InfoSecNexus briefing

Live Cybersecurity Brief for October 3, 2026: Active Threats, CVEs, and Vendor Advisories

Cybersecurity analyst monitoring a holographic shield and threat map

A continuously updated operational brief built from current government, vulnerability-database, open-source, and vendor security advisories.

As of October 3, 2026 12:15 am IST, this edition tracks 16 prioritized developments, including 5 known-exploited entries, 6 critical records, and 0 high-severity records. Treat the list as a starting point: final urgency depends on deployed versions, exposure, privilege, and available compensating controls.

Executive security snapshot

The highest-value work is to connect each advisory to a real asset and an accountable owner. Known exploitation and direct vendor warnings move ahead of ordinary backlog scoring, while newly disclosed records still require version and reachability checks before a response team declares exposure.

Top developments for October 3, 2026

CVE-2026-102490: Zammad GmbH Zammad Improper Privilege Management Vulnerability

CISA Known Exploited Vulnerabilities | October 2, 2026 5:30 am IST | Known Exploited | CVSS 9.8

Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489.

Why it matters: Zammad GmbH Zammad belongs in an exploit-led queue only after the affected product is matched to a reachable asset and accountable owner.

What to verify: Confirm the affected version and reachable component, preserve useful telemetry, apply the publisher guidance, and record the evidence used to close the item.

Open the original source record

CVE-2026-102489: Zammad GmbH Zammad Session Fixation Vulnerability

CISA Known Exploited Vulnerabilities | October 2, 2026 5:30 am IST | Known Exploited | CVSS 9.8

Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490.

Why it matters: Zammad GmbH Zammad belongs in an exploit-led queue only after the affected product is matched to a reachable asset and accountable owner.

What to verify: Start with asset ownership and exposure, compare the fixed release with the deployed build, and validate both security behavior and service health afterward.

Open the original source record

CVE-2026-104286: Fortinet FortiMail Path Traversal Vulnerability

CISA Cybersecurity Advisories | October 1, 2026 5:30 pm IST | Known Exploited

Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

Why it matters: Fortinet FortiMail commonly protects an internet edge or management boundary. Exposure there can affect remote access, traffic inspection, credentials, and the trust placed in downstream systems.

What to verify: Check the running firmware and model, restrict management access, compare configuration changes and new accounts, preserve independent logs, and rotate credentials if compromise cannot be excluded.

Open the original source record

CVE-2026-76504: Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability

CISA Cybersecurity Advisories | September 30, 2026 5:30 pm IST | Known Exploited

Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request.

Why it matters: Cisco Catalyst SD-WAN Manager commonly protects an internet edge or management boundary. Exposure there can affect remote access, traffic inspection, credentials, and the trust placed in downstream systems.

What to verify: Check the running firmware and model, restrict management access, compare configuration changes and new accounts, preserve independent logs, and rotate credentials if compromise cannot be excluded.

Open the original source record

CVE-2026-19652: The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in…

NIST National Vulnerability Database | October 2, 2026 7:47 pm IST | CRITICAL | CVSS 9.8

The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.0. This is due to the `dmem_form_submit_handler()` function determining the new user's role by iterating all WordPress roles and calling `password_verify()` against an attacker-controlled bcrypt hash supplied in the `form_id` POST parameter, with no validation or whitelist of allowed roles. This makes it possible for unauthenticated attackers to register a new account with the administrator role by submitting…

Why it matters: The Divi Membership plugin for WordPress is vulnerable to Privilege Escalation in… may sit directly on a public website, so a vulnerable core, plugin, or theme can turn a routine content system into an initial-access path.

What to verify: Record the exact WordPress core and extension versions, confirm whether the affected feature is enabled, review administrator accounts, and inspect web requests before and after the update.

Open the original source record

CVE-2026-86950: Apple Multiple Products Out-of-Bounds Write Vulnerability

CISA Cybersecurity Advisories | September 29, 2026 5:30 pm IST | Known Exploited

Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.

Why it matters: Apple Multiple Products is a memory-safety issue whose practical impact depends on the reachable parser, process privileges, platform protections, and reliability of attacker-controlled input.

What to verify: Confirm the exact affected build and component exposure, update from the vendor channel, review crash and restart telemetry, and keep network containment in place until the fixed process is running.

Open the original source record

CVE-2026-97637: The JSON API Auth plugin for WordPress is vulnerable to Authentication Bypass…

NIST National Vulnerability Database | October 2, 2026 1:47 pm IST | CRITICAL | CVSS 9.8

Continue reading the full briefing.

Corrections and tips

Need to add context to this briefing?

Send corrections, security tips, source updates, or collaboration notes through the contact page so the editorial team can review them properly.

Contact InfoSecNexus