
Citrix shipped a fix for its third exploited NetScaler bug in a week, which barely counts as news.
Since June, when Anthropic gave its cyber partners Mythos 5, we've been writing about bugs getting cheaper to find. In July Searchlight Cyber spent about $25 of model time finding a WordPress bug that exploit brokers pay up to $500,000 for. That same month Trail of Bits warned that capable models "will soon create a firehose of bug reports, and OSS maintainers are already spread thin."
On October 1, Google stopped paying for product bugs in its open source bounty program because most of the automated reports were invalid, and GitHub put daily rate limits on private vulnerability reports the same day. Three months after that warning, the people receiving reports started writing their own rules.
Google's open source bug bounty, the Open Source VRP, paused rewards for product vulnerabilities in its 26 flagship and 47 important projects, a list that includes Go, Angular, Flutter, Bazel and Protocol Buffers. A flagship product bug used to pay $500 to $7,500. Reports of supply-chain compromise still pay, up to $31,337. Google's stated reason was "a significant rise in automated submissions, the vast majority of which are not valid," and it promised an update in the first quarter of 2027.
GitHub added daily per-user rate limits to private vulnerability reporting, also on October 1, because maintainers were getting "more low-quality and automated vulnerability reports, which can bury the reports that matter." A new default form requires a summary, details, impact and a proof of concept of at least 150 characters, and reporters can say whether AI helped. Maintainers can raise their repository's limit, allow-list trusted reporters, require a CWE, or write their own form in .github/VULNERABILITY_REPORT.yml.
A 150-character proof of concept is as easy for a model to write as for a person. The min_length setting in .github/VULNERABILITY_REPORT.yml is how a maintainer asks for more than that.
DIVD, the Dutch nonprofit that scans for vulnerable systems and notifies their owners, says an attacker got in on September 21 through two zero-days in Zammad, the open source ticketing system it runs. CVE-2026-102489 hijacks a session to run code as the zammad user, and CVE-2026-102490 escalates from there to root. DIVD noticed the next day and blocked access to its whole datacenter. The confirmed loss so far is "volunteer data," such as "DIVD email addresses and possibly contact details."
DIVD calls it "an agentic AI powered attack." According to its case file, the attacker's scripts include notes in which "the agent justifies its own actions, explaining why what it's doing is okay and really not phishing," and DIVD says those "overexplaining comments have made our reverse engineering a lot easier." The GPT-6 Astra results we covered last week came from simulated tests.
Zammad says CVE-2026-102489 affects version 6.5 and earlier, which are out of support, and that 7.x is not exploitable in practice. CVE-2026-102490 has no fix yet, and Zammad advises restricting server access to trusted administrators. DIVD began notifying owners of exposed Zammad instances on September 26, with blunt advice to upgrade to version 7 "or to take it offline." That case file also includes a script for checking Zammad logs against the indicators DIVD found.
If a vulnerability notice signed by a DIVD volunteer reaches you this month, the stolen addresses mean it may not have come from DIVD. DIVD asks that you check with communications@divd.nl first whenever a message from someone there "feels off."
Atlassian's October 5 advisory for CVE-2026-21589, rated 9.3, covers an unauthenticated file read in the Data Center editions of Jira Software, Jira Service Management, Confluence, Bitbucket, Bamboo and Crowd, plus Crucible and Fisheye. Atlassian says an attacker must know the exact file path and cannot list directories. Cloud is already patched, and Atlassian found no evidence of exploitation there.
watchTowr diffed the patch the next day. The bug sits in the shared atlassian-plugins-webresource library, version 6.0.7 and earlier, which turns :: into / when it unescapes a resource path. Routes like /download/resources/ need no login, so a request ending in ..::..::..::WEB-INF::web.xml walks out of the web root.
On a Jira instance connected to Crowd, the file at WEB-INF/classes/crowd.properties holds the application name and password Jira uses to talk to Crowd. watchTowr used those to create a user and add it to jira-administrators.
watchTowr says a quick internet search turns up "just under 700,000" Confluence instances alone. Fixed versions include Confluence 9.2.26 and 10.2.19 and Jira Software 9.12.40, 10.3.26 and 11.3.12. Teams that can't patch yet can use the WAF rule, Tomcat RewriteValve or urlrewrite.xml mitigations in the advisory.
