Why Should I Care? โ 2026-10-02 | ๐ด 4 HIGH ยท ๐ก 4 MEDIUM ยท ๐ต 20 RADAR ยท โช 101 FILTERED
๐ Briefing โ 2026-10-02
28 vendor intel items scanned | ๐ด 4 HIGH | ๐ก 4 MEDIUM | ๐ต 20 RADAR | โช 101 FILTERED
๐ด Critical โ action required:
- CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-104286) โ Yes, if you run Fortinet FortiMail versions 6.0.0 to 6.4.5: This vulnerability allows attackers to traverse directories and access sensitive files, potentially leading to total control of the system.
- Armatura LLC Armatura One (CVE-2023-46604) โ Yes, if you run Armatura One <4.7.2 or Armatura One (USA) <4.6.1: You are at high risk of unauthorized access and code execution.
- Monta monta.app (CVE-2026-95102, CVE-2026-97363, CVE-2026-97212, CVE-2026-93474) โ Yes, if you run Monta monta.app: all versions are affected and could allow attackers to gain unauthorized administrative control or disrupt services.
- Improper limitation of a pathname to a restricted directory โ Yes, if you run FortiGate versions 7.0.0 to 7.0.9, 6.2.0 to 6.2.10, 6.4.0 to 6.4.11, 5.6.0 to 5.6.15: this vulnerability allows unauthenticated attackers to write arbitrary files on your system.
Everything else can wait.
๐ก Medium โ review when time permits:
- CISA Malcolm โ Yes, if you run CISA Malcolm versions earlier than v26.06.0: multiple critical vulnerabilities could allow attackers to execute arbitrary code and gain unauthorized access.
- Johnson Controls EasyIO Neo Series EC and CW Controllers โ Yes, if you run Johnson Controls EasyIO Neo Series EC Controllers V3.3b62, V3.3b63 or CW Controllers V3.3b24, V3.3b25: an attacker could intercept sensitive data, including credentials.
- Meari IoT Cloud Platform OpenAPI Service โ Yes, if you run any version of Meari IoT Cloud Platform OpenAPI Service: attackers can manipulate device configurations and access sensitive information without proper authorization.
- Johnson Controls EasyIO Neo Series EC and CW Controllers โ Yes, if you run Johnson Controls EasyIO Neo Series EC Controllers V3.3b63, V3.3b62, CW Controllers V3.3b25, or V3.3b24: this vulnerability allows attackers to access sensitive information that could be used for further attacks.
๐ต 15 items on the radar โ see below โ
Why Should I Care? ๐ด HIGH โ Handle Now
CISA Adds One Known Exploited Vulnerability to Catalog
CISA Advisories [CISA KEV] | CVSS 8.8 | CVE-2026-104286
โ Why Should I Care?
Yes, if you run Fortinet FortiMail versions 6.0.0 to 6.4.5: This vulnerability allows attackers to traverse directories and access sensitive files, potentially leading to total control of the system.
๐ฏ Affected versions: 6.0.0 to 6.4.5
Not affected: 6.4.6 and later
๐ญ In plain English:
This vulnerability lets attackers navigate through your system's directories and access files they shouldn't be able to, which could allow them to take full control of your FortiMail system. For example, an attacker could read sensitive emails or even alter system configurations.
๐ง Prerequisites:
- Running Fortinet FortiMail versions 6.0.0 to 6.4.5
- Network access to the affected FortiMail system
โฑ Urgency: High urgency due to active exploitation and the risk of full system compromise.
โ Fixed in: 6.4.6, 6.4.7
๐ก Context: The root cause is improper validation of user-supplied input that allows directory traversal.
Armatura LLC Armatura One
CISA Advisories [CISA KEV] | CVSS 9.8 | CVE-2023-46604
โ Why Should I Care?
Yes, if you run Armatura One <4.7.2 or Armatura One (USA) <4.6.1: You are at high risk of unauthorized access and code execution.
๐ฏ Affected versions: Armatura One <4.7.2, Armatura One (USA) <4.6.1
๐ญ In plain English:
An attacker could exploit these vulnerabilities to gain full control over your system, allowing them to steal sensitive data or take over your physical access control systems. For example, they could unlock doors remotely or access your internal databases.
๐ง Prerequisites:
- Unpatched Armatura One version <4.7.2
- Unpatched Armatura One (USA) version <4.6.1
โฑ Urgency: High urgency due to the critical nature of the vulnerabilities and the potential for full system compromise.
โ Fixed in: 4.7.2, 4.6.1_USA
๐ก Context: The root cause includes deserialization flaws and hard-coded cryptographic keys, allowing attackers to execute code and decrypt sensitive information.
