DefenStory
WEEKLY VULNERABILITY BRIEF

This Week’s
Vulnerabilities

These summaries help your organization assess impact and review response capabilities, beyond simply listing vulnerability news.

Disclosure Period: Sep 28–Oct 3, 2026Based on newly disclosed information2 selected vulnerabilities
Last reviewed Oct 3, 2026 · Summary based on public advisories
CVE-2026-76504

Cisco Catalyst SD-WAN Manager API Authentication Bypass

Cisco · First disclosed Sep 30, 2026 · CVSS 3.1 9.8 (Critical)
Exploitation confirmed · Listed in CISA KEV

What Is the Issue?

An authentication bypass in API request processing may allow an unauthenticated remote attacker to gain administrative privileges. Prioritize reviewing the management system’s network exposure and access controls.

Priority Checks

  • Presence and installed version of Catalyst SD-WAN Manager
  • External accessibility of management APIs and interfaces
  • Whether the fixed version listed in the vendor advisory is installed
  • Suspicious activity in administrative accounts and system logs
Asset Owners

Confirm the product, version, and internet exposure, and update the asset inventory.

Security Operations

Plan upgrades to fixed versions according to the advisory and review relevant logs.

Managers and Decision-Makers

Assign action owners and deadlines, and approve operational impact and compensating controls.

Base remediation decisions on affected and fixed versions in Cisco’s latest advisory. CVSS does not equal organizational risk; consider asset criticality and exposure as well.
CVE-2026-104286

Fortinet FortiMail Path Traversal and Arbitrary File Write

Fortinet · Disclosed Oct 1, 2026 · CVSS 9.8 (Critical)
Exploitation reported

What Is the Issue?

In certain versions, path traversal and NULL byte handling issues may allow unauthenticated file writes. Confirm the exact version, as impact may depend on the environment and feature configuration.

Priority Checks

  • FortiMail version and whether IBE is enabled
  • Whether the management GUI is directly exposed to the internet
  • Temporary mitigations and fixed release status in the vendor advisory
  • Mail security appliance and management interface logs
Asset Owners

Check affected versions and review the inventory of externally exposed devices and services.

Security Operations

Review mitigations according to the vendor’s latest notice and monitor unusual activity.

Response Owners

If immediate remediation is difficult, manage exposure reduction, temporary controls, and follow-up patch schedules.

Fixed versions and mitigations may change shortly after disclosure. This is a summary as reviewed on Oct 3, 2026; consult Fortinet’s current advisory before taking action.