Has anyone rotated the Crowd application password your Jira uses since you patched? The patch leaves that password as it was, so anyone who read crowd.properties before then can still talk to Crowd as Jira.
On October 2, Fenrisk's Maxime Rinaudo published CVE-2026-56004, rated CVSS 10, in Open Build Service, the openSUSE platform that turns source code into RPM, DEB, Flatpak and AppImage packages. It builds openSUSE itself and is used by VLC, Dell and Intel, with a public instance at build.opensuse.org. Fenrisk found the bug on June 29, and it was fixed on July 2.
The obs_scm service ran hg update <revision> with no -- separator, and the revision came from a _service file in a commit. A revision of --config=hooks.pre-update=<command> made Mercurial run the command on the source service server. OBS checked the value with Python's argparse first, but a value containing a space isn't read as an option, so it passed, and Mercurial then read it as configuration. Fenrisk says an attacker on that server could "push malicious packages or modify legitimate packages."
Fenrisk's earlier OBS finding, CVE-2024-22033, published in March 2025, was also an argument injection, through wget in the download_url service.
Search your build scripts for a branch name or URL passed straight to git or wget, since both read a leading dash as an option the way Mercurial did. For git, put --end-of-options before a revision, because a plain -- there marks the start of file paths, and check your version first, since checkout and reset only accept it from Git 2.43.1.
• Citrix NetScaler ADC and Gateway CVE-2026-88779, CVSS 4.0 8.7, a zero-day. A memory overflow lets an unauthenticated attacker crash the appliance, and only appliances configured as a SAML service provider or identity provider are exposed. Citrix classifies the impact as denial of service, but Kevin Beaumont reported that one of his honeypots, already patched for last week's two NetScaler zero-days, was running a downloaded malware binary. Citrix's bulletin is dated October 3. Fixed in 14.1-73.41 and 13.1-64.28, and in 13.1-37.282 for 13.1-FIPS and NDcPP builds (14.1-FIPS is fixed in 14.1-73.41 FIPS). CISA added it to KEV on October 4 with an October 7 deadline. (Citrix, SecurityWeek)
• Fortinet FortiMail CVE-2026-104286, CVSS 9.8, a zero-day. A path traversal combined with improper NULL-byte handling lets an unauthenticated attacker write arbitrary files to the appliance with crafted HTTP or HTTPS requests. Fortinet found it internally and published on October 1, before fixed builds were out for most branches, and CISA added it to KEV the same day. An October 5 update lists fixes in 7.4.9, 7.6.7 and 8.0.2, and 7.2 users have to move to 7.4 or later. Affects 7.2.0 through 8.0.1. Until you upgrade, Fortinet's workaround is to turn off the IBE service or keep the webmail interface off the internet. (Fortinet)
• Cisco Catalyst SD-WAN Manager CVE-2026-76504, CVSS 9.8, a zero-day. Cisco's login module checks the raw request path while the WildFly server underneath decodes it first, so one unauthenticated POST to /%6a_security_check (%6a is an encoded j) returns an admin API session, as VulnCheck showed on October 1. Cisco published September 30 and says there is no workaround. First fixed releases are 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1. CISA added it to KEV on September 30. To check for compromise, Cisco points to j_security_check requests from unknown addresses in serviceproxy-access.log. (Cisco, VulnCheck)
• Zammad CVE-2026-102489 and CVE-2026-102490, CVSS 4.0 8.7 and 8.5, both zero-days and the subject of this week's DIVD Deep Dive. The first hijacks a session to run code on 6.5 and earlier, and the second escalates to root on every version and has no fix yet. CISA added both to KEV on October 2. (Zammad)
• Zimbra Collaboration CVE-2026-73570, CVSS 8.9. A crafted email injects OS commands through SNMP notification processing, with no login or user interaction, on servers that have the optional zimbra-snmp package installed and SNMP notifications enabled. It ran in this list in early September. What is new is Microsoft's September 30 report that two scanning tools probed the injection point between July 28 and August 7, after the July 20 fix but before public disclosure on August 13, and that compromised servers got web shells, reverse shells, privilege escalation and mailbox theft. Fixed in 10.1.20, in KEV since August 21. If you cannot upgrade, Microsoft says to uninstall zimbra-snmp or disable SNMP notifications. (Microsoft Threat Intelligence)
