A patchless FortiMail webshell, a one-character Cisco SD-WAN bypass, and NetScaler still burning a week on.

CVEasy Weekly

This Week in Exposure

Week 41 · 2026-W41 · October 5 to October 11, 2026

Two new zero-days hit the edge this week, and both read the same bytes two different ways. FortiMail checks a filename for a safe extension, then writes the file after a null byte quietly cuts that extension off. Cisco SD-WAN Manager blocks the login path by its literal spelling, then runs the same path once a hex escape is decoded back to it. One safety check, one sink, a parser disagreement in the gap, and an attacker gets in with a single request and no credentials.

Both are confirmed exploited and both landed on CISA KEV the day they were disclosed. FortiMail had no patch at all when the first webshells dropped, so the only move is to turn the feature off. Underneath them, last week's NetScaler pre-auth pair is still being abused on boxes that never got the fix. Here is the week, ranked by what an attacker actually gets.

Top Exposures This Week

1. A null byte writes a webshell onto FortiMail before you log in

CVE-2026-104286 · FortiMail Identity-Based Encryption module · CVSS 9.8, unauthenticated · CISA KEV, federal deadline October 4, no patch at disclosure

Fortinet disclosed this on October 1 in advisory FG-IR-26-175 and confirmed it was already being exploited, with weeks of prior activity against the Identity-Based Encryption handler on the FortiMail web interface. The bug pairs a path traversal (CWE-22) with an embedded null byte (CWE-158). The handler checks the suffix of the path it was handed so a caller cannot drop a script where only data belongs, but that check runs against a C string, and a C string ends at the first null. An attacker sends a path like ../../../../data/bin/webconsole%00.cgi. The validator reads .cgi at the tail and allows the write. The filesystem call stops at the null and lands ../../../../data/bin/webconsole instead. Two parts of the same program read the same bytes and disagree on where the string ends, and that gap is the whole vulnerability. One unauthenticated request drops a webshell the appliance runs as CGI, and field reporting describes a path from first byte to a root-level shell in under two minutes. Two further writes, a binary at /bin/smit and a modified /data/bin/mailservice, rebuild persistence on normal mail delivery after any GUI reinstall. IBE ships on by default across every affected build, and no fixed build existed on disclosure day.

Risk read: Exploitation sits in the top band on two independent signals, Fortinet's own PSIRT confirmation and the KEV listing with a three-day federal deadline of October 4. The attack path is a single pre-auth request with no interaction, so mean time to first touch is counted in hours. Exposure is top band on any FortiMail with its management interface on the public internet and IBE left on, and several bands lower on a box reached only through an admin VPN with IBE disabled, because neither the handler nor the path is reachable. Blast radius is wide: the appliance holds the mail archive, DKIM private keys, LDAP bind credentials, and S/MIME and IBE keys, so a shell here is a mail tap, a key leak, and a foothold into the directory at once.

Read where the null byte splits the string →

2. One hex-encoded letter walks past the Cisco SD-WAN login

CVE-2026-76504 · Cisco Catalyst SD-WAN Manager · CVSS 9.8, unauthenticated auth bypass · CISA KEV, federal deadline October 3

Cisco PSIRT published advisory cisco-sa-sdwan-webauth-xr8beuuU on September 30, confirmed in-the-wild exploitation, and CISA added the CVE to KEV the same day. The authentication filter in front of the Java form-login servlet, j_security_check, matches the path by its literal spelling. A request to POST /j_security_check engages the filter and gets rejected. The same request as POST /%6a_security_check, where %6a is the hex encoding of the letter j, slips past because the filter sees a path that does not match its rule. The dispatcher then percent-decodes the URI, resolves the same servlet, and runs the request as an authenticated administrator. Cisco names the root cause CWE-177, improper handling of URL encoding. The filter reads raw bytes and the dispatcher reads the canonical form, the two never share a decoding step, and the window between those readings is the bug. It is the fifth actively exploited SD-WAN zero-day of the year, and it needs no credential, cookie, or captured token.

Risk read: Exploitation is top band on Cisco PSIRT confirmation plus a KEV listing with a 72-hour federal deadline of October 3. Reachability sets the rest: an internet-exposed Manager sits in the top action band, the same build reachable only from a management VRF behind a jump host drops several bands, and a patched instance leaves the queue. Blast radius is the SD-WAN control plane itself. Admin API access means policy push to every vEdge and cEdge, template changes, certificate operations, and the CA material, and a branch router has no way to tell a malicious template push from a real one. Fixed trains are 26.2.1, 26.1.2.1, 20.18.4.1, 20.15.6.1, 20.12.8.2, and 20.9.10.1; anything on 20.6, 20.7, or 20.8 has no in-place fix and needs migration, and there is no workaround that fully closes it.

