CVE Digest

CVE Digest — October 2, 2026

  • Security Bulletin
9 CVE 2 KEV Critical
CVEProductCVSSSeveritySummaryReferences
CVE-2026-102490 KEVZammad GmbH Zammad9.8CriticalImproper privilege management (CWE-269) in all Zammad versions lets the local ‘zammad’ user escalate privileges to root (CVSS 9.8, critical). Listed in CISA KEV; chainable with CVE-2026-102489. Apply vendor mitigations and patch per BOD 26-04.
CWE-269
CVE-2026-102489 KEVZammad GmbH Zammad9.8CriticalSession fixation (CWE-384) in Zammad 6.3.0-6.5.4 enables remote code execution as the ‘zammad’ user (CVSS 9.8, critical); also present in 7.0.0-7.1.3 but not exploitable. In CISA KEV; chainable with CVE-2026-102490. Patch per vendor guidance.
CWE-384
sanate-vulnerabilita-in-fortra-boks––CriticalFortra security updates fix 8 vulnerabilities (3 critical, 3 high) in Core Privileged Access Manager (BoKS). Apply the latest patches promptly to reduce exposure.
tp-link-aggiornamenti-di-sicurezza-risolvono-8-vulnerabilita––HighTP-Link released updates fixing 8 vulnerabilities (6 high) across products. Exploitation could bypass security controls, expose sensitive data, allow arbitrary code execution, or cause denial of service. Update affected devices.
tenable-sanate-vulnerabilita-in-nessus-1––CriticalTenable security updates fix 9 vulnerabilities (1 critical, 4 high) in the Nessus vulnerability scanner. Update Nessus installations to the latest versions to remediate.
risolta-vulnerabilita-in-watchguard-endpoint-security––CriticalWatchGuard patched a critical vulnerability in Endpoint Security for Windows. A local authenticated attacker could escalate privileges and execute arbitrary code on affected systems. Update promptly.
risolte-vulnerabilita-in-apache-http-server––CriticalSecurity updates fix multiple vulnerabilities in Apache HTTP Server, including 3 critical and 13 high severity. Update Apache installations and apply the latest patches to mitigate risk.
CVE-2026-102489–9.8CriticalACN reports active exploitation of Zammad CVEs CVE-2026-102489 and CVE-2026-102490 (already patched by vendor). Chained exploitation yields code execution as ‘zammad’ user, then privilege escalation to root. Apply vendor patches urgently.
CVE-2026-104286–9.8CriticalACN reports active exploitation of a critical path traversal (CWE-22) in Fortinet FortiMail (8.0.x, 7.6.x, 7.4.x, 7.2.x). An unauthenticated attacker can write arbitrary files via crafted HTTP/HTTPS requests (CVSS 9.8). Apply Fortinet patches.

Disclaimer

This page is generated automatically from public sources. Details, scores and affected versions can change: always check the linked advisories before taking action.