Rapid responses
The runZero Rapid Response program detects emerging threats and notifies you immediately. Older entries move to standalone queries or templates.
Citrix NetScaler ADC (formerly Citrix ADC) is an application delivery controller that provides load balancing, traffic optimization, and web application security. Citrix NetScaler Gateway (formerly Citrix Gateway) is a secure remote access solution that handles user authentication and encrypted connections to internal applications and virtual desktops.
Certain versions of NetScaler ADC and NetScaler Gateway are affected by a memory overflow vulnerability. A remote, unauthenticated attacker can trigger improper restriction of operations within the bounds of a memory buffer, leading to unpredictable or erroneous behavior or a denial-of-service condition.
Evidence indicates that this vulnerability is actively exploited in the wild, leading to its addition to the CISA Known Exploited Vulnerabilities (KEV) catalog on October 4, 2026.
The following versions are affected:
- NetScaler ADC and NetScaler Gateway 14.1: Versions prior to 14.1-73.41
- NetScaler ADC and NetScaler Gateway 13.1: Versions prior to 13.1-64.28
- NetScaler ADC 14.1-FIPS: Versions prior to 14.1-73.41 FIPS
- NetScaler ADC 13.1-FIPS and 13.1-NDcPP: Versions prior to 13.1-37.282
hw:="Citrix NetScaler%" OR hw:="Citrix ADC%" OR os:="Citrix NetScaler%" OR os:="Citrix ADC"
Zammad is an open source help desk and ticketing system that organizations self-host to manage customer support requests across email, chat, and social channels.
While investigating a separate incident (DIVD-2026-00014), the Dutch Institute for Vulnerability Disclosure (DIVD) identified two vulnerabilities in Zammad:
-
CVE-2026-102489: A session hijacking vulnerability classified under CWE-384 (Session Fixation) that allows a remote attacker to hijack a Zammad user’s session, potentially leading to remote code execution (RCE) under the context of the local zammad user.
-
CVE-2026-102490: A local privilege escalation vulnerability enabling the local zammad user to escalate privileges to
root.
Evidence indicates that CVE-2026-102489 and CVE-2026-102490 are actively exploited in the wild, leading to their addition to the CISA Known Exploited Vulnerabilities (KEV) catalog on October 2, 2026.
The following versions are affected:
- Zammad: Versions 1.5.0 through 7.1.0-alpha.
Exploitability Notes:
- CVE-2026-102489: Directly affects versions 6.3.0 through 6.5.4. Versions 7.0.0 through 7.1.3 contain the underlying code flaw but are not exploitable in practice due to runtime environment conditions on those releases.
- CVE-2026-102490: Reported to affect versions 1.5.0 through 7.1.0-alpha. The vendor disputes this report, stating it has not received technical details from DIVD to confirm the flaw, its scope, or affected releases.
_asset.protocol:=http AND protocol:=http AND favicon.ico.image.mmh3:="-1687285536"
FortiMail is Fortinet’s email security appliance, providing antispam, antivirus, and data loss prevention capabilities for inbound and outbound mail traffic.
Certain versions of FortiMail contain an improper limitation of a pathname to a restricted directory (‘path traversal’) and improper neutralization of NULL byte vulnerabilities. These flaws allow an unauthenticated, remote attacker to write arbitrary files to the underlying system via crafted HTTP or HTTPS requests.
Evidence indicates that this vulnerability is actively exploited in the wild, leading to its addition to the CISA Known Exploited Vulnerabilities (KEV) catalog on October 1, 2026.
The following versions are affected:
- FortiMail 8.0: Versions 8.0.0 through 8.0.1
- FortiMail 7.6: Versions 7.6.0 through 7.6.6
- FortiMail 7.4: Versions 7.4.0 through 7.4.8
- FortiMail 7.2: Versions 7.2.0 through 7.2.9
hw:="Fortinet FortiMail"
The Cisco Catalyst SD-WAN Controller serves as the centralized control-plane element, utilizing the Overlay Management Protocol (OMP) to manage routing intelligence, distribute security keys, and enforce network-wide policies. In contrast, the Cisco Catalyst SD-WAN Manager acts as the centralized management system, providing the graphical interface necessary for the configuration, monitoring, and orchestration of all devices within the fabric.