Read why %6a passes and j does not →

3. The NetScaler pre-auth pair is still being exploited a week on

CVE-2026-88771 and CVE-2026-88772 · Citrix NetScaler ADC and Gateway · both CVSS 9.5, unauthenticated · CISA KEV, federal deadline passed September 30

Last week's twin NetScaler zero-days have not gone quiet. Both were abused before Citrix shipped a fix under bulletin CTX697096 on September 27, and unpatched boxes are still being hit. CVE-2026-88771 is an improper input validation flaw (CWE-20) reachable on a code path every NetScaler ADC and Gateway runs, including the default configuration, so one crafted request runs the attacker's command as the NetScaler service. CVE-2026-88772 is a memory overflow reached over DTLS, which listens on UDP port 443 by default on any VPN virtual server unless an operator turned it off, so a crafted DTLS record to that address yields code execution. Neither bug touches the management plane, so the usual guidance about locking the management interface behind ACLs and jump hosts closes neither one.

Risk read: Exploitation stays top band, and the federal deadline already passed on September 30, so any instance still unpatched is both out of compliance and in active attacker scope. Blast radius is the VPN and AAA edge: a rooted Gateway sees session tokens, terminates the tunnel every remote user rides, and sits inside the network it was meant to guard. Exposure is top band on any Gateway, VPN virtual server, or AAA virtual server reachable from the internet. Treat any box that ran unpatched through the last two weeks as a rotate-everything event once it was reachable, because a pre-auth root primitive on the edge leaves footholds a single patch does not clear.

Read how both pre-auth paths reach the edge →

Threat Actor Spotlight

No public reporting has tied a named group to this week's FortiMail or Cisco SD-WAN zero-days yet, and that absence is itself the signal. What the vendors and first responders describe is an opportunistic edge-exploitation pattern: scan the internet for a known appliance, fire a single pre-auth request the moment a bug is public or sometimes before, and drop a webshell that survives the obvious cleanup. On FortiMail that shows up as a shell at /data/bin/webconsole plus persistence binaries at /bin/smit and /data/bin/mailservice that run on normal mail flow after a GUI reinstall. On Cisco SD-WAN Manager it shows up as encoded j_security_check probes against the login path. The common thread is speed against devices most teams patch slowly, and attribution usually arrives weeks later, once forensics catch up, not on disclosure day. Hardening takeaway: do not wait for a name to act. Any internet-facing appliance that ran vulnerable, even briefly, should be treated as compromised until a hunt clears it. Watch behavior and artifacts rather than version banners, check for the specific files above, and rotate every secret the box held, because a patch closes the door the attacker used and not the ones they left open behind it.

Patch This First

FortiMail CVE-2026-104286. It is the only item this week with no patch to install, it is already being exploited, and it goes from one request to a root shell in about two minutes. There is nothing to upgrade to yet, so shut Identity-Based Encryption off at the CLI now: config system encryption ibe, then set status disable, then end. That closes the vulnerable handler without touching the rest of the mail flow, and if you were not using IBE the change is invisible to users. Then pull the management interface off the public internet, hunt every FortiMail for /data/bin/webconsole, /bin/smit, and any recent change to /data/bin/mailservice, and rotate the DKIM keys, LDAP bind credentials, and S/MIME and IBE keys on any appliance that was reachable, because a pre-auth write on a box that holds this much is a rotate-everything event.

Signed CVEasy threat-intel IOC bundle current as of 2026-10-05. The desktop app verifies the ED25519 signature before import.

Every top item this week carries a CVSS near the ceiling, and the number still cannot tell you which box is your emergency. The one to touch first is the one with no patch at all, FortiMail, where the fix is a config change and the clock is already running. Ordering that helps is built on your own exposure and on what attackers are doing today, which is the loop our CTEM platform runs with TRIS, and the loop I want this letter to run for you every Monday.

Patch well,
Chris Boker
Founder, CVEasy AI

You are receiving CVEasy Weekly because you subscribed at cveasyai.com.
CVEasy AI · This Week in Exposure · Unsubscribe