Monta monta.app
CISA Advisories | CVSS 9.4 | CVE-2026-95102, CVE-2026-97363, CVE-2026-97212, CVE-2026-93474
โ Why Should I Care?
Yes, if you run Monta monta.app: all versions are affected and could allow attackers to gain unauthorized administrative control or disrupt services.
๐ฏ Affected versions: all/*
๐ญ In plain English:
The vulnerability means that attackers can pretend to be charging stations and take control of the system, potentially stopping people from charging their vehicles. For example, an attacker could disrupt the charging service by sending fake commands to the system.
๐ง Prerequisites:
- Access to the WebSocket endpoints
- Lack of proper authentication mechanisms
โฑ Urgency: High urgency due to the critical infrastructure sectors affected and the potential for unauthorized administrative control and denial-of-service attacks.
๐ก Context: The root cause is the lack of proper authentication mechanisms and rate limiting on the WebSocket endpoints.
Improper limitation of a pathname to a restricted directory
Fortinet PSIRT | CVSS 9.8 | null
โ Why Should I Care?
Yes, if you run FortiGate versions 7.0.0 to 7.0.9, 6.2.0 to 6.2.10, 6.4.0 to 6.4.11, 5.6.0 to 5.6.15: this vulnerability allows unauthenticated attackers to write arbitrary files on your system.
๐ฏ Affected versions: FortiGate versions 7.0.0 to 7.0.9, 6.2.0 to 6.2.10, 6.4.0 to 6.4.11, 5.6.0 to 5.6.15
Not affected: null
๐ญ In plain English:
This vulnerability means an attacker can send special HTTP or HTTPS requests to your FortiGate device and write files anywhere on the system, even without logging in. For example, an attacker could place a malicious script in a directory that gets executed automatically, allowing them to take control of your device.
๐ง Prerequisites:
- Unauthenticated access to the FortiGate device
- The device is running one of the affected versions
โฑ Urgency: High urgency due to the critical nature of the vulnerability and reports of exploitation in the wild.
โ Fixed in: 7.0.10, 6.2.11, 6.4.12, 5.6.16
๐ก Context: The root cause is improper validation of file paths and NULL byte handling in HTTP or HTTPS requests, allowing attackers to traverse directory restrictions and write files.
Why Should I Care? ๐ก MEDIUM (4)
CISA Malcolm
CISA Advisories | CVSS 8.8 | CVE-2026-90444
โ Why Should I Care?
Yes, if you run CISA Malcolm versions earlier than v26.06.0: multiple critical vulnerabilities could allow attackers to execute arbitrary code and gain unauthorized access.
๐ฏ Affected versions: CISA Malcolm < v26.06.0
๐ญ In plain English:
The software has several flaws that allow attackers to inject malicious commands or scripts, potentially taking over your system. For example, an attacker could upload a file that tricks the system into running harmful commands, giving them control over your data and network.
๐ง Prerequisites:
- Authenticated access
- Network access
โฑ Urgency: High urgency due to the high CVSS score and the potential for attackers to execute arbitrary code and gain unauthorized access.
โ Fixed in: v26.06.0
๐ก Context: The root cause includes improper validation and neutralization of input, allowing attackers to exploit the system through crafted inputs.
Johnson Controls EasyIO Neo Series EC and CW Controllers
CISA Advisories | CVSS 5.4 | CVE-2026-64893
โ Why Should I Care?
Yes, if you run Johnson Controls EasyIO Neo Series EC Controllers V3.3b62, V3.3b63 or CW Controllers V3.3b24, V3.3b25: an attacker could intercept sensitive data, including credentials.
๐ฏ Affected versions: EasyIO Neo Series EC Controllers V3.3b62, V3.3b63; CW Controllers V3.3b24, V3.3b25
๐ญ In plain English:
This vulnerability means that sensitive information, like passwords and session data, is sent without encryption. An attacker could eavesdrop on the network and steal this information. For example, they could intercept a password and use it to log into your system.
๐ง Prerequisites:
- Network access to the device
- Device running affected firmware versions
โฑ Urgency: High urgency because an attacker could gain unauthorized access to sensitive information, potentially leading to system compromise.
โ Fixed in: EC firmware V3.3b64, CW firmware V3.3b26
๐ก Context: The root cause is the transmission of sensitive data in cleartext over the network, which allows interception by unauthorized parties.
Meari IoT Cloud Platform OpenAPI Service
CISA Advisories | CVSS 7.7 | CVE-2026-101104, CVE-2026-96613
โ Why Should I Care?
Yes, if you run any version of Meari IoT Cloud Platform OpenAPI Service: attackers can manipulate device configurations and access sensitive information without proper authorization.