A vulnerability in the SD-WAN Manager component improperly handles URI encoding elements of a HTTP requests, which allows an attacker to send requests that bypass authentication checks and gain administrative access to the administrative APIs.
There is evidence that this vulnerability is being actively exploited in the wild and the vulnerability has been added to the CISA KEV list September 30th, 2026.
The following versions are affected:
- Catalyst SD-WAN releases prior to 20.9
- Catalyst SD-WAN release 20.9 versions prior to 20.9.10.1
- Catalyst SD-WAN release 20.12 versions prior to 20.12.8.2
- Catalyst SD-WAN release 20.15 versions prior to 20.15.6.1
- Catalyst SD-WAN release 20.18 versions prior to 20.18.4.1
- Catalyst SD-WAN release 26.1 versions prior to 26.1.2.1
- Catalyst SD-WAN release 26.2 versions prior to 26.2.1
hw:="Cisco vManage" OR os:="Cisco Viptela OS"
Citrix NetScaler ADC (formerly Citrix ADC) is an application delivery controller that provides load balancing, traffic optimization, and web application security. Citrix NetScaler Gateway (formerly Citrix Gateway) is a secure remote access solution that handles user authentication and encrypted connections to internal applications and virtual desktops.
Certain versions of NetScaler ADC and NetScaler Gateway are affected by multiple vulnerabilities:
-
CVE-2026-88771: Improper input validation allows an unauthenticated, remote attacker to execute arbitrary commands.
-
CVE-2026-88772: Improper restriction of operations within the bounds of a memory buffer allows an unauthenticated, remote attacker to achieve remote code execution (RCE) or cause a denial-of-service condition.
-
CVE-2026-88773: Inconsistent interpretation of HTTP requests (HTTP request/response smuggling) allows a remote attacker to manipulate how requests and responses are processed.
-
CVE-2026-88774: Improper use of HTTP URL based expressions in a feature policy allows a remote attacker to bypass configured policy restrictions.
-
CVE-2026-88775: A memory overflow condition can lead to unpredictable or erroneous behavior or a denial-of-service condition.
-
CVE-2026-88776: A memory overflow condition can lead to unpredictable or erroneous behavior or a denial-of-service condition.
-
CVE-2026-88777: A memory overflow condition can lead to unpredictable or erroneous behavior or a denial-of-service condition.
-
CVE-2026-88778: Use of a predictable exact value derived from previous values allows a remote attacker to predict a security-sensitive value.
This Rapid Response initially flagged unconfirmed reports of active exploitation prior to Citrix’s disclosure of the CVEs above.
Evidence indicates that CVE-2026-88771 and CVE-2026-88772 are actively exploited in the wild, leading to their addition to the CISA Known Exploited Vulnerabilities (KEV) catalog on September 27, 2026.
The following versions are affected:
- NetScaler ADC and NetScaler Gateway 14.1: Versions prior to 14.1-73.37
- NetScaler ADC and NetScaler Gateway 13.1: Versions prior to 13.1-64.23
- NetScaler ADC 14.1-FIPS: Versions prior to 14.1-73.37 FIPS
- NetScaler ADC 13.1-FIPS and 13.1-NDcPP: Versions prior to 13.1-37.279 FIPS/NDcPP
hw:="Citrix NetScaler%" OR hw:="Citrix ADC%" OR os:="Citrix NetScaler%" OR os:="Citrix ADC"
Arista VeloCloud Orchestrator (VCO) is the centralized management and orchestration component of the VeloCloud SD-WAN solution, used to configure, monitor, and manage VeloCloud Edge devices across an enterprise network.
