CISA adds Zammad flaws to exploited-vulnerabilities catalog; FortiMail zero-day tops the week's KEV batch
Tags Policy & Law · Product
CISA's Known Exploited Vulnerabilities catalog added chainable Zammad session-fixation and privilege-escalation flaws (CVE-2026-102489/102490) on Oct. 2, alongside a FortiMail path-traversal/NULL-byte zero-day (CVE-2026-104286) added Oct. 1 and Cisco, Citrix and Apple bugs, all with three-day remediation deadlines. The Zammad pair can be chained to reach remote code execution as root, and FortiMail CVE-2026-104286 (Fortinet advisory FG-IR-26-175) lets an unauthenticated attacker write arbitrary files via crafted HTTP/HTTPS requests. The same week's batch includes Cisco Catalyst SD-WAN Manager CVE-2026-76504 (added Sept. 30) and Apple multiple-products CVE-2026-86950 (added Sept. 29). CISA requires forensic triage under BOD 26-04 for these entries and directs agencies to apply vendor mitigations or discontinue use.
Technical significance
The three-day remediation deadlines compress the patch window for federal agencies and, by extension, the vendors' broader customer bases, making these flaws operationally urgent for any organization running Zammad helpdesk, FortiMail gateways or Cisco SD-WAN Manager. The Zammad chain is notable because two individually moderate flaws combine into root-level remote code execution, a pattern defenders should treat as a single high-severity exposure. FortiMail's unauthenticated arbitrary-file-write is the kind of pre-auth primitive that historically precedes widespread exploitation, so perimeter email gateways warrant priority patching.