Cyberattack Law and Disclosure Digest for 2026-10-02
Key Facts
- Primary record digest compiled for 2026-10-02.
- Aggregates official announcements from DOJ, CISA, SEC EDGAR, and allied cyber agencies.
- All cited documents are in the public domain or official government publications.
Summary of official government advisories, court filings, and sanctions published on 2026-10-02.
CISA Adds One Known Exploited Vulnerability to Catalog ↗
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2026-76504 Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to
CISA Adds One Known Exploited Vulnerability to Catalog ↗
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2026-104286 Fortinet FortiMail Path Traversal Vulnerability
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the feder
CISA Adds Two Known Exploited Vulnerabilities to Catalog ↗
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2026-65660 Microsoft SharePoint Code Injection Vulnerability
- CVE-2026-67279 Mikrotik RouterOS Improper En
CISA Malcolm ↗
Summary
The following versions of CISA Malcolm are affected:
- Malcolm
CVSS Vendor Equ MikroTik RouterOS ↗
Summary
Successful exploitation of this vulnerability could allow an attacker to achieve remote code execution or cause a denial of service.
The following versions of MikroTik RouterOS are affected:
- RouterOS <7.24 (CVE-2026-84411)
CISA Adds One Known Exploited Vulnerability to Catalog ↗
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2026-86950 Apple Multiple Products Out-of-Bounds Write Vulnerability
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks t
CISA Adds Two Known Exploited Vulnerabilities to Catalog ↗
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2026-88771 Citrix NetScaler Improper Input Validation Vulnerability
- Meari IoT Cloud Platform OpenAPI Service ↗
Summary
Successful exploitation of these vulnerabilities could allow attackers to manipulate device configurations, trigger unauthorized behaviors, and access sensitive information such as device credentials, owner details, and network data without proper authorization.
The following versions of Meari IoT Cloud Platform Open
VIVOTEK Camera Firmware ↗
Summary
Successful exploitation of this vulnerability may allow attackers to achieve remote command execution on affected devices, potentially with root privileges, leading to full compromise of the camera system.
The following versions of VIVOTEK Camera Firmware are affected:
- V Series model_FD9187 (CVE-2026-227
Armatura LLC Armatura One ↗
Summary
Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to the database, execute arbitrary code on the host with the highest level of privilege, or gain control of the physical access-control system.
The following versions of Armatura LLC Armatura One are affected:
- CVE-2026-87902 WordPress Core Remote File Inclusion Vulnerability
- EasyIO Neo Series EC Controllers V3.3b62 (CVE-2026-6489
Johnson Controls EasyIO Neo Series EC and CW Controllers ↗
Summary
Successful exploitation of this vulnerability could allow an attacker to gain access to sensitive information that could be used to conduct further attacks against the system.
The following versions of Johnson Controls EasyIO Neo Series EC and CW Controllers are affected:
- EasyIO Neo Series EC Controllers
Lantronix G520 Series Cellular Gateway ↗
Summary
Successful exploitation of these vulnerabilities could allow an attacker to replace software and execute arbitrary code with root privileges.
The following versions of Lantronix G520 Series Cellular Gateway are affected:
- G520 Series 2.6.0.4R6_stable (CVE-2026-84409, CVE-2026-91191)
Toptech TMS7 and TopHAT ↗
Summary
Successful exploitation of these vulnerabilities could allow an attacker to access critical data or execute arbitrary code.
The following versions of Toptech TMS7 and TopHAT are affected:
- TMS7 7.6.3 (CVE-2026-71379, CVE-2026-70356, CVE-2026-72510, CVE-2026-63713, CVE-2026-68954, CVE-2026-68068, CVE-2026-
Monta monta.app ↗
Summary
Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks.
The following versions of Monta monta.app are affected:
- monta.app vers:all/* (CVE-2026-9510
ABB Protection and Control IED Manager PCM600 ↗
Summary
Successful exploitation of these vulnerabilities could allow an attacker to escalate privileges or overwrite files.
The following versions of ABB Protection and Control IED Manager PCM600 are affected:
- Protection and Control IED Manager PCM600 <=2.14 (CVE-2026-15952, CVE-2026-15953)
Baicells Nova 430H ↗
Summary
Successful exploitation of this vulnerability could allow an attacker to inject malformed messages which may lead to a denial-of-service condition.
The following versions of Baicells Nova 430H are affected:
- Nova 430H eNodeB (model pBS3101SH) <=BaiBLQ_3.0.12 (CVE-2026-96274)
Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC, Gateway ↗Update October 2, 2026:
CISA has updated this Alert to provide a SIGMA detection rule resource to help identify potentially suspicious activity.
CISA is amplifying Citrix’s disclosure of eight new vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway products: CVE-2026-88771, CVE-20
Viidure Dashcam Android Application ↗
Summary
Successful exploitation of these vulnerabilities could allow attackers to access, modify, or delete sensitive user data and critical system files, potentially compromising the operation of the entire platform.
The following versions of Viidure Dashcam Android Application are affected:
- Dashcam Android App
Anjvision YSSD-RTMP-H5 ↗
Summary
Successful exploitation of these vulnerabilities could allow an attacker to access sensitive information, access user accounts, execute OS-level commands, or take full control over the device.
The following versions of Anjvision YSSD-RTMP-H5 are affected:
- YSSD-RTMP-H5 firmware 3.3.2.4_build_2024-12-26 (C
- monta.app vers:all/* (CVE-2026-9510
- EasyIO Neo Series EC Controllers
CISA Adds One Known Exploited Vulnerability to Catalog ↗
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the
Johnson Controls EasyIO Neo Series EC and CW Controllers ↗
Summary
Successful exploitation of this vulnerability could allow an attacker tointercept and read sensitive information, including credentials andsession data.
The following versions of Johnson Controls EasyIO Neo Series EC and CW Controllers are affected:
- V Series model_FD9187 (CVE-2026-227