TL;DR
Cisco SD-WAN Manager zero-day is actively exploited in the field with no patch available; CISA added it to KEV on Sept 30. Zimbra and Zammad suffer critical RCE attacks enabling credential theft and network access. Microsoft's 974-CVE patch batch includes critical flaws. Patch immediately and segment SD-WAN infrastructure.
Executive Summary
- Cisco Catalyst SD-WAN Manager zero-day (CVE-2026-76504) actively exploited by attackers to gain admin access; CISA added to KEV catalog with federal remediation deadline of October 3, 2026.
- Zimbra Collaboration Suite vulnerability (CVE-2026-73570, CVSS 8.9) exploited by threat actors to deploy webshells and harvest authentication secrets and mailbox data.
- Zammad open-source ticketing system compromised via zero-day vulnerability chain (CVE-2026-102489, CVE-2026-102490); Dutch Institute for Vulnerability Disclosure (DIVD) network breach attributed to these flaws.
- Over 543,000 valid credentials remain exposed in public GitHub repositories despite platform security measures.
- Attackers abuse legitimate platforms (MSP360 RMM, ChatGPT Custom GPTs) as delivery vectors for remote-access trojans and malware via social engineering.
Top Threats Today
1. Cisco Catalyst SD-WAN Manager – Critical Authentication Bypass Under Active Attack
Severity: CRITICAL Affected: Government Finance Technology
Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability (CVE-2026-76504) that allows unauthenticated remote attackers to access affected systems with admin privileges due to improper handling of URI encoding in HTTP requests [1][2]. Cisco confirmed active exploitation in the wild ⚠[2][3]. CISA added CVE-2026-76504 to the Known Exploited Vulnerabilities catalog on September 30, 2026, with a federal remediation deadline of October 3, 2026 [3]. This is a widely-deployed network infrastructure component; organizations managing SD-WAN deployments are at immediate risk of lateral movement and network compromise [1].
Sources:[1] The Hacker News[2] BleepingComputer[3] CISA KEV
Recommended Action
- Immediately isolate or air-gap SD-WAN Manager instances from untrusted networks pending patch availability
- Monitor Cisco advisories for patch release; apply immediately upon availability
- Review access logs and firewall rules to detect unusual admin-level access or configuration changes
- Implement network segmentation to limit SD-WAN Manager exposure to trusted administrative networks only
2. Zimbra Collaboration Suite – Weaponized OS Command Injection
Severity: CRITICAL Affected: Government Finance Technology
A patched security flaw in Zimbra Collaboration Suite (CVE-2026-73570, CVSS 8.9) has been actively weaponized by threat actors to deploy webshells, harvest authentication secrets, and access mailbox data, according to Microsoft Security Research findings [1]. The vulnerability is an unauthenticated operating system command injection, requiring immediate investigation of any Zimbra deployments for signs of compromise [1].
Sources:[1] The Hacker News
Recommended Action
- Verify Zimbra instances are running the latest patched version; check release notes for CVE-2026-73570 remediation
- Search mail server logs for suspicious process execution or shell command patterns indicative of webshell activity
- Reset authentication credentials (admin, service accounts) if any Zimbra instance has been online unpatched
- Implement application-level monitoring for unusual outbound connections from Zimbra processes
3. Zammad Zero-Day Chain – Ticketing System Breach and Network Intrusion
Severity: CRITICAL Affected: Technology Government
The Dutch Institute for Vulnerability Disclosure (DIVD) disclosed that its network breach was enabled by a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system (CVE-2026-102489 and CVE-2026-102490) [1]. The vulnerability chain allowed attackers to gain unauthorized access to DIVD's infrastructure; organizations using Zammad for internal ticketing or customer support are at immediate risk [1].
Sources:[1] BleepingComputer
Recommended Action
- Identify all Zammad instances in your environment and immediately isolate from internet-facing access if not already patched
- Check Zammad security advisories and GitHub repository for available patches addressing CVE-2026-102489 and CVE-2026-102490
- Audit access logs for unauthorized user creation, privilege escalation, or data exports
- Consider temporary discontinuation of Zammad use until patches are validated and deployed
4. Massive Credential Exposure in GitHub Repositories
Severity: HIGH Affected: Technology
Over 543,000 valid credentials that were exposed in public GitHub repositories remained valid as of July 2026, demonstrating the ineffectiveness of GitHub's current platform-level secrets detection and remediation workflows [1]. Exposed credentials include API keys, database passwords, and deployment tokens, creating a risk of unauthorized access to downstream systems [1].
Sources:[1] BleepingComputer
Recommended Action
- Conduct a comprehensive audit of all secrets stored in Git repositories (internal and external) using automated secret-scanning tools
- Rotate all API keys, database passwords, and authentication tokens that may have been committed to version control
- Enable GitHub's secret scanning features and require enforcement of push protections on all repositories
- Implement pre-commit hooks to block credential patterns before they are pushed
5. Social Engineering Attacks via Legitimate Platforms (MSP360, ChatGPT)
Severity: HIGH Affected: Technology Finance
Microsoft has warned of phishing campaigns distributing the legitimate MSP360 Remote Monitoring and Management (RMM) software disguised as meeting invitations, PDF lures, and software updates; once executed, the legitimate MSP360 installer can be chained to deploy ScreenConnect for secondary access [1]. Separately, threat actors are abusing ChatGPT Custom GPTs by disguising them as legitimate product offerings and directing victims to sites employing ClickFix lures to deliver remote-access trojans (RAT) [2]. Both attacks exploit trust in legitimate vendors and platforms to bypass email filtering and user awareness [1][2].
Sources:[1] The Hacker News[2] The Hacker News
Recommended Action
- Block or monitor execution of MSP360 and ScreenConnect if not required; verify all RMM deployments are authorized
- Train users to verify RMM and software update notifications through out-of-band channels before execution
- Monitor for ClickFix and other fake-support-alert campaigns; block known malicious domains at the gateway
- Restrict ChatGPT Custom GPT access in corporate environments if feasible, or monitor for suspicious redirects to external sites
Ongoing Threats
Russian state actor Star Blizzard continues to deploy CosmicPulse backdoor using a new “RedFlick” phishing tactic; Microsoft Patch Tuesday delivered 974 CVE fixes (see earlier coverage). MikroTik RouterOS critical pre-auth RCE flaws (CVE-2026-84411, CVE-2026-67276, CVE-2026-86060) confirmed by CISA; immediate patching required.
Today’s Action Checklist
- ☐ URGENT: Isolate or block untrusted network access to Cisco Catalyst SD-WAN Manager instances; monitor for unauthorized admin access
- ☐ URGENT: Verify Zimbra Collaboration Suite patches are installed; search logs for webshell indicators and reset admin credentials
- ☐ URGENT: Take Zammad instances offline if unpatched; investigate DIVD breach details for IOCs matching your environment
- ☐ HIGH: Rotate all exposed credentials found in GitHub repositories; enable secret scanning across all Git platforms
- ☐ HIGH: Deploy email and endpoint controls to block MSP360/ScreenConnect abuse and ClickFix/ChatGPT-based RAT delivery
- ☐ STANDARD: Apply MikroTik RouterOS patches for CVE-2026-84411, CVE-2026-67276, CVE-2026-86060