News Room
16
Share
Critical FortiMail and Cisco SD-WAN Zero-Days Under Active Exploitation
criticalZero-Day Exploits

Critical FortiMail and Cisco SD-WAN Zero-Days Under Active Exploitation

Security agencies have issued urgent warnings following the active exploitation of critical zero-day vulnerabilities in Fortinet FortiMail and Cisco Catalyst SD-WAN Manager, leading to CISA KEV inclusion.

₿

Encrygma is selling the entire Full Cyber Weapon Research of Critical FortiMail and Cisco SD-WAN Zero-Days Under Active Exploitation for ₿ 0.10 BTC. Contact us.

07 October 2026Last updated 07 October 20264 min readCISA / Fortinet / Cisco
E
Encrygma AI Cyber Weapons Advisory Services : ₿ 0.10 BTCWe sell the full cyber research about this cyber weapon, including full source code, technical blueprints, exploits, implants and control and command dashboards. Consult with us · Telegram

Executive Takeaway — TL;DR

Category:
Zero-Day Exploits
Severity:
Critical
Actor Type:
APT
Geography:
Global
Confidence:
Confirmed
CVE:
CVE-2026-104286, CVE-2026-76504
Source:
CISA / Fortinet / Cisco
Read Time:
4 min

Executive Summary

In the last 48 hours, the cybersecurity landscape has been dominated by the active exploitation of two critical zero-day vulnerabilities affecting enterprise infrastructure. Fortinet has confirmed that CVE-2026-104286, a critical flaw in FortiMail, is being leveraged by threat actors to achieve arbitrary file writes. Simultaneously, Cisco is managing the fallout from CVE-2026-76504, an authentication bypass vulnerability in its Catalyst SD-WAN Manager that has also been confirmed as exploited in the wild. Both vulnerabilities have been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, mandating immediate remediation for federal agencies.

Threat Analysis

The rapid weaponization of these vulnerabilities suggests a coordinated effort by sophisticated threat actors to target edge devices. The FortiMail vulnerability (CVE-2026-104286) allows unauthenticated remote attackers to bypass security controls, while the Cisco SD-WAN flaw (CVE-2026-76504) provides a gateway for unauthorized access to critical network management interfaces. These exploits are particularly dangerous as they target the perimeter, providing attackers with a foothold to move laterally within corporate networks.

Technical Details

CVE-2026-104286 in FortiMail (CVSS 9.8) stems from a combination of path traversal (CWE-22) and improper handling of NULL bytes (CWE-158). By sending specially crafted HTTP/HTTPS requests, an attacker can write arbitrary files to the underlying system. Cisco’s CVE-2026-76504 involves an API authentication bypass that allows unauthenticated users to interact with the SD-WAN Manager, potentially leading to full system compromise. Both vulnerabilities were identified as being exploited in the wild, with evidence of modified system files observed in real-world incidents.

Attribution Assessment

While specific threat actor groups have not been publicly named by vendors, the nature of these exploits—targeting high-value network appliances—is consistent with the tactics, techniques, and procedures (TTPs) of state-sponsored Advanced Persistent Threat (APT) groups. The speed at which these vulnerabilities were weaponized following disclosure indicates a high level of technical capability and pre-existing exploit development pipelines.

Implications

Organizations relying on FortiMail and Cisco Catalyst SD-WAN are at immediate risk of data exfiltration, persistent backdoor installation, and potential ransomware deployment. The inclusion of these flaws in the CISA KEV catalog underscores the severity of the threat to both public and private sector entities.

Recommendations

  1. Immediate Patching: Apply the latest security updates provided by Fortinet and Cisco without waiting for standard maintenance cycles.
  2. Compromise Assessment: Audit affected systems for unauthorized file modifications, unexpected administrative accounts, or anomalous API traffic.
  3. Perimeter Hardening: Restrict access to management interfaces to trusted IP ranges and implement multi-factor authentication where applicable.
  4. Monitoring: Enhance logging for HTTP/HTTPS requests directed at edge appliances to detect potential exploitation attempts.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo