Automatic post. Built by KEH-TECH from CISA’s Known Exploited Vulnerabilities catalog, as read by the Patch Tuesday hub, and published without editing. The figures are the source’s own; follow the links for the full detail.
Between 28 September 2026 and 4 October 2026, CISA added 6 entries to its list of vulnerabilities being exploited in the wild. US federal agencies must fix these by the deadline shown; everyone else should treat that date as the latest sensible one.
Added this week
CVE-2026-86950Apple Multiple Products Out-of-Bounds Write Vulnerability. Added 29 Sep; federal deadline 2 October 2026.CVE-2026-76504Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability. Added 30 Sep; federal deadline 3 October 2026.CVE-2026-104286Fortinet FortiMail Path Traversal Vulnerability. Added 1 Oct; federal deadline 4 October 2026.CVE-2026-102489Zammad GmbH Zammad Session Fixation Vulnerability. Added 2 Oct; federal deadline 5 October 2026.CVE-2026-102490Zammad GmbH Zammad Improper Privilege Management Vulnerability. Added 2 Oct; federal deadline 5 October 2026.CVE-2026-88779Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability. Added 4 Oct; federal deadline 7 October 2026.
Running any of these? Each CVE’s vendor advisory has the fix or the workaround. Found one in your environment? The Patch Panel is the place to compare notes.