with null byte injection (%00) to achieve arbitrary unauthenticated file creation.
Threat Architecture & Technical Impact
- Unauthenticated File Write: Remote threat actors send crafted HTTP/HTTPS POST payloads targeting web management endpoints, bypassing directory sanitation gates to write executable scripts directly to server webroots.
- Persistence & Interception: Compromised appliances grant root access, enabling persistent SSH tunnels, harvesting of in-flight enterprise emails, and extraction of Active Directory synchronization credentials.
- Emergency Workarounds: Fortinet recommends immediately disabling Identity-Based Encryption (IBE) support if immediate patch deployment is delayed.
π Published: September 30, 2026
π¨ Cisco Catalyst SD-WAN Manager Authentication Bypass (CVE-2026-76504)
Added to CISA KEV on September 30, 2026: CVE-2026-76504 in Cisco Catalyst SD-WAN Manager (vManage) allows remote attackers to bypass API authentication gates via crafted URI hex encoding, gaining unrestricted administrative control over software-defined WAN fabrics.
π Published: September 27, 2026
π¨ Citrix NetScaler ADC & Gateway Remote Code Execution Zero-Days (CVE-2026-88771 & CVE-2026-88772)
Added to the CISA KEV catalog on September 27, 2026: Critical vulnerabilities affecting NetScaler ADC (Citrix ADC) and NetScaler Gateway appliances. Attackers exploit boundary corruption in AAA-TM packet assembly to obtain an interactive root shell on the underlying FreeBSD operating system.
π Published: September 25, 2026
π¨ MikroTik RouterOS Administrative Control Takeover (CVE-2026-67279)
Added to CISA KEV on September 25, 2026: An improper workflow enforcement flaw in MikroTik RouterOS software exploited in chained attacks (the βMikroTrickβ chain) to hijack routing tables, alter DNS resolvers, and implant rogue WinBox proxy accounts across edge routers.