๐ฏ Affected versions: vers:all/*
๐ญ In plain English:
The vulnerability means that anyone with access can change settings on your devices and see sensitive information like passwords and network details. For example, an attacker could change your camera settings to point at a different area or steal your device credentials.
๐ง Prerequisites:
- Authenticated user access
โฑ Urgency: High urgency because attackers can manipulate device configurations and access sensitive information, leading to potential unauthorized access and data breaches.
๐ก Context: The root cause is a missing authorization check in the Meari IoT Cloud Platform OpenAPI Service.
Johnson Controls EasyIO Neo Series EC and CW Controllers
CISA Advisories | CVSS 3.5 | CVE-2026-64892
โ Why Should I Care?
Yes, if you run Johnson Controls EasyIO Neo Series EC Controllers V3.3b63, V3.3b62, CW Controllers V3.3b25, or V3.3b24: this vulnerability allows attackers to access sensitive information that could be used for further attacks.
๐ฏ Affected versions: EasyIO Neo Series EC Controllers V3.3b63, V3.3b62, CW Controllers V3.3b25, V3.3b24
๐ญ In plain English:
This vulnerability means that an attacker could peek into your system and find sensitive information, like passwords or system configurations, which they could then use to cause more damage. For example, they could use this information to take control of your building's HVAC system and manipulate temperatures.
๐ง Prerequisites:
- Access to the debug port
- No physical access controls in place
โฑ Urgency: Moderately urgent, as the exposure of sensitive information can lead to further attacks, but the CVSS score indicates a moderate impact.
โ Fixed in: EC firmware V3.3b64, CW firmware V3.3b26
๐ก Context: The root cause is a lack of proper access controls on the debug interfaces, allowing unauthorized access to sensitive information.
Why Should I Care? ๐ต On the Radar (20)
- Fortinet warns of critical FortiMail flaw exploited in zero-day attacks (BleepingComputer) โ Fortinet has identified a critical flaw in FortiMail that allows attackers to execute unauthorized code. This affects multiple versions of FortiMail and is being actively exploited in zero-day attacks.
- CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV (The Hacker News) โ A critical flaw in Cisco Catalyst SD-WAN Manager allows attackers to bypass authentication and gain admin access. This is a high-priority issue because it can be exploited remotely and affects network security.
- Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path (The Hacker News) โ A flaw in Apple's CoreGraphics framework can be exploited through malicious PDFs, causing crashes on unpatched iPhones and Macs. This could potentially lead to more serious security issues if exploited further.
- Hackers stole Pentagon personnel records of over 3 million people (BleepingComputer) โ Hackers stole sensitive data from over 3 million Pentagon personnel, including SSNs and personal details. This breach underscores the importance of robust cybersecurity for sensitive data.
- Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs (The Hacker News) โ A critical vulnerability in Citrix NetScaler ADC and Gateway allows attackers to execute commands and drop web shells without authentication. This could lead to theft of configuration data and unauthorized access.
- MetaMask Security Incident Prompts Exit of Affected Ethereum Validators (The Hacker News) โ MetaMask is dealing with a security issue that affects its infrastructure, prompting the exit of affected Ethereum validators. This does not immediately threaten MetaMask wallets but could impact staking rewards and uptime for validators.
- Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft (The Hacker News) โ Bitget, a cryptocurrency exchange, was hacked due to a zero-day vulnerability in third-party security products, leading to a $387.5 million theft. This shows that even with robust internal security, third-party flaws can lead to significant breaches.
- Metamask discloses security incident affecting its infrastructure (BleepingComputer) โ MetaMask, a popular Ethereum wallet, is dealing with a security issue affecting its infrastructure. While they claim there's no immediate threat to wallets, they are taking precautionary measures by exiting affected validators, which could impact staking rewards and uptime.
- Autonomous AI agents tried to hack US, Canadian government websites (BleepingComputer) โ Report of autonomous AI agents attempting to hack government websites.
- ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories (The Hacker News) โ News article summarizing various security threats and vulnerabilities.
- Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers (The Hacker News) โ News article reporting on the arrest of a 16-year-old suspected of running the KillSec ransomware group.
- Microsoft says threat actors are ahead in the early AI race (BleepingComputer) โ News article reporting on Microsoft's statement about AI in cyberattacks.
- How Financial Services Companies Can Modernize Their Software Supply Chain (The Hacker News) โ Article on modernizing software supply chains in financial services.
- WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory (The Hacker News) โ Description of a self-healing WordPress backdoor.
- Kiteworks patches max severity code injection vulnerability (BleepingComputer) โ Kiteworks releases security updates for 126 vulnerabilities.
โช 101 low-priority items filtered.
๐ฆ Aggregated and triaged by Donna AI | Sources: 8 vendor feeds | CISA KEV