Certain versions of on-premises VeloCloud Orchestrator (VCO) contain an improper input validation vulnerability. An attacker can exploit this flaw to access privileged internal functionality and compromise the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and its managed data.
Exploitation requires network access to the VCO web interface and an active certificate-based authentication setup between a VeloCloud Edge and the Orchestrator; tenant or operator credentials are not required. Hosted versions (including Dedicated instances) were also affected and have already been patched by Arista.
Evidence indicates that this vulnerability is actively exploited in the wild, leading to its addition to the CISA Known Exploited Vulnerabilities (KEV) catalog on September 22, 2026.
The following versions are affected:
- VCO 5.2.x: Versions 5.2.0 through 5.2.3.15
- VCO 6.1.x: Versions 6.1.0 through 6.1.3.7
- VCO 6.4.x: Versions 6.4.0 through 6.4.2.7
- VCO 7.0.x: Versions 7.0.0 through 7.0.0.2
_asset.protocol:=http AND protocol:=http AND (http.body:"single-spa-application:@velocloud/vco-header" OR last.http.body:"single-spa-application:@velocloud/vco-header")
Check Point Security Gateways act as physical or virtual enforcement points that inspect network traffic and execute access rules in real time. Spark Firewalls are compact, enterprise-grade appliances designed to extend these security controls to small-to-medium businesses and remote branch offices. The Security Management Server serves as the centralized database and control plane that stores configuration settings, processes logs, compiles security policies, and deploys them to those gateways. Multi-Domain Security Management (MDS) extends this architecture by hosting multiple, isolated virtual management servers on a single platform.
Certain versions of Check Point products are affected by multiple vulnerabilities:
-
CVE-2026-85102: Improper certificate trust validation during VPN negotiation in Security Gateway, Spark Firewall (Centrally Managed and Locally Managed) allows an unauthenticated, remote attacker to execute arbitrary code on the gateway. A fix has been available since September 9, 2026, but exploitation attempts targeting Spark Firewall customers have since been observed.
-
CVE-2026-85103: A heap-based buffer overflow in the VPN certificate ASN.1 decoding flow of Security Gateway, Security Management Server, and Spark Firewall (Centrally Managed and Locally Managed) allows an unauthenticated, remote attacker to execute arbitrary code on the affected appliance.
-
CVE-2026-93616: A pre-authentication directory traversal and file upload vulnerability in the Check Point Management web service (Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent) allows an unauthenticated attacker to upload a script to an arbitrary path, execute it, and load an arbitrary Java class.
Evidence indicates that CVE-2026-85102 and CVE-2026-93616 are actively exploited in the wild, leading to their addition to the CISA Known Exploited Vulnerabilities (KEV) catalog on September 22, 2026.
The following versions are affected:
- Security Gateway: R81.20, R82, R82.10, and End-of-Support (EOS) versions R80 through R81.10 (affected by CVE-2026-85102 and CVE-2026-85103).
- Spark Firewall (Centrally Managed and Locally Managed): R82.00.X prior to R82.00.10 Build 2325, and R81.10.X prior to R81.10.17 Build 4968 (affected by CVE-2026-85102 and CVE-2026-85103).
- Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent: R82.20 with no Jumbo Hotfix, R82.10 with Jumbo Hotfix Take 44 or below, R82 with Jumbo Hotfix Take 126 or below, R81.20 with Jumbo Hotfix Take 166 or below, and End-of-Support (EOS) versions R81.10 with Jumbo Hotfix Take 190 or below through R80 (affected by CVE-2026-85103 and CVE-2026-93616).
os:="Check Point Gaia"
F5 BIG-IP Access Policy Manager (APM) is a module that provides secure, context-aware access control for applications and networks, including support for OAuth-based authentication and authorization profiles.
When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can trigger a heap-based buffer overflow, leading to remote code execution. This vulnerability allows an unauthenticated attacker to perform remote code execution. This is a data plane issue; there is no control plane exposure.
