securityonline.info 5 Oct 2026, 01:44 UTC

Seven Newly Exploited Flaws Put Cisco, MediaWiki and Zammad at Risk

Seven Newly Exploited Flaws Put Cisco, MediaWiki and Zammad at Risk

RESEARCHERS tracked 2,652 new CVEs between 28 September and 4 October 2026, with seven flaws showing confirmed exploitation. Daily Cybersecurity (DC) flagged six exploited flaws, and six appeared in CISA’s Known Exploited Vulnerabilities (KEV) catalog. Five of the exploited flaws appeared in both feeds on the same day, while one vulnerability remains exclusive to DC. The KEV-only entry for this week is CVE-2026-104286 in Fortinet FortiMail.

Notable exploited flaws and their impact include CVE-2026-86950 (Apple iOS, iPadOS and macOS)—an out-of-bounds write in iOS 26.7.1 and macOS Tahoe 26.7.1; DC and KEV both mark it as exploited on or after 29 September 2026. CVE-2026-76504 in Cisco Catalyst SD-WAN Manager is a high-severity authentication bypass that could grant unauthenticated admin access to the API; Cisco PSIRT and Rapid7 report that patching is the remedy, with suggested fixed releases such as 20.15.6[.]1 or 26.2.1.

CVE-2026-100382 in MediaWiki External Data extension is a perfect 10.0 OS command injection, allowing unauthenticated command execution on wiki servers; public activity included automated attempts within a day of disclosure and a public PoC. CVEs in Zammad (CVE-2026-102489 and CVE-2026-102490) describe a chain leading to root on compromised instances, prompting guidance to upgrade to version 7 or take exposed systems offline.

CVE-2026-88779 affects Citrix NetScaler ADC and Gateway with exploitable remote access on affected builds; DC and KEV list equivalent dates for added risk.

Defenders are urged to patch Cisco SD-WAN Manager promptly, lockdown FortiMail management interfaces, upgrade MediaWiki External Data to 3.7, update Citrix NetScaler to specified builds when SAML is in use, and move Zammad to version 7 or isolate exposed instances. Also apply iOS 26.7.1 or macOS Tahoe 26.7.1 updates for Apple devices.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline