Why Should I Care? โ€” 2026-10-02 | ๐Ÿ”ด 4 HIGH ยท ๐ŸŸก 4 MEDIUM ยท ๐Ÿ”ต 20 RADAR ยท โšช 101 FILTERED

๐Ÿ“‹ Briefing โ€” 2026-10-02

28 vendor intel items scanned  |  ๐Ÿ”ด 4 HIGH  |  ๐ŸŸก 4 MEDIUM  |  ๐Ÿ”ต 20 RADAR  |  โšช 101 FILTERED

๐Ÿ”ด Critical โ€” action required:

  1. CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-104286) โ€” Yes, if you run Fortinet FortiMail versions 6.0.0 to 6.4.5: This vulnerability allows attackers to traverse directories and access sensitive files, potentially leading to total control of the system.
  2. Armatura LLC Armatura One (CVE-2023-46604) โ€” Yes, if you run Armatura One <4.7.2 or Armatura One (USA) <4.6.1: You are at high risk of unauthorized access and code execution.
  3. Monta monta.app (CVE-2026-95102, CVE-2026-97363, CVE-2026-97212, CVE-2026-93474) โ€” Yes, if you run Monta monta.app: all versions are affected and could allow attackers to gain unauthorized administrative control or disrupt services.
  4. Improper limitation of a pathname to a restricted directory โ€” Yes, if you run FortiGate versions 7.0.0 to 7.0.9, 6.2.0 to 6.2.10, 6.4.0 to 6.4.11, 5.6.0 to 5.6.15: this vulnerability allows unauthenticated attackers to write arbitrary files on your system.

Everything else can wait.

๐ŸŸก Medium โ€” review when time permits:

  1. CISA Malcolm โ€” Yes, if you run CISA Malcolm versions earlier than v26.06.0: multiple critical vulnerabilities could allow attackers to execute arbitrary code and gain unauthorized access.
  2. Johnson Controls EasyIO Neo Series EC and CW Controllers โ€” Yes, if you run Johnson Controls EasyIO Neo Series EC Controllers V3.3b62, V3.3b63 or CW Controllers V3.3b24, V3.3b25: an attacker could intercept sensitive data, including credentials.
  3. Meari IoT Cloud Platform OpenAPI Service โ€” Yes, if you run any version of Meari IoT Cloud Platform OpenAPI Service: attackers can manipulate device configurations and access sensitive information without proper authorization.
  4. Johnson Controls EasyIO Neo Series EC and CW Controllers โ€” Yes, if you run Johnson Controls EasyIO Neo Series EC Controllers V3.3b63, V3.3b62, CW Controllers V3.3b25, or V3.3b24: this vulnerability allows attackers to access sensitive information that could be used for further attacks.

๐Ÿ”ต 15 items on the radar โ€” see below โ†“


Why Should I Care? ๐Ÿ”ด HIGH โ€” Handle Now


CISA Adds One Known Exploited Vulnerability to Catalog

CISA Advisories [CISA KEV] | CVSS 8.8 | CVE-2026-104286

โ“ Why Should I Care?
Yes, if you run Fortinet FortiMail versions 6.0.0 to 6.4.5: This vulnerability allows attackers to traverse directories and access sensitive files, potentially leading to total control of the system.

๐ŸŽฏ Affected versions: 6.0.0 to 6.4.5
Not affected: 6.4.6 and later

๐ŸŽญ In plain English:
This vulnerability lets attackers navigate through your system's directories and access files they shouldn't be able to, which could allow them to take full control of your FortiMail system. For example, an attacker could read sensitive emails or even alter system configurations.

๐Ÿ”ง Prerequisites:

  • Running Fortinet FortiMail versions 6.0.0 to 6.4.5
  • Network access to the affected FortiMail system

โฑ Urgency: High urgency due to active exploitation and the risk of full system compromise.

โœ… Fixed in: 6.4.6, 6.4.7

๐Ÿ’ก Context: The root cause is improper validation of user-supplied input that allows directory traversal.


Armatura LLC Armatura One

CISA Advisories [CISA KEV] | CVSS 9.8 | CVE-2023-46604

โ“ Why Should I Care?
Yes, if you run Armatura One <4.7.2 or Armatura One (USA) <4.6.1: You are at high risk of unauthorized access and code execution.

๐ŸŽฏ Affected versions: Armatura One <4.7.2, Armatura One (USA) <4.6.1

๐ŸŽญ In plain English:
An attacker could exploit these vulnerabilities to gain full control over your system, allowing them to steal sensitive data or take over your physical access control systems. For example, they could unlock doors remotely or access your internal databases.

๐Ÿ”ง Prerequisites:

  • Unpatched Armatura One version <4.7.2
  • Unpatched Armatura One (USA) version <4.6.1

โฑ Urgency: High urgency due to the critical nature of the vulnerabilities and the potential for full system compromise.

โœ… Fixed in: 4.7.2, 4.6.1_USA

๐Ÿ’ก Context: The root cause includes deserialization flaws and hard-coded cryptographic keys, allowing attackers to execute code and decrypt sensitive information.


Monta monta.app

CISA Advisories | CVSS 9.4 | CVE-2026-95102, CVE-2026-97363, CVE-2026-97212, CVE-2026-93474

โ“ Why Should I Care?
Yes, if you run Monta monta.app: all versions are affected and could allow attackers to gain unauthorized administrative control or disrupt services.

๐ŸŽฏ Affected versions: all/*

๐ŸŽญ In plain English:
The vulnerability means that attackers can pretend to be charging stations and take control of the system, potentially stopping people from charging their vehicles. For example, an attacker could disrupt the charging service by sending fake commands to the system.

๐Ÿ”ง Prerequisites:

  • Access to the WebSocket endpoints
  • Lack of proper authentication mechanisms

โฑ Urgency: High urgency due to the critical infrastructure sectors affected and the potential for unauthorized administrative control and denial-of-service attacks.

๐Ÿ’ก Context: The root cause is the lack of proper authentication mechanisms and rate limiting on the WebSocket endpoints.


Improper limitation of a pathname to a restricted directory

Fortinet PSIRT | CVSS 9.8 | null

โ“ Why Should I Care?
Yes, if you run FortiGate versions 7.0.0 to 7.0.9, 6.2.0 to 6.2.10, 6.4.0 to 6.4.11, 5.6.0 to 5.6.15: this vulnerability allows unauthenticated attackers to write arbitrary files on your system.

๐ŸŽฏ Affected versions: FortiGate versions 7.0.0 to 7.0.9, 6.2.0 to 6.2.10, 6.4.0 to 6.4.11, 5.6.0 to 5.6.15
Not affected: null

๐ŸŽญ In plain English:
This vulnerability means an attacker can send special HTTP or HTTPS requests to your FortiGate device and write files anywhere on the system, even without logging in. For example, an attacker could place a malicious script in a directory that gets executed automatically, allowing them to take control of your device.

๐Ÿ”ง Prerequisites:

  • Unauthenticated access to the FortiGate device
  • The device is running one of the affected versions

โฑ Urgency: High urgency due to the critical nature of the vulnerability and reports of exploitation in the wild.

โœ… Fixed in: 7.0.10, 6.2.11, 6.4.12, 5.6.16

๐Ÿ’ก Context: The root cause is improper validation of file paths and NULL byte handling in HTTP or HTTPS requests, allowing attackers to traverse directory restrictions and write files.


Why Should I Care? ๐ŸŸก MEDIUM (4)


CISA Malcolm

CISA Advisories | CVSS 8.8 | CVE-2026-90444

โ“ Why Should I Care?
Yes, if you run CISA Malcolm versions earlier than v26.06.0: multiple critical vulnerabilities could allow attackers to execute arbitrary code and gain unauthorized access.

๐ŸŽฏ Affected versions: CISA Malcolm < v26.06.0

๐ŸŽญ In plain English:
The software has several flaws that allow attackers to inject malicious commands or scripts, potentially taking over your system. For example, an attacker could upload a file that tricks the system into running harmful commands, giving them control over your data and network.

๐Ÿ”ง Prerequisites:

  • Authenticated access
  • Network access

โฑ Urgency: High urgency due to the high CVSS score and the potential for attackers to execute arbitrary code and gain unauthorized access.

โœ… Fixed in: v26.06.0

๐Ÿ’ก Context: The root cause includes improper validation and neutralization of input, allowing attackers to exploit the system through crafted inputs.


Johnson Controls EasyIO Neo Series EC and CW Controllers

CISA Advisories | CVSS 5.4 | CVE-2026-64893

โ“ Why Should I Care?
Yes, if you run Johnson Controls EasyIO Neo Series EC Controllers V3.3b62, V3.3b63 or CW Controllers V3.3b24, V3.3b25: an attacker could intercept sensitive data, including credentials.

๐ŸŽฏ Affected versions: EasyIO Neo Series EC Controllers V3.3b62, V3.3b63; CW Controllers V3.3b24, V3.3b25

๐ŸŽญ In plain English:
This vulnerability means that sensitive information, like passwords and session data, is sent without encryption. An attacker could eavesdrop on the network and steal this information. For example, they could intercept a password and use it to log into your system.

๐Ÿ”ง Prerequisites:

  • Network access to the device
  • Device running affected firmware versions

โฑ Urgency: High urgency because an attacker could gain unauthorized access to sensitive information, potentially leading to system compromise.

โœ… Fixed in: EC firmware V3.3b64, CW firmware V3.3b26

๐Ÿ’ก Context: The root cause is the transmission of sensitive data in cleartext over the network, which allows interception by unauthorized parties.


Meari IoT Cloud Platform OpenAPI Service

CISA Advisories | CVSS 7.7 | CVE-2026-101104, CVE-2026-96613

โ“ Why Should I Care?
Yes, if you run any version of Meari IoT Cloud Platform OpenAPI Service: attackers can manipulate device configurations and access sensitive information without proper authorization.

๐ŸŽฏ Affected versions: vers:all/*

๐ŸŽญ In plain English:
The vulnerability means that anyone with access can change settings on your devices and see sensitive information like passwords and network details. For example, an attacker could change your camera settings to point at a different area or steal your device credentials.

๐Ÿ”ง Prerequisites:

  • Authenticated user access

โฑ Urgency: High urgency because attackers can manipulate device configurations and access sensitive information, leading to potential unauthorized access and data breaches.

๐Ÿ’ก Context: The root cause is a missing authorization check in the Meari IoT Cloud Platform OpenAPI Service.


Johnson Controls EasyIO Neo Series EC and CW Controllers

CISA Advisories | CVSS 3.5 | CVE-2026-64892

โ“ Why Should I Care?
Yes, if you run Johnson Controls EasyIO Neo Series EC Controllers V3.3b63, V3.3b62, CW Controllers V3.3b25, or V3.3b24: this vulnerability allows attackers to access sensitive information that could be used for further attacks.

๐ŸŽฏ Affected versions: EasyIO Neo Series EC Controllers V3.3b63, V3.3b62, CW Controllers V3.3b25, V3.3b24

๐ŸŽญ In plain English:
This vulnerability means that an attacker could peek into your system and find sensitive information, like passwords or system configurations, which they could then use to cause more damage. For example, they could use this information to take control of your building's HVAC system and manipulate temperatures.

๐Ÿ”ง Prerequisites:

  • Access to the debug port
  • No physical access controls in place

โฑ Urgency: Moderately urgent, as the exposure of sensitive information can lead to further attacks, but the CVSS score indicates a moderate impact.

โœ… Fixed in: EC firmware V3.3b64, CW firmware V3.3b26

๐Ÿ’ก Context: The root cause is a lack of proper access controls on the debug interfaces, allowing unauthorized access to sensitive information.


Why Should I Care? ๐Ÿ”ต On the Radar (20)


โšช 101 low-priority items filtered.


๐Ÿฆ… Aggregated and triaged by Donna AI  |  Sources: 8 vendor feeds  |  CISA KEV