There is evidence that this vulnerability is being actively exploited in the wild, and it was added to the CISA Known Exploited Vulnerabilities (KEV) catalog on September 22, 2026.
The following versions are affected:
- BIG-IP 21.1.x: Versions in the 21.1.0 release branch prior to the vendor-supplied engineering hotfix
- BIG-IP 17.5.x: Versions in the 17.5.0 release branch prior to the vendor-supplied engineering hotfix
- BIG-IP 17.1.x: Versions in the 17.1.0 release branch prior to the vendor-supplied engineering hotfix
vendor:=F5 AND product:="BIG-IP Access Policy Manager"
Cisco Identity Services Engine (ISE) is a network access control and policy enforcement platform, and Cisco ISE Passive Identity Connector (ISE-PIC) provides passive identity mapping for third-party enforcement devices.
On September 16, 2026, Cisco published four advisories covering multiple vulnerabilities in ISE and ISE-PIC. All four advisories affect the same 3.1-3.5 release lines and share an identical set of first-fixed releases, so they are combined here into a single rapid response with one remediation path. The vulnerabilities are independent of one another; a release affected by one is not necessarily affected by the others.
-
CVE-2026-76460 (CVSS 10.0, cisco-sa-ISE-ABP-VNSW7Tn5): An unauthenticated, remote attacker can bypass authentication on an API endpoint due to insufficient authentication control, gaining unauthorized access to the web-based management interface.
-
CVE-2026-76423 (CVSS 10.0, cisco-sa-ise-multi-hrP9jQSQ): An unauthenticated, remote attacker can gain administrative access via the REST API due to insufficient authorization checks on the exposed REST API port.
-
CVE-2026-76424 (CVSS 7.2, cisco-sa-ise-multi-hrP9jQSQ): An authenticated attacker can upload or copy arbitrary files via the REST API due to insufficient path validation, leading to root command execution.
-
CVE-2026-76425 (CVSS 7.6, cisco-sa-ise-multi-hrP9jQSQ): An authenticated attacker can conduct SQL injection against the backend database and perform SSRF.
-
CVE-2026-76426 (CVSS 4.9, cisco-sa-ise-multi-hrP9jQSQ): An authenticated attacker can conduct SQL injection against the monitoring database via the REST API.
-
CVE-2026-76427 (CVSS 4.9, cisco-sa-ise-multi-hrP9jQSQ): An authenticated attacker can read arbitrary files via XML external entity injection in the offline profiler feed service.
-
CVE-2026-76428 (CVSS 4.9, cisco-sa-ise-multi-hrP9jQSQ): An authenticated attacker can conduct SQL injection against the session database via the REST API.
-
CVE-2026-20307 (CVSS 9.9, cisco-sa-ise-rce-se7bYU57): A low-privileged, authenticated attacker can execute arbitrary root-level commands via insecure deserialization of a Java object in the web-based management interface.
-
CVE-2026-20176 (CVSS 9.1, cisco-sa-ise-rce-se7bYU57): A high-privileged, authenticated attacker can execute arbitrary root-level commands due to insufficient input validation.
-
CVE-2026-20211 (CVSS 9.1, cisco-sa-ise-rce-se7bYU57): A high-privileged, authenticated attacker can execute arbitrary root-level commands via insecure deserialization of Java objects.
Cisco also disclosed a hardening release (cisco-sa-hardening-ise-XU5EwX5T) covering multiple vulnerabilities found during internal security testing. Cisco grouped these by underlying CWE class and assigned one CVE ID per class, so each CVE below represents several related internal findings rather than a single flaw:
-
CVE-2026-20130 (CVSS 10.0, cisco-sa-hardening-ise-XU5EwX5T): Improper neutralization of special elements in output (CWE-74), covering command injection, cross-site scripting, XML injection, code injection, and resource injection findings.
-
CVE-2026-20192 (CVSS 10.0, cisco-sa-hardening-ise-XU5EwX5T): Improper access control (CWE-284), covering authorization, authentication, privilege, and bypass findings.
