← All briefings

Filter email through FortiMail? Patch it now

Week of 28 September to 4 October 2026

This week's top item: if your business filters email through Fortinet FortiMail, patch it today. Fortinet confirms criminals are already using a critical flaw (no password needed) to plant malicious files on FortiMail devices, and the fix window is tight. If staff connect in through Citrix NetScaler ADC or Gateway, that's still worth doing too. The Australian Cyber Security Centre says criminals were exploiting two of eight newly fixed flaws before Citