Skip to content
BLACKMESA.CA Brief

Friday, October 2, 2026 · generated · about 5 min read

Morning Brief

Patch today vendors with the most new CVEs today

Ranked by CVE count. Each vendor opens the CVE Feed filtered to that vendor and these dates.

Top developments ranked by cross-source trending

  1. Image: Cyber Security News

    Hackers Turned a Microsoft SQL Server Into a Command and Data Exfiltration Channel

    News Cyber Security News52m ago11 sources

    Hackers turned a Microsoft SQL Server into a channel for running commands and moving collected files in an intrusion linked to a Viva Aerobus environment. Their own publicly accessible server then exposed attack tools and stolen material to unrelated internet users. The activity, observed between September 25 and 29, 2026, involved credential harvesting, source code collection, and preparation to access additional systems. The investigation did not establish how the attackers first entered the environment or identify a named malware family. The available records describe a toolkit rather than…

    Also in Infosecurity Magazine The Record SecurityWeek +3

    View on Security Feed

  2. Fortinet sounds the alarm over actively exploited FortiMail zero-day

    News The Register Security4h ago4 sources

    Fortinet is warning customers to lock down FortiMail after attackers started exploiting a critical bug that lets them write files to vulnerable systems without logging in. The flaw, tracked as CVE-2026-104286, carries a CVSS score of 9.8 and affects multiple versions of Fortinet's email security platform. Fortinet describes the vulnerability as a combination of path traversal and improper handling of null characters in FortiMail's web interface. An unauthenticated attacker can exploit it using specially crafted HTTP or HTTPS requests to write arbitrary files to the underlying system. Writing…

    Also in SecurityWeek Bleeping Computer CISA Alerts & Advisories

    CVE-2026-104286 ↗View on Security Feed

  3. SMTP is the key: BPFDoor and AVERAT hitting the network edge

    Research Rapid7 Blog1h ago3 sources

    Overview Rapid7 tracked a set of Linux samples that blend into the software and device conventions of the telecom environments they target. The set spans a newly observed BPFDoor variant, a BPF Rekoobe build seen against South Korean targets, a dropper, and six builds of a Linux implant we track as AVERAT , deployed against Taiwanese appliances. Additionally, we provide source code details of the Rapid7 BPFDoor controller introduced in our April 2026 blog, Stealthy BPFDoor Variants are a Needle That Looks Like Hay . The chain uses two binaries. A dropper writes a shell script to the…

    Also in Dark Reading The Hacker News

    View on Security Feed

  4. Google Rolls Out Gemini 4 Argon to Trusted Cyber Defenders, Plans Guardrail-Free Version

    News The Hacker News1 Oct4 sources

    Google on Wednesday announced its latest frontier artificial intelligence (AI) model, Gemini 4 Argon, that it said is being rolled out to a set of trusted cyber defenders through its Fairwind Program. "It delivers frontier performance in complex workflows across real-world software engineering, enterprise knowledge work like legal and finance, and cybersecurity defense," Koray Kavukcuoglu,

    Also in CCCS Alerts & Advisories Dark Reading Infosecurity Magazine +1

    View on Security Feed

  5. ZDI-26-750: WatchGuard FireWare OS spamd statushdlr Stack-based Buffer Overflow Remote Code Execution Vulnerability

    Research Zero Day Initiative30 Sep2 sources

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-18145.

    Also in CCCS Alerts & Advisories CCCS Alerts & Advisories Zero Day Initiative

    View on Security Feed

  6. Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes

    News The Hacker News9h ago2 sources

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerability, tracked as CVE-2026-104286 (CVSS score: 9.8), allows unauthenticated attackers to write arbitrary files on the underlying system. "An improper

    Also in CCCS Alerts & Advisories

    View on Security Feed

  7. CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV

    News The Hacker News1 Oct3 sources

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV), following reports of active exploitation. The vulnerability, tracked as CVE-2026-76504 (CVSS score: 9.8), could allow an unauthenticated, remote attacker to access an affected system with

    Also in Infosecurity Magazine CCCS Alerts & Advisories The Hacker News

    View on Security Feed

  8. Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools

    News The Hacker News6h ago2 sources

    Google has announced a new security measure that limits access to Android's accessibility services to verified applications classified as Accessibility Tools when Advanced Protection is enabled. With malicious Android applications abusing the API serving as the main conduit for malware and financial fraud, the tech giant said the move would block a major attack pathway. Advanced Protection is a

    Also in SecurityWeek

    View on Security Feed

  9. macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor

    News SecurityWeek1h ago2 sources

    The dropper “carries a complete universal Mach-O inside itself, roughly 756 KB in the development build, and extracts it at runtime.

    Also in Infosecurity Magazine

    View on Security Feed

  10. Exposed WordPress Backups Became a Gold Mine of AWS and Email Credentials

    News Cyber Security News2h ago2 sources

    Exposed WordPress backups have become a valuable source of cloud and email credentials for attackers using a toolkit called TIKTOUK. Rather than relying on one technique, its components search websites for sensitive files, recover stored passwords, and collect secrets from JavaScript delivered to visitors. The operation was already active at scale when researchers first observed it. A leaked control panel contained approximately 50,000 real server-side credentials across about 37,000 domains, including hundreds of AWS keys that the attackers had validated as active. LevelBlue researchers…

    Also in The Hacker News

    View on Security Feed

Vulnerability watch what to look at, most urgent first

Details CVEProductSeverity CVSSEPSS KEVFixIn the news
Highest scoring today 10new CVEs, highest CVSS first
CVE-2026-79901 BoKS Manager boks-serverMicrosoft Critical 9.9 — — None linked — CVSS 9.9No fix linked
CVE-2026-96658 Red Hat Satellite 6.16 for RHEL 8Red Hat Critical 9.9 — — None linked — CVSS 9.9No fix linked
CVE-2026-93698 cPanelWebpros Critical 9.9 — — None linked — CVSS 9.9No fix linked
CVE-2026-15989 Super Forms – Drag & Drop Form BuilderWordPress Critical 9.8 — — None linked — CVSS 9.8No fix linked
CVE-2026-75957 Ultimate Multisite – WordPress Multisite SaaS & WaaS PlatformWordPress Critical 9.8 — — None linked — CVSS 9.8No fix linked
CVE-2026-103244 ground-stationsgoudelis Critical 9.8 — — None linked — CVSS 9.8No fix linked
CVE-2026-103752 AuthorizerPaul Ryan Critical 9.8 — — None linked — CVSS 9.8No fix linked
CVE-2026-12627 Fortra's Core Privileged Access Manager (BoKS)Fortra Critical 9.8 — — None linked — CVSS 9.8No fix linked
CVE-2026-56154 Apache HTTP ServerApache Critical 9.8 — — None linked — CVSS 9.8No fix linked
CVE-2026-57941 Apache HTTP ServerApache Critical 9.8 — — None linked — CVSS 9.8No fix linked

Click a row, or press +, to expand it.EPSS is FIRST's estimated chance of exploitation in the next 30 days.Full CVE Feed

Worth reading quieter, still worth your time

  1. Critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in the wild (CVE-2026-76504)

    Research Rapid7 Blog30 Sep2 sources

    Overview On September 30, 2026, Cisco published a security advisory for CVE-2026-76504 , a critical API authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Manager. The vulnerability has a CVSSv3.1 score of 9.8 and results from improper handling of URL encoding ( CWE-177 ). An unauthenticated, remote attacker can send a crafted HTTP request that bypasses an authentication rule for a specific API endpoint, gaining access to the API with the privileges of the admin user. According to Cisco, CVE-2026-76504 is being actively exploited in the wild; Cisco PSIRT became aware of the…

    Also in CISA Alerts & Advisories

    CVE-2026-76504 ↗View on Security Feed

Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score. No AI writes any of this, and every number traces back to something already published on those two tools.

Top developments come from the Security Feed's cross-source trending detection. Vulnerability watch comes from the CVE Feed's daily NVD and CISA KEV sync.