• Rejetto HFS CVE-2026-61500, CVSS 4.0 9.3. HFS derives its session-cookie signing key from JavaScript's Math.random() and exposes other outputs of the same generator at login, so an attacker who collects a few login responses can rebuild the generator state, forge an admin cookie and run code through the server_code setting. Horizon3's Zach Hanley found it using Anthropic's Mythos and published the details September 30. VulnCheck's canaries then picked up small-scale reconnaissance from a single China Telecom IP against decoys in Japan and the US, and VulnCheck added it to its own KEV list. It is not in CISA's KEV. Affects 3.0.0 through 3.2.0, fixed in 3.2.1 in July. (Horizon3.ai, VulnCheck)
• Ninja Forms and WPC Product Bundles for WooCommerce CVE-2026-94504 and CVE-2026-93836, CVSS 7.1. Both are unauthenticated stored XSS in WordPress plugins, so script planted in a Ninja Forms submission or a WooCommerce order quantity runs when an administrator opens that record. Patchstack saw one payload, x.js from imgcdn1.com, arrive through WPC Product Bundles on October 4 and Ninja Forms on October 5. It installs a fake "WP Smart Thumbnails" plugin, a visible admin, an admin hidden from the Users screen, a backdoor login URL and an unauthenticated file manager. Fixed in Ninja Forms 3.15.4 and WPC Product Bundles 8.6.7, but the hidden admin and the login URL persist through must-use plugins, and Patchstack says removing the vulnerable plugin, or even the fake one, does not close them. (Patchstack)
• Kiteworks Email Protection Gateway CVE-2026-54154, CVSS 10.0. Input-handling flaws, path traversal among them, in publicly reachable endpoints let an unauthenticated attacker run code with root privileges. Affects every release before 9.4.1, fixed in 9.4.1 on September 30, in the same release round that fixed 125 other Kiteworks bugs. (Kiteworks)
• Dell Container Storage Modules and Dell System Update CVE-2026-63688 and CVE-2026-86360, CVSS 10.0 and 9.6. In CSM, Dell's storage plugins for Kubernetes, the csm-authorization-storage gRPC server has no authentication, so a remote attacker can pull the storage admin credentials for every registered array. It is one of two CSM flaws rated 10.0, all fixed in 1.18.0. DSU, which applies driver, BIOS and firmware updates to PowerEdge servers, has an unauthenticated path traversal that Dell says can lead to code execution as root, fixed in 2.3.0.0. Both advisories were published October 1. (Dell)
• GitLab AI Gateway (self-hosted) CVE-2026-90970, CVSS 9.9. A logged-in user with Duo Agent Platform access can escape the prompt-template sandbox with a crafted custom flow configuration and run commands on the gateway. Only organizations that host their own AI Gateway need to act. Affects 18.1.6 up to 19.2.4, 19.3 before 19.3.2 and 19.4 before 19.4.1, fixed October 2. (GitLab)
• Atlassian Data Center products CVE-2026-21589, CVSS 4.0 9.3. An unauthenticated read of known file paths across eight products, covered in this week's Deep Dive. (Atlassian)
• Open Build Service CVE-2026-56004, CVSS 10.0. Argument injection into Mercurial through a _service revision value, covered in this week's Deep Dive. Fixed July 2 in the tar_scm source service 0.12.4. (Fenrisk)
• Bouncy Castle for Java CVE-2026-71885, CVSS 4.0 9.2. The Messaging Layer Security (RFC 9420) code never checked that an X.509 credential's certificate key matched the leaf's signature_key, so a member could present someone else's certificate and be accepted as them. In a group that admits external commits without its own credential check, an unauthenticated attacker can join as a victim, evict them and read later group messages. Only MLS deployments using X.509 credentials are affected. Fixed in 1.86, disclosed October 3. (Bouncy Castle)
• LibreOffice and Apache OpenOffice CVE-2026-63277 and CVE-2026-59265, rated critical by Apache for OpenOffice. A spreadsheet can link a cell range to an external data source that names a Java database driver hosted remotely, so opening the file runs the attacker's Java code. LibreOffice fixed it October 5 in 26.2.5 and 26.8.0. OpenOffice 4.1.16 and earlier stay exposed until 4.1.17 ships, and Apache says disabling Java integration in the Preferences dialog prevents the attack. Codean Labs and V12 are credited with the report, and there are no reports of use in attacks. (LibreOffice, Apache OpenOffice)
• The Model Isn't Cooperating (PortSwigger Research, James Kettle) Why it's worth your time: Kettle pointed a swarm of agents at a "research cascade," where one finding seeds new findings on other targets, and got one significant discovery. In the traces, models drifted toward low-impact, easy-to-observe results whenever a broad prompt left room, while narrow tasks like turning a known desync trigger into response queue poisoning worked fine. His self-described "dirty eval" across several models drew no refusals, and in a follow-up that steered models toward high-impact outcomes, Opus 4.6 responded best. His working rule for now is tightly scoped tasks with minimal wiggle room.
