Skip to content
BLACKMESA.CA Brief

Thursday, October 1, 2026 · generated · about 5 min read

Morning Brief

Patch today vendors with the most new CVEs today

Ranked by CVE count. Each vendor opens the CVE Feed filtered to that vendor and these dates.

Top developments ranked by cross-source trending

  1. Image: The Register Security

    Microsoft catches hackers exploiting Zimbra bug before disclosure

    News The Register Security53m ago8 sources

    Attackers were poking at a critical Zimbra mail server bug weeks before it was publicly disclosed, and then moved on to steal credentials, raid mailboxes, and take deeper control of compromised systems. Microsoft Threat Intelligence said it tracked exploitation of CVE-2026-73570, an unauthenticated command injection vulnerability in Zimbra Collaboration Suite that gives attackers a potentially easy route into exposed mail servers. No stolen password or unfortunate employee clicking a dodgy link is required. An attacker can send a specially crafted email to a vulnerable internet-facing server…

    Also in Cyber Security News Infosecurity Magazine Cyber Security News +3

    View on Security Feed

  2. Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path

    News The Hacker News9h ago6 sources

    Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals. The trigger is a malicious PDF with a crafted embedded font that crashes unpatched iPhones and Macs. The code causes a crash, not an execution error. Turning the memory corruption into a working

    Also in Infosecurity Magazine Dark Reading The Register Security +3

    CVE-2026-86950 ↗View on Security Feed

  3. CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV

    News The Hacker News5h ago4 sources

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV), following reports of active exploitation. The vulnerability, tracked as CVE-2026-76504 (CVSS score: 9.8), could allow an unauthenticated, remote attacker to access an affected system with

    Also in Infosecurity Magazine CCCS Alerts & Advisories SecurityWeek +1

    View on Security Feed

  4. Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution

    News The Hacker News30 Sep5 sources

    Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-88772 (CVSS score: 9.5), has been described as a memory overflow bug in the Datagram Transport Layer Security (DTLS) protocol handling that's rooted in the NetScaler

    Also in Palo Alto Unit 42 CyberScoop The Register Security +1

    CVE-2026-88771 ↗CVE-2026-88772 ↗View on Security Feed

  5. Someone ‘Torturing’ LLMs in a Robot Prison Has Triggered the Dumbest Debate in AI Yet

    News 404 Media18h ago4 sources

    One of the most heated discussions occurring on X at the moment is about the ethics of a GitHub project in which a person is running Saw-like “torture” and “pain” experiments on a series of locally hosted large language models, causing a series of effective altruists and people who believe LLMs are sentient to beg GitHub to delete the project on the grounds that the AI is suffering and that this glorified text adventure game is somehow cruel. The saga is an outgrowth of several recent viral papers and blog posts that have sparked a wildly tiresome conversation about AI consciousness and the…

    Also in SecurityWeek Bleeping Computer The Hacker News

    View on Security Feed

  6. Google Rolls Out Gemini 4 Argon to Trusted Cyber Defenders, Plans Guardrail-Free Version

    News The Hacker News7h ago4 sources

    Google on Wednesday announced its latest frontier artificial intelligence (AI) model, Gemini 4 Argon, that it said is being rolled out to a set of trusted cyber defenders through its Fairwind Program. "It delivers frontier performance in complex workflows across real-world software engineering, enterprise knowledge work like legal and finance, and cybersecurity defense," Koray Kavukcuoglu,

    Also in Dark Reading The Record Infosecurity Magazine +2

    View on Security Feed

  7. WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory

    News The Hacker News59m ago3 sources

    Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the final payload kept returning without having to infect the site again. The backdoor has been codenamed SC after the "SC_" markers present in the injected content. Sucuri has described the malware as a "self-healing mesh" that's

    Also in Cyber Security News SANS Internet Storm Center

    View on Security Feed

  8. Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs

    News The Hacker News11h ago3 sources

    Threat actors have been observed exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway to drop web shells and attempt theft of configuration data. LevelBlue's Threat Hunt Operations & Research (THOR) team, which analyzed the exploitation activity across multiple customer environments, said it identified malicious NetScaler

    Also in The Hacker News Dark Reading CyberScoop

    View on Security Feed

  9. Critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in the wild (CVE-2026-76504)

    Research Rapid7 Blog30 Sep3 sources

    Overview On September 30, 2026, Cisco published a security advisory for CVE-2026-76504 , a critical API authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Manager. The vulnerability has a CVSSv3.1 score of 9.8 and results from improper handling of URL encoding ( CWE-177 ). An unauthenticated, remote attacker can send a crafted HTTP request that bypasses an authentication rule for a specific API endpoint, gaining access to the API with the privileges of the admin user. According to Cisco, CVE-2026-76504 is being actively exploited in the wild; Cisco PSIRT became aware of the…

    Also in Bleeping Computer CISA Alerts & Advisories

    CVE-2026-76504 ↗View on Security Feed

  10. ZDI-26-750: WatchGuard FireWare OS spamd statushdlr Stack-based Buffer Overflow Remote Code Execution Vulnerability

    Research Zero Day Initiative30 Sep2 sources

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-18145.

    Also in CCCS Alerts & Advisories Zero Day Initiative CCCS Alerts & Advisories

    View on Security Feed

Vulnerability watch what to look at, most urgent first

Details CVEProductSeverity CVSSEPSS KEVFixIn the news
Highest scoring today 10new CVEs, highest CVSS first
CVE-2026-96349 SiteSkiteSiteSkite Critical 10.0 — — None linked — CVSS 10.0No fix linked
CVE-2026-55107 kobakoelct9620 Critical 10.0 — — None linked — CVSS 10.0No fix linked
CVE-2026-102455 EasyFlow .NETDigiWin Critical 9.8 — — None linked — CVSS 9.8No fix linked
CVE-2026-102458 EasyFlow .NETDigiWin Critical 9.8 — — None linked — CVSS 9.8No fix linked
CVE-2026-88920 Apache WSS4JApache Critical 9.8 — — None linked — CVSS 9.8No fix linked
CVE-2026-76504 Catalyst Sd-Wan ManagerCisco Critical 9.8 — KEV None linked story 9, 3 sources KEVCVSS 9.8No fix linkedin the news
CVE-2026-96350 EstatikEstatik Critical 9.8 — — None linked — CVSS 9.8No fix linked
CVE-2026-97248 Booking ActivitiesBooking Activities Team Critical 9.8 — — None linked — CVSS 9.8No fix linked
CVE-2026-97274 OAuth Single Sign On – SSO (OAuth Client)miniOrange Critical 9.8 — — None linked — CVSS 9.8No fix linked
CVE-2026-82307 SOPLOGDolusoft Software Technologies Critical 9.8 — — None linked — CVSS 9.8No fix linked

Click a row, or press +, to expand it.EPSS is FIRST's estimated chance of exploitation in the next 30 days.Full CVE Feed

Worth reading quieter, still worth your time

  1. The Blue Agent POV: Investigating Multi-Platform Data Exfiltration Across AWS and GitHub

    Research Wiz Research29 Sep2 sources

    See how the Blue Agent investigated a multi-platform attack in minutes, following evidence across AWS and GitHub to uncover compromised credentials, stolen source code, and custom data exfiltration tooling

    Also in Infosecurity Magazine

    View on Security Feed

Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score. No AI writes any of this, and every number traces back to something already published on those two tools.

Top developments come from the Security Feed's cross-source trending detection. Vulnerability watch comes from the CVE Feed's daily NVD and CISA KEV sync.