Edge Devices Under Fire: FortiMail and Cisco SD-WAN Zero-Days, NetScaler Persistence, and an AI-Driven Breach
The past 24 hours were dominated by actively exploited flaws in network edge and security infrastructure: an unauthenticated file-write bug in Fortinet FortiMail and an authentication bypass in Cisco Catalyst SD-WAN Manager, both now on CISA's Known Exploited Vulnerabilities (KEV) list. New analysis also shows how attackers are entrenching on compromised Citrix NetScaler appliances. A Dutch nonprofit also showed how an autonomous AI agent chained two helpdesk zero-days to breach its network, and European police dismantled the KillSec ransomware operation. Below, we look past the advisories at why these issues matter and how to prioritize them.
Priority at a glance
If you run any of the first three products, treat them as same-day work. Mitigation alone does not settle the risk: each has been exploited, so each also needs a check for prior compromise.
| Issue | Exploited | Fix status | CISA KEV deadline (federal) | Our recommended timing |
|---|---|---|---|---|
| Fortinet FortiMail, CVE-2026-104286 | Yes, as a zero-day | Fixed builds announced; confirm availability. Workarounds available now | Oct 4 | Today: mitigate, then hunt |
| Cisco Catalyst SD-WAN Manager, CVE-2026-76504 | Yes | Fixed releases available; no workaround | Oct 3 | Today: patch, then hunt |
| Citrix NetScaler ADC/Gateway, CVE-2026-88771 and -88772 | Yes | Fixed builds available since Sept 27 | Listed Sept 27 | This week: compromise check, even if already patched |
| Zammad helpdesk, CVE-2026-102489 and -102490 | Yes, in one confirmed breach | Upgrade to 7.x | Not listed | This week, if you run Zammad |
1. Fortinet FortiMail zero-day allows unauthenticated file writes (CVE-2026-104286)
What happened. On October 1, Fortinet disclosed a critical flaw in the FortiMail management interface that is being exploited in the wild. CISA added it to the KEV catalog the same day and gave federal agencies until October 4 to triage and mitigate.
Who is affected. FortiMail 7.2.0–7.2.9, 7.4.0–7.4.8, 7.6.0–7.6.6 and 8.0.0–8.0.1. Fixed releases are 7.4.9, 7.6.7 and 8.0.2; the 7.2 branch has no fix and must move to 7.4 or later.
Severity. CVSS 9.8. The bug combines path traversal (CWE-22) with improper handling of null bytes (CWE-158), letting a remote, unauthenticated attacker write arbitrary files through crafted HTTP or HTTPS requests. An arbitrary file write on an email security gateway is a short path to code execution and to visibility into an organization's mail flow. Fortinet has published file hashes and two attacker IP addresses as indicators of compromise.
Analysis. An email security gateway is one of the most valuable footholds an attacker can get. It sits in line with inbound and outbound mail, is trusted by the mail servers behind it, and often holds directory and relay credentials. Control of the gateway can give an attacker visibility into business correspondence and a trusted platform for onward phishing.
Fortinet's choice of workaround is telling. IBE is the feature that lets external recipients pick up encrypted messages through a web portal, so it is typically reachable from the internet by design. Organizations that kept the admin console private may still be exposed through IBE.
Timing is the second concern. At disclosure, SecurityWeek reported that the fixed releases had not yet shipped, and the 7.2 branch will get no fix at all. For some organizations, workarounds are the only control for now, and the 7.2-to-7.4 upgrade becomes unplanned work under pressure. Because exploitation came before disclosure, mitigating today does nothing about access an attacker may already have. CISA's order for federal agencies to carry out forensic triage, not only to mitigate, reflects that. We would treat any FortiMail appliance whose IBE portal or management interface was reachable from the internet as potentially compromised until hunting shows otherwise.
What to do. — click a step to check it off
- Upgrade to a fixed release as soon as it is available for your branch. Plan the 7.2-to-7.4 migration now.
- Until patched, disable the Identity-Based Encryption (IBE) feature as Fortinet advises, and restrict management interface access to trusted internal networks only.
- Search appliance and network logs for Fortinet's published IOCs, including connections from 79.141.169.187 and 45.129.0.192.
- If the management interface was internet-facing, treat the device as potentially compromised and follow CISA's forensic triage guidance before returning it to service.
2. Cisco Catalyst SD-WAN Manager authentication bypass exploited (CVE-2026-76504)
What happened. Cisco warned on September 30 that attackers are exploiting a critical authentication bypass in Catalyst SD-WAN Manager (formerly vManage). CISA added it to the KEV catalog with an October 3 federal deadline. It is the eighth Cisco SD-WAN flaw added to KEV this year.
Who is affected. All Catalyst SD-WAN Manager deployments, regardless of configuration. There are no workarounds. Fixed releases are 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1. Releases older than 20.9 must migrate to a supported, fixed train.
Severity. CVSS 9.8. Improper handling of URI encoding lets a crafted HTTP request slip past an authentication rule and reach the API as the admin user, with no credentials. Because the Manager controls the entire SD-WAN fabric, a compromise can affect routing and policy across every site it manages.
Analysis. This flaw is one more in a sustained campaign against the SD-WAN management plane.
- February: Cisco disclosed CVE-2026-20127 (CVSS 10.0), already being exploited. Cisco Talos attributed the activity to UAT-8616, a highly sophisticated actor that has targeted Cisco SD-WAN since at least 2023.
- March: A public proof of concept appeared for a separate chain of SD-WAN flaws. About ten additional threat clusters went on to exploit it to deploy web shells, cryptominers and credential stealers.
- May: A second CVSS 10.0 bypass, CVE-2026-20182, prompted CISA Emergency Directive 26-03.
Well-resourced operators and opportunistic crime groups are both watching this product, and new bypasses are being turned into working attacks quickly.
UAT-8616's tradecraft is the part defenders should study. According to Cisco and allied government reporting, the group:
- added rogue peers to the SD-WAN fabric;
- downgraded the software to reintroduce an old root-level flaw (CVE-2022-20775), then restored the original version to cover its tracks;
- injected SSH keys and deleted forensic evidence.
That playbook is built to survive patching. Moving to today's fixed release closes CVE-2026-76504, but it will not remove access gained earlier. Any organization whose SD-WAN Manager was reachable from the internet at any point this year should run a full compromise assessment:
- verify the peer inventory;
- review software version history for unexplained downgrades;
- audit authorized SSH keys and local accounts;
- compare on-device logs against off-box copies.
The lasting fix is architectural: the management plane should never be reachable from the internet.
What to do. — click a step to check it off, click any code snippet to copy it
- Patch to the fixed release for your train immediately, prioritizing internet-exposed instances.
- Restrict access to the Manager's administrative ports (443, 22, 830) to trusted management networks.
- Hunt in
serviceproxy-access.logandvmanage-server.logfor POST requests to URL-encoded variants of/j_security_check(for example/%6a_security_check) from unfamiliar IP addresses. - Review for unexpected accounts beginning with
viptela-reserved-. If you find signs of compromise, collectrequest admin-techoutput and open a case with Cisco TAC.
3. Citrix NetScaler attackers plant persistent superuser accounts and disguised web shells
What happened. New analysis from LevelBlue, published October 1, details what attackers deploy after exploiting CVE-2026-88771, the NetScaler zero-day disclosed September 27. A Perl payload creates a superuser account named sec_monitor, exfiltrates configuration data, and installs a PHP web shell at /var/netscaler/logon/LogonPoint/.local_journal. It then modifies the HTTP configuration so the shell is served under URLs that resemble ordinary NetScaler CSS files. A Python reverse shell calls out over TCP 443.
Who is affected. NetScaler ADC and Gateway 14.1 before 14.1-73.37 and 13.1 before 13.1-64.23, plus corresponding FIPS/NDcPP builds. CVE-2026-88771 (CVSS 4.0 score 9.5) is a pre-authentication command injection in default configurations. The companion flaw, CVE-2026-88772, is a memory overflow exploitable when DTLS is enabled. Both are on the KEV list.
Analysis. NetScaler has been at the center of mass exploitation before, most notably with CitrixBleed (CVE-2023-4966) in 2023 and CitrixBleed 2 (CVE-2025-5777) in 2025. The lesson from both was that patching closed the hole but did not remove what attackers had already taken or left behind. Today's research shows the same pattern, with more deliberate persistence.
The details are designed to beat a quick review. The account is named sec_monitor, which reads like a monitoring service. The web shell sits in a hidden file inside the login portal's own directory, and the configuration change makes requests to it look like ordinary stylesheet traffic. An administrator who glances at accounts, files and web logs could reasonably miss all three. Before broader disclosure, the Dutch National Cyber Security Centre (NCSC-NL) had already warned organizations about active exploitation and advised taking affected appliances offline, which signals how seriously responders took the risk.
Remote-access gateways are identity infrastructure. A compromised NetScaler can expose the credentials and sessions of every user who authenticates through it. Handle a confirmed compromise as an identity incident, not only as an appliance rebuild: reset credentials for users who signed in during the exposure window, and invalidate active sessions.
What to do. — click a step to check it off, click any code snippet to copy it
- Confirm every NetScaler instance runs a fixed build.
- Check for a
sec_monitoraccount, unexpected files under the LogonPoint directory, and HTTP configuration changes mapping CSS-style paths to scripts. - Block and search for the published infrastructure (64.94.85.67, 31.56.197.72, 23.27.143.20, 45.141.21.130).
- If you find evidence of compromise, rebuild the appliance from a known-good image and rotate all credentials, certificates and session secrets it held.
4. AI agent breaches vulnerability nonprofit through Zammad zero-days (CVE-2026-102489, CVE-2026-102490)
What happened. On September 21, an attacker broke into the Dutch Institute for Vulnerability Disclosure (DIVD) through two previously unknown flaws in Zammad, an open-source helpdesk platform. DIVD disclosed the incident on September 24 and published details of the flaws on September 30. Its investigators concluded the intrusion was carried out by an autonomous AI agent that decided each next step itself. They described it as fast but sloppy, including password spraying in the middle of its own interception attempt. The agent's verbose comments made reverse engineering easier.
Who is affected. Organizations running self-hosted Zammad. Zammad reports more than 2,000 customers.
- CVE-2026-102489 allows session hijacking that leads to remote code execution as the Zammad service user. It is exploitable in 6.3.0–6.5.4. The flaw is present in 7.0.0–7.1.3, but DIVD says it is not exploitable there.
- CVE-2026-102490 lets that service user escalate to root, and DIVD says it affects all versions back to 1.5.0.
DIVD says network segmentation limited how far the attacker got.
Analysis. Helpdesk platforms get less attention than they deserve. They hold customer personal data and internal discussions, and often credentials or configuration details pasted into tickets. They are also commonly integrated with email and directory services.
The AI angle needs measured treatment. Microsoft's latest Digital Defense Report says that observed attacks still depend on humans for key decisions. It is not yet public whether the agent found these flaws itself or was handed them. Either way, this is a documented case of an agent independently chaining exploitation through to root on a real network. The lesson is not that AI attackers are unstoppable; this one was noisy and made obvious mistakes. The lesson is that speed now favors the attacker, so detection has to be in place and watched, and segmentation has to hold when it is tested.
What to do. — click a step to check it off
- Upgrade self-hosted Zammad to a current 7.x release. If you cannot do so promptly, take the instance offline or restrict it to VPN access.
- Run DIVD's published log-check script to look for signs of prior exploitation.
- Review the helpdesk host for unexpected processes, accounts and outbound connections, and rotate any credentials stored in or used by the platform.
- Confirm the fix status of the root-escalation flaw (CVE-2026-102490) against Zammad's own advisory; early reporting was inconsistent.
5. European police dismantle KillSec ransomware operation
What happened. In an operation involving German, Spanish and Romanian authorities, the FBI and Europol, police arrested three suspects on September 30. They include a 16-year-old in Spain alleged to be KillSec's administrator. Officers carried out eight searches across four countries, took down five servers including the group's main infrastructure, and secured at least 110 TB of data.
Context. KillSec began as a hacktivist group and moved to ransomware in October 2023. Investigators link it to about 1,000 attempted attacks, roughly 500 of them successful. The group typically gained entry through unpatched software and poorly secured cloud storage.
Analysis. KillSec's profile shows how low the barrier to entry for extortion has become. The group was a hacktivist brand that turned into an extortion business. Its alleged administrator is a teenager, and its access came largely from unpatched software and misconfigured cloud storage rather than advanced exploits. Roughly 500 successful intrusions from that toolkit say more about defenders' basic hygiene than about attacker sophistication. The seized data, at least 110 TB, may also mean some organizations learn only now that their data was taken.
What to do. Takedowns disrupt but rarely end the threat; affiliates often regroup under new names. The group's entry points remain the lesson: audit cloud storage permissions and public exposure, and keep internet-facing software patched. Former victims should watch for law enforcement outreach, as seized data can support notifications and recovery.
Touchpoint's Take
Four themes connect today's stories, and together they argue for changes to how security programs handle infrastructure, not just faster patching.
- The window between disclosure and exploitation has nearly closed. Google counted 141 exploited vulnerabilities through August, already more than the 127 it recorded for all of 2025. Microsoft's 2026 Digital Defense Report puts the median time from discovery to weaponization well below 24 hours. Two of today's flaws were exploited before any fix existed. A monthly patch cycle cannot keep pace with that.
-
Patching is not the same as remediation. Every exploited-device story today carries the same warning:
- NetScaler attackers leave accounts and web shells that survive upgrades.
- UAT-8616 downgrades and restores Cisco software to hide its path.
- CISA is ordering forensic triage on FortiMail, not just mitigation.
Once a device has been exposed during an exploitation window, the question is whether someone got in, not only whether it is patched.
- AI is changing the pace on both sides. The DIVD intrusion is an early, documented case of an AI agent working through an attack chain on a real network. It was noisy and made mistakes, and it still reached root. Defenders should expect more volume and speed rather than perfect execution, and should invest in detection that keeps up.
What we would change in a security program:
- Inventory edge devices with named owners. Record each device's version, exposure and management-plane access. You cannot respond quickly to a device you did not know you had.
- Take management interfaces off the internet. Put admin consoles behind a VPN or a dedicated management network as standard policy. Today, this alone would have reduced the risk from both the FortiMail and Cisco flaws.
- Pre-approve emergency change windows for edge devices, so a KEV-listed fix can be applied within hours rather than waiting for the next scheduled window.
- Write a compromise-assessment playbook for each device class. Cover accounts, keys, configuration diffs, version history and off-box log comparison, so the check after patching is routine rather than improvised.
- Send appliance logs to a central system. Attackers routinely wipe local logs, and off-box copies are often the only record that survives.
- Treat gateway compromises as identity incidents. Reset credentials, invalidate sessions and review access for every user who passed through the device.
None of this is new advice. Taken together, today's stories show it can no longer be deferred.
If you would like help assessing your exposure to any of these issues, the Touchpoint Security team is available to talk.
Sources
- Fortinet warns of critical FortiMail flaw exploited in zero-day attacks – BleepingComputer
- Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes – The Hacker News
- Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action – SecurityWeek
- Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager – The Hacker News
- CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV – The Hacker News
- Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability – SecurityWeek
- FAQ about the continued exploitation of Cisco Catalyst SD-WAN vulnerabilities (UAT-8616) – Tenable
- Cisco SD-WAN Zero-Day Under Exploitation for 3 Years – Dark Reading
- Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs – The Hacker News
- Citrix NetScaler Zero-Day RCE FAQ: CVE-2026-88771 and CVE-2026-88772 – watchTowr
- DIVD-2026-00015: Vulnerabilities in Zammad – DIVD CSIRT
- AI agent used Zammad zero-days to breach Dutch vulnerability disclosure non-profit – Help Net Security
- DIVD says Zammad zero-days enabled AI-driven network breach – BleepingComputer
- Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers – The Hacker News
- Vulnerability disclosures double to 10,000 per month as AI fuels exploitation – The Record
- Microsoft says threat actors are ahead in the early AI race – BleepingComputer
Not sure where you stand on any of this?
Our team is available to talk through your exposure to today's issues.