• How to Fix a Bug in a Fix (Google Project Zero, Natalie Silvanovich) Why it's worth your time: she argues that when a bug is under active exploitation, most vendors are slowed by testing and delivery rather than by triage or writing the patch. She lays out four ways around that, with examples. They are feature flags tested in advance (Apple turned off Group FaceTime this way in 2019), filtering rules such as Android's Intent Firewall, separate update channels for single components, and hotpatching such as Linux Livepatch. She also warns that an emergency update channel becomes attack surface if the client does not verify that updates came from the vendor.
• GitHub Repos Exposed 543,699 Credentials. Nobody Revoked Them. (Truffle Security, published September 29) Why it's worth your time: Truffle scanned The Stack v3, a snapshot of 224 million public repositories assembled for AI training, and found 543,699 credentials still working in July 2026, with a median of 784 days in a public default branch and the oldest committed in 2009. In the twelve months either side of GitHub's push protection rollout, leaks of the types it blocks fell 53 percent while the rest fell 7 percent. But 51.8 percent of what is still live, connection strings and Google API keys among it, is a type that push protection does not block by default, and the credential types that disappear are the ones whose vendors revoke leaked keys.
• A Realistic Code Execution Exploit Chain in OpenBao and Vault (ControlPlane, Alex Scheel, published September 28) Why it's worth your time: four OpenBao bugs chain from no credentials to code execution in a setup where SPIFFE workloads authenticate with certificates from an ACME-enabled OpenBao CA. An ACME validation bypass forges a provisioner certificate, a non-canonical URL slips past an ACL deny to rewrite the admin role, a cross-namespace policy widens access, and a malicious snapshot restore runs any binary already on the host whose SHA-256 the attacker guesses. OpenBao fixed it in 2.6.3 and 2.7.0 on September 23. The bugs also affect Vault Community Edition, which has no fix yet, and the post says IBM "is unwilling to discuss" a mutual disclosure agreement with OpenBao.
• Beyond Valid Credentials: How Exposed AWS Keys Are Tested for Amazon Bedrock Access (Datadog Security Labs, Martin McCloskey)
Why it's worth your time: credential harvesters now grade stolen AWS keys by whether they reach Bedrock. One platform, KMON_NOC, has probed more than 80 Datadog Cloud SIEM customers since August 31, validating keys with STS GetCallerIdentity, flagging Bedrock-capable ones and pulling AWS_BEARER_TOKEN_BEDROCK values. Two checker scripts on VirusTotal call ListFoundationModels across regions, then send a Converse request with the prompt "ping" capped at four tokens to prove a model works at almost no cost. Datadog saw the same pattern at 12 organizations in 30 days, and its advice is to investigate any Bedrock activity from an identity with no history of AI use.
• Decision Models vs. CVE Data (Jerry Gamblin) Why it's worth your time: Gamblin ran Cloudflare's Clef classifiers on a laptop through Ollama's new decision endpoint over all 27,489 CVEs published August 4 to October 3, asking whether each description says what an attacker could do. Outside the Linux kernel, 989 of 23,736 (4.2%) never do, while the kernel CNA leaves impact out by policy in 3,661 of 3,753 records. The smaller Clef Flash model took a median 0.84 seconds per description, with no API bill.
The briefing security leaders actually read. CVEs, tooling shifts, and remediation trends — distilled into 5 minutes every week.
Join security leaders who start their week with the briefing. Free, 5 minutes, no fluff.
First briefing drops this week. Check your inbox.
Weekly only. No spam. Unsubscribe anytime.