Skip to content

Cybersecurity & Threat Defense Bulletins

Welcome to the Cybersecurity & Threat Defense Bulletins stream. This live chronological journal tracks emergency CVE disclosures, actively exploited zero-days added to the CISA Known Exploited Vulnerabilities (KEV) catalog, exploit forensics, and verified mitigation procedures.

All bulletins include official source attribution, publication timestamps, and actionable remediation steps.


Latest AdvisoryActive KEVπŸ›οΈ Source: CISA KEV & Fortinet PSIRT

πŸ“… Published: October 01, 2026

🚨 Fortinet FortiMail Critical Path Traversal & Null Byte Injection Zero-Day (CVE-2026-104286)

CVSS 9.8 CriticalCISA KEV ListedActive Exploitation

On October 1, 2026, CISA issued an emergency addition of CVE-2026-104286 (CVSS 9.8) to the Known Exploited Vulnerabilities catalog. The vulnerability affects Fortinet FortiMail secure email gateway appliances and combines path traversal (../) with null byte injection (%00) to achieve arbitrary unauthenticated file creation.

Threat Architecture & Technical Impact

  1. Unauthenticated File Write: Remote threat actors send crafted HTTP/HTTPS POST payloads targeting web management endpoints, bypassing directory sanitation gates to write executable scripts directly to server webroots.
  2. Persistence & Interception: Compromised appliances grant root access, enabling persistent SSH tunnels, harvesting of in-flight enterprise emails, and extraction of Active Directory synchronization credentials.
  3. Emergency Workarounds: Fortinet recommends immediately disabling Identity-Based Encryption (IBE) support if immediate patch deployment is delayed.
πŸ“– Read Full Bulletin & Mitigation Runbook (CLI Workaround, Access Restriction & Audit Commands)Click to Expand ↓

Step 1: Disable Identity-Based Encryption (IBE) CLI Workaround

01

Disable Vulnerable IBE Subsystem via FortiMail CLI

Immediate Workaround

If maintenance windows do not allow immediate firmware upgrading, disable the affected Identity-Based Encryption feature:

# Connect via SSH to the FortiMail appliance:
config system encryption ibe
set status disable
end

Step 2: Restrict Ingress Management Interface Access

02

Isolate Web Management Interface to Private Subnets

Network Isolation

Ensure the FortiMail web management interface is strictly blocked from the public internet:

# Restrict administrative web access exclusively to trusted internal subnets:
config system admin
edit "admin"
set trusted-host 10.10.100.0/24 10.20.50.10/32
next
end

Previous AdvisoryActive KEVπŸ›οΈ Source: CISA KEV & Cisco PSIRT

πŸ“… Published: September 30, 2026

🚨 Cisco Catalyst SD-WAN Manager Authentication Bypass (CVE-2026-76504)

CVSS 9.8 CriticalSD-WAN ControllerCISA KEV Listed

Added to CISA KEV on September 30, 2026: CVE-2026-76504 in Cisco Catalyst SD-WAN Manager (vManage) allows remote attackers to bypass API authentication gates via crafted URI hex encoding, gaining unrestricted administrative control over software-defined WAN fabrics.

πŸ“– Read Full Bulletin & Mitigation Runbook (Firewall Filtering, API Session Audit & Version Checks)Click to Expand ↓

Step 1: Verify Running SD-WAN Manager Version

01

Check Catalyst SD-WAN Manager Software Release via VShell

Version Audit

Connect to the SD-WAN Manager via SSH and verify installed package release:

# Query software release version from the vManage CLI:
vmanage# show version
# Verify installed software repository images:
vmanage# show software

Step 2: Restrict Ingress HTTPS Access via Upstream Access Control Lists

02

Drop Public Internet Ingress Traffic to SD-WAN Ports

Perimeter Isolation

SD-WAN Manager web interfaces (TCP ports 443 and 8443) should never be exposed to public transit networks:

# Edge gateway ACL restricting access strictly to internal NOC subnet:
ip access-list extended RESTRICT-VMANAGE
permit tcp 10.250.0.0 0.0.255.255 host 198.51.100.5 eq 443
permit tcp 10.250.0.0 0.0.255.255 host 198.51.100.5 eq 8443
deny tcp any host 198.51.100.5 eq 443 log
deny tcp any host 198.51.100.5 eq 8443 log

Previous AdvisoryActive KEVπŸ›οΈ Source: CISA KEV & Cloud Software Group

πŸ“… Published: September 27, 2026

🚨 Citrix NetScaler ADC & Gateway Remote Code Execution Zero-Days (CVE-2026-88771 & CVE-2026-88772)

CVSS 9.5 CriticalCISA KEV ListedActive Exploitation

Added to the CISA KEV catalog on September 27, 2026: Critical vulnerabilities affecting NetScaler ADC (Citrix ADC) and NetScaler Gateway appliances. Attackers exploit boundary corruption in AAA-TM packet assembly to obtain an interactive root shell on the underlying FreeBSD operating system.

πŸ“– Read Full Bulletin & Forensics Scripts (Build Check, Webshell Hunt & rc.netscaler Audit)Click to Expand ↓

Step 1: Hunt for Unauthorized Files and Persistence in rc.netscaler

01

Inspect Startup Scripts and Web Directories via Shell

Forensic Sweep

Audit startup persistence files and inspect web directories for suspicious PHP/sh webshells:

Terminal window
# Drop from NetScaler CLI into the underlying BSD shell:
> shell
# Inspect rc.netscaler startup script for unauthorized backdoor execution lines:
cat /nsconfig/rc.netscaler
# Scan web directories for recently modified or planted web shells:
find /netscaler/ns_gui/ -type f -mtime -14 -ls

Previous AdvisoryActive KEVπŸ›οΈ Source: CISA KEV & MikroTik Security

πŸ“… Published: September 25, 2026

🚨 MikroTik RouterOS Administrative Control Takeover (CVE-2026-67279)

CVSS 6.9 WarningCISA KEV ListedEdge Routers

Added to CISA KEV on September 25, 2026: An improper workflow enforcement flaw in MikroTik RouterOS software exploited in chained attacks (the β€œMikroTrick” chain) to hijack routing tables, alter DNS resolvers, and implant rogue WinBox proxy accounts across edge routers.

πŸ“– Read Full Bulletin & RouterOS Hardening CommandsClick to Expand ↓

Step 1: Audit Active RouterOS Services & Disable Unused Ports

01

Lock Down RouterOS Management Plane via Terminal

Router Hardening

Disable legacy web and telnet interfaces and bind WinBox strictly to internal management interfaces:

# Disable vulnerable plaintext management services:
/ip service disable www
/ip service disable telnet
/ip service disable ftp
# Restrict WinBox access to trusted internal admin subnets:
/ip service set winbox address=192.168.1.0/24

Comments