Researchers published 2,652 new CVEs between September 28 and October 4, 2026. This weekly CVE report, built from CVE Watchtower data, tracks seven flaws with confirmed exploitation. Daily Cybersecurity’s intelligence sources flagged six of them, and CISA’s Known Exploited Vulnerabilities (KEV) catalog listed six.
The Week in Numbers
Severity skewed high this week. Of the 2,652 new CVEs, 305 rated Critical and 1,082 rated High. Another 1,088 were Medium, 115 were Low, and 62 still await a score. By CVSS score, 304 flaws hit 9.0 or above, while 1,070 landed between 7.0 and 8.9.
On the exploitation side, Daily Cybersecurity (DC) flagged six flaws as exploited. Five of them also reached CISA KEV during the week. One remains exclusive to DC. CISA added one more flaw that DC did not flag.
The Intelligence Lead: Daily Cybersecurity vs CISA KEV
The table below compares when each feed marked a flaw as exploited. Dates come from CVE Watchtower CVE Watchtower and CISA KEV catalog version 2026.10.04.
| CVE ID | Affected product | DC marked exploited | CISA KEV date added | Lead time |
|---|---|---|---|---|
| CVE-2026-86950 | Apple iOS, iPadOS and macOS | 2026-09-29 | 2026-09-29 | Same day |
| CVE-2026-76504 | Cisco Catalyst SD-WAN Manager | 2026-09-30 | 2026-09-30 | Same day |
| CVE-2026-100382 | MediaWiki External Data extension | 2026-10-01 | Not listed | Not listed / Exclusive to DC |
| CVE-2026-102489 | Zammad | 2026-10-02 | 2026-10-02 | Same day |
| CVE-2026-102490 | Zammad | 2026-10-02 | 2026-10-02 | Same day |
| CVE-2026-88779 | Citrix NetScaler ADC and Gateway | 2026-10-04 | 2026-10-04 | Same day |
This week, DC and CISA moved in step. All five shared flaws appeared in both feeds on the same calendar day, so DC held no lead. However, DC surfaced one critical flaw that CISA has not yet listed. Note that this is a feed-to-feed comparison, not a controlled benchmark, and “Not listed” flaws could still join KEV later.
Exploited Vulnerabilities from CISA KEV Only
| CVE ID | Affected product | Vulnerability type | CVSS | CISA KEV date added |
|---|---|---|---|---|
| CVE-2026-104286 | Fortinet FortiMail | Path traversal (unauthenticated file write) | 9.8 | 2026-10-01 |
The Flaws That Stand Out
MediaWiki External Data (CVE-2026-100382)
This OS command injection bug carries a perfect 10.0 CVSS score. It lets unauthenticated attackers run commands on wiki servers. According to a detection-engineering write-up on DEV Community, administrators “logged automated attempts within a day of the 25 September disclosure.” That write-up also says a public proof of concept sits in Wikimedia Phabricator. Attackers then dropped PHP web shells.
Cisco Catalyst SD-WAN Manager (CVE-2026-76504)
This 9.8 authentication bypass hands attackers admin access to the SD-WAN Manager API. Cisco PSIRT found the attacks in September 2026, Rapid7 reports. Moreover, iTnews reports that Cisco offers no workaround, so patching is the only fix.
Fortinet FortiMail (CVE-2026-104286)
This path traversal flaw lets unauthenticated attackers write arbitrary files to FortiMail appliances. “This is trivial to exploit,” watchTowr’s Yordan Ganchev told Cybersecurity Dive. At that report’s time, Fortinet offered workarounds but no patch.
Zammad Zero-Day Chain (CVE-2026-102489, CVE-2026-102490)
Attackers chained these two Zammad bugs against the Dutch Institute for Vulnerability Disclosure (DIVD) on September 21. SecurityWeek reports that DIVD described the intrusion as an “agentic AI-powered attack” that reached root in seconds.
What Defenders Should Do
- Patch Cisco SD-WAN Manager first. Install the fixed release for your branch, such as 20.15.6.1 or 26.2.1.
- Lock down FortiMail. Remove internet access to the management interface and apply Fortinet’s workarounds until a patch ships.
- Upgrade MediaWiki External Data to 3.7. Then hunt for unexpected PHP files in the web root.
- Update Citrix NetScaler to 14.1-73.41 or 13.1-64.28 if SAML is in use.
- Move Zammad to version 7 or take exposed instances offline.
- Update Apple devices to iOS 26.7.1 or macOS Tahoe 26.7.1.
Get the Full Weekly Data
This premium content is securely locked. You must upgrade your subscription to access the full threat intelligence report, including detailed mitigation steps, deep-dive analysis, and active exploitation metrics. Your attempt to inspect the DOM will only reveal this placeholder text. Please support our work to read the actual coverage.
Unlock Premium Threat Intelligence
This is a premium content. Upgrade to Pro or Team to unlock full access and remove all reading restrictions.