Zammad Zero-Day Vulnerabilities Exploited

Two Zammad zero-day vulnerabilities give attackers root on helpdesk servers. Used against DIVD, on CISA KEV, one flaw had no fix at disclosure.

Two Zammad zero-day vulnerabilities, CVE-2026-102489 and CVE-2026-102490, let an attacker take over the open-source helpdesk and reach root on its server. The Dutch Institute for Vulnerability Disclosure (DIVD) says an automated AI agent chained them against its own network on September 21. CISA has added the first flaw to its Known Exploited Vulnerabilities catalog, and…

Read More

FortiMail Zero-Day Vulnerability Exploited in the Wild

A FortiMail zero-day vulnerability lets attackers write files with no login. Exploited now; fixes for 7.4, 7.6 and 8.0 were pending at disclosure.

A FortiMail zero-day vulnerability, CVE-2026-104286 (CVSS 9.8), lets an unauthenticated attacker write arbitrary files onto Fortinet’s email security appliance with nothing more than crafted web requests. Fortinet confirmed active exploitation on October 1, CISA added the flaw to its Known Exploited Vulnerabilities catalog the same day, and fixed releases for the 7.4, 7.6 and 8.0…

Read More

Top 5 Cybersecurity News

Top 5 Cybersecurity News October 2, 2026: Cisco SD-WAN zero-day, WSO2 CVSS 10 auth bypass, Citrix backdoors persist, Apple CoreGraphics exploit, GUTcert breach.

This week’s Top 5 Cybersecurity News for October 2, 2026 follows a pattern that has been building across the year: attackers are targeting the layers that other infrastructure trusts. A critical-severity zero-day in Cisco’s SD-WAN Manager — the console that programs an entire enterprise WAN — arrived in CISA’s Known Exploited Vulnerabilities catalog on September…

Read More

GUTcert critical infrastructure data breach

A breach at certifier GUTcert exposed German critical infrastructure data; energy utility ENTEGA confirms it is a downstream victim.

A GUTcert critical infrastructure data breach has exposed roughly 640 GB of documentation submitted by German energy-grid operators as certification evidence, including exact substation locations and network topology maps. On September 24, Darmstadt utility ENTEGA AG confirmed it is a downstream victim, and more operators are expected to come forward. What Happened GUTcert is a…

Read More

Spectre v2 Branch Target Reuse vulnerability

A new Spectre v2 Branch Target Reuse vulnerability lets attackers leak a Linux root password hash in minutes, bypassing existing CPU defenses.

Researchers disclosed a new Spectre v2 Branch Target Reuse vulnerability on September 29 that lets an attacker recover a Linux system’s root password hash in minutes, on a fully patched Intel machine, by abusing a gap between how CPUs and just-in-time compilers handle recycled memory. The flaw touches Intel, AMD and Arm processors alike, and…

Read More