-
CVE-2026-20194 (CVSS 9.1, cisco-sa-hardening-ise-XU5EwX5T): Incorrect resource transfer between spheres (CWE-669), covering exposure of sensitive information in transit, improper removal of sensitive information before storage, and unrestricted file upload findings.
-
CVE-2026-20234 (CVSS 9.9, cisco-sa-hardening-ise-XU5EwX5T): Insufficiently protected credentials (CWE-522), covering information disclosure and passwords stored or encoded in a recoverable format.
-
CVE-2026-20237 (CVSS 9.9, cisco-sa-hardening-ise-XU5EwX5T): Improper input validation (CWE-20), covering path traversal and external control of file paths.
-
CVE-2026-20287 (CVSS 6.5, cisco-sa-hardening-ise-XU5EwX5T): Improper privilege management (CWE-269), covering incorrect privilege assignment, privilege chaining, and misuse of privilege-checking APIs.
These vulnerabilities affect Cisco ISE and ISE-PIC regardless of device configuration.
There is evidence that CVE-2026-76460 is being actively exploited in the wild, and it was added to the CISA Known Exploited Vulnerabilities (KEV) catalog on September 16, 2026.
The following releases are affected by one or more of these vulnerabilities:
- Cisco ISE and ISE-PIC 3.1: Versions through 3.1 Patch 11
- Cisco ISE and ISE-PIC 3.2: Versions through 3.2 Patch 10
- Cisco ISE and ISE-PIC 3.3: Versions through 3.3 Patch 11
- Cisco ISE and ISE-PIC 3.4: Versions through 3.4 Patch 6
- Cisco ISE and ISE-PIC 3.5: Versions through 3.5 Patch 3
Cisco ISE Software Release 3.0 has reached End of Software Maintenance; customers are advised to migrate to a supported release that includes the fixes.
vendor:="Cisco" AND product:="Identity Services Engine"
Cisco Secure Email Gateway is a secure email security appliance that allows organizations to handle email securely and potentially quarantine malicious or unwanted emails for analysis.
Certain versions of the Secure Email Gateway are affected by an unauthenticated SQL injection vulnerability, that could allow an unauthenticated actor to execute commands with administrative privileges on the underlying operating system.
There is evidence that these vulnerabilities are being actively exploited in the wild and the vulnerability has been added to the CISA KEV list September 14, 2026.
The following versions are affected
- 15.5.4-012 and earlier
- 16.0.3-044 and earlier
- 16.5.0 before 16.5.0-780
_asset.protocol:=http AND protocol:=http AND last.html.title:"Cisco%Gateway%C" AND NOT last.html.title:"Cloud"
runZero has identified multiple vulnerabilities in a large subset of major baseboard management controllers (BMCs) that can lead to device compromise or segmentation breakdowns. Details of individual vulnerabilities will be published as the disclosure process completes.
BMCs are embedded into every modern enterprise server. These devices run their own OS, have their own network interfaces, and are network-reachable even when the server is powered off. The devices speak a protocol called IPMI that was thoroughly trashed by Dan Farmer’s ground-breaking research in 2013. Since Farmer’s original research into Cipher Zero authentication bypass and RAKP password hash disclosure, dozens of new vulnerabilities have been identified in these devices, but none of this research revisits the IPMI protocol itself.
High level details of our findings will be presented at Black Hat 2026 & DEF CON 34.
(protocol:ipmi OR type:=BMC) AND ( hw:=OpenBMC OR hw:="Super Micro IPMI" OR hw:="HP% iLO%" OR hw:="Dell iDRAC%" OR hw:="AMI MegaRAC" OR (hw:="Raritan%" AND type:="Power Device") OR hw:="H3C HDM" OR hw:="Fujitsu%")
Each Rapid Response includes a query that finds matching assets, a trigger that analyzes all inventories for exposure, and a blog post with the details of the issue, so you can mitigate exposures before compromise.