FortiMail and NetScaler Exploitation Drives an Urgent Enterprise Patch Cycle
FortiMail path traversal and NetScaler SAML flaw under active exploit join CISA KEV, forcing urgent patching plus PHP, PaperCut and Spectre fixes.
Illustrative image generated with AI
Two network-facing enterprise products are under active attack. Fortinet FortiMail and Citrix NetScaler vulnerabilities have entered CISA’s Known Exploited Vulnerabilities catalog, bringing explicit remediation requirements for U.S. federal agencies.
Other security developments include a remotely triggered PHP denial of service, a signature-verification bypass in Red Hat’s oc-mirror, and a PaperCut intrusion that reached an Active Directory domain controller. Researchers also reported a Spectre v2 variant, while Glow Labs documented public screenshot exposure involving AI coding agents.
Law-enforcement operations targeted people allegedly associated with KillSec and ShinyHunters. Those arrests and group assessments remain distinct from independently verified evidence for every claimed victim or theft.
FortiMail path traversal enables unauthenticated file writes
CVE-2026-104286 is a critical path-traversal vulnerability in Fortinet FortiMail. CISA warned that attackers are actively exploiting it.
An unauthenticated attacker can use crafted HTTP or HTTPS requests to write arbitrary files on the underlying system. NVD assigns the flaw a CVSS v3.1 score of 9.8, the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, and the classification CWE-22.
NVD’s full description identifies these affected branches:
- FortiMail 8.0.0 through 8.0.1
- FortiMail 7.6.0 through 7.6.6
- FortiMail 7.4.0 through 7.4.8
- FortiMail 7.2.0 through 7.2.9
Its shorter product field only lists FortiMail through 7.4.8, so defenders should use the complete set of ranges rather than that abbreviated entry.
CVE-2026-104286 entered CISA’s KEV catalog on October 1, 2026. NVD records October 4, 2026 as the remediation deadline for U.S. federal agencies.
CISA requires mitigations consistent with vendor instructions, BOD 26-04 risk-based security-update guidance, and its “Forensics Triage Requirements.” For cloud services, organizations must follow the applicable BOD 26-04 provisions or discontinue use when mitigations are unavailable. Stakeholders must also evaluate each asset’s internet exposure and follow the directive’s patching guidance.
Defenders should inventory FortiMail versions, determine which systems are internet-accessible, apply Fortinet’s instructions, and conduct the required forensic triage. The available evidence supplies no campaign-specific IP addresses, domains, or file hashes.
NetScaler attacks depend on SAML deployment conditions
Citrix released security updates for CVE-2026-88779, a NetScaler vulnerability reportedly used in targeted zero-day attacks.
The issue is described as a memory overflow that can produce denial of service. Exploitation under the reported scenario requires a customer-managed NetScaler ADC or NetScaler Gateway deployment configured as either a SAML service provider (SP) or SAML identity provider (IdP).
NVD’s full description gives the following affected-version thresholds:
- NetScaler ADC before 14.1-73.41
- NetScaler ADC before 13.1-64.28
- NetScaler ADC before 14.1-73.41 FIPS
- NetScaler ADC before 13.1-37.282
- NetScaler Gateway before 14.1-73.41
- NetScaler Gateway before 13.1-64.28
The severity assessments differ. The weekly recap reports 8.7, while NVD assigns CVSS v3.1 7.5, with CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H and CWE-119. The supplied reporting does not explain that discrepancy.
CISA added CVE-2026-88779 to KEV on October 4, 2026. The federal remediation deadline is October 7, 2026. The required action is to follow vendor mitigations, BOD 26-04, and CISA’s forensic-triage requirements. Applicable cloud services must follow the directive or be discontinued if mitigations are unavailable.
Administrators should check both the installed release and the system’s SAML role. Although Citrix issued updates, the available material does not include installation steps or a separate workaround.
The two entries are part of a broader run of KEV additions involving Fortinet or Citrix. Other additions during the preceding 90 days include CVE-2026-88771 and CVE-2026-88772 on September 27, 2026; CVE-2025-25249 and CVE-2026-19490 on September 9, 2026; CVE-2026-8452 on August 26, 2026; and CVE-2025-68686 on July 27, 2026.
PHP SOAP recursion can exhaust worker pools
PHP’s ext-soap contains a remotely reachable denial-of-service vulnerability tracked as CVE-2026-91765 and GHSA-rgrp-mwpx-f6rm. GitHub published the advisory on September 24, 2026.
The vulnerable cleanup_xml_node() routine recursively traverses parsed XML without limiting nesting depth. It executes after libxml2 has parsed the document, meaning libxml2’s own parsing limits do not constrain this later PHP operation.
An unauthenticated attacker can post a SOAP request containing tens of thousands of nested elements to a SoapServer endpoint. The advisory’s proof of concept constructs 50,000 nested <a> elements and causes a SIGSEGV inside cleanup_xml_node().
No authentication, WSDL interaction, or special configuration is required. Under PHP-FPM, the worker processing the request terminates; repeated requests can exhaust the pool and take the endpoint offline. The advisory classifies the result as denial of service and says stack exhaustion does not provide control over the crash.
Affected versions are those below 8.2.34, 8.3.35, 8.4.26, and 8.5.11 in their respective release lines. Those releases are also the patched versions.
The fix adds SOAP_MAX_XML_DEPTH with a value of 2048 and introduces SOAP_MAX_DECODE_DEPTH. It also replaces recursive cleanup and WSDL-search operations with iterative processing, while tracking decode depth to reject cyclic or excessively long href chains.
The advisory identifies two other recursion paths: master_to_zval_int() in ext/soap/php_encoding.c and get_node_with_attribute_recursive_ex() in ext/soap/php_xml.c. NVD classifies the vulnerability as CWE-674, while the GitHub advisory lists no CWE. Both assign a CVSS score of 7.5.
oc-mirror may accept malicious release payloads
Red Hat rates CVE-2026-75939 as Important. The flaw affects openshift/oc-mirror and its validation of PGP signatures for release images.
The tool checks for signature errors before processing the complete signed body. An attacker capable of intercepting or altering traffic to the signature endpoint could provide a PGP message containing a valid Red Hat release key ID but a forged signature.
If the check is bypassed, oc-mirror could place a malicious release payload into a disconnected registry. Software subsequently obtained from that registry could therefore lose its expected integrity protections.
Red Hat assigns a preliminary CVSS v3 score of 7.4, with CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N and CWE-347. The issue is associated with Bugzilla 2517976.
The Red Hat assessment states that mitigation is either unavailable or that current options do not meet its Product Security criteria for deployment, broad applicability, or stability. It does not provide a workaround or fixed build.
Four Wireshark issues were also detailed. CVE-2026-95389 affects SCTP dissection and scores 8.1. CVE-2026-95391 crashes the ZigBee ZCL dissector, CVE-2026-96419 can cause a profile-import crash and possible code execution, and CVE-2026-96421 causes an infinite loop and memory leak during USB HID dissection. The latter three score 5.5.
PaperCut exploitation reached a domain controller
In late August 2026, attackers reportedly exploited PaperCut MF vulnerabilities CVE-2026-82078 and CVE-2026-81578 as zero-days.
The initial exploitation loaded an in-memory Java loader, which deployed a web shell. Operators then used that shell to install a trojanized Microsoft Copilot binary containing an AdaptixC2 implant.
AdaptixC2 is the post-compromise framework in this chain, not the identified operator. Its lateral-movement module was used to steal a token from a process running under a domain-privileged service account, allowing movement to a domain controller.
Once there, the attackers dumped credentials to recover the service account’s NTLM hash and enabled Windows Restricted Admin mode. They ultimately dumped the Active Directory NTDS.dit database in an attempt to obtain password hashes for all domain accounts.
The supplied recap does not name an operator or include detection indicators for this intrusion. That limitation applies to the available excerpt and does not establish what the underlying eSentire reporting may contain.
A separate phishing operation was attributed to the Russian state-sponsored actor Star Blizzard. In that activity, RedFlick is the delivery technique, while CosmicPulse is the custom backdoor delivered at the end of the chain.
The operator reportedly sent invitation-themed messages and followed a victim’s reply with a password-protected archive. That archive started the RedFlick sequence, which established scheduled tasks. Microsoft said the flow required one user interaction, compared with multiple actions in the actor’s earlier ClickFix-based infection chains.
Researchers also reported Branch Target Reuse, a Spectre v2 variant that manipulates stale branch-predictor information after a JIT engine reuses memory. They claimed average Linux root-password recovery times of three minutes on Raptor Cove and five minutes on Lion Cove. The available evidence does not establish exploitation in the wild or provide a mitigation.
PixelLeak exposure and cybercrime arrests
Glow Labs reported that AI coding agents placed more than 13,000 sensitive screenshots associated with 343 companies in public GitHub repositories. The activity was named PixelLeak, and about one-third of the reported exposures involved gitshot.
The investigated cases began when developers asked agents to demonstrate that visual changes worked. Agents then made screenshots available to reviewers through adjacent public repositories without accounting for the resulting exposure. The supplied recap provides aggregate findings but does not identify the affected companies, repositories, or screenshot contents.
Police in Spain also apprehended a 16-year-old suspected of leading KillSec, also known as Kill Security Ransomware Group. Under Operation KillSwitch, authorities provisionally arrested three suspects and searched eight properties in Greece, Romania, Spain, and the U.K.
Europol said authorities took control of KillSec’s leak site on September 30, 2026, securing at least 110 terabytes of data. It estimates that the group launched around 1,000 attacks after emerging in 2024, with at least half succeeding. Group-IB identified 274 publicly claimed victims and characterized KillSec as both a ransomware operator and a data broker.
Those figures remain attributed to Europol and Group-IB. A listing on an extortion site does not independently verify that the claimed victim was compromised or that data was stolen.
The recap separately reported two arrests involving alleged ShinyHunters associates: a 24-year-old Amsterdam man believed to be Pepijn van der Stap, and Saif al-Din Khader, detained by Jordanian authorities. Their identities and relationships with the group are reported attributions, not independently established findings in the supplied evidence.
Sources
This article is an original reworking based on the sources below.
- primary sourceRed Hat
- primary sourceGitHub Security Advisory
- The Hacker News
CVEs covered in this article
- CVE-2026-104286Critical9.8An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the
- CVE-2026-95389High8.1SCTP protocol dissector crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service
- CVE-2026-91765High7.5cleanup_xml_node() in the SOAP XML parser recurses once per XML nesting level with no depth limit. An unauthenticated attacker can post a SOAP request containing tens of thousands of nested elements to any SoapServer endpoint, exhaust the stack and crash the process. The same unbounded recursion exi
- CVE-2026-88779High7.5Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.
- CVE-2026-75939High7.4A flaw was found in openshift/oc-mirror. The tool incorrectly verifies PGP (Pretty Good Privacy) release image signatures by checking for signature errors before the entire signed body is processed, leading to a bypass of the signature verification. A remote attacker, by intercepting or manipulating
- CVE-2026-95391Medium5.5ZigBee ZCL protocol dissector crash in 4.6.0 to 4.6.8 allows denial of service
- CVE-2026-96419Medium5.5Profile import crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service and possible code execution
- CVE-2026-96421Medium5.5USB HID protocol dissector infinite loop and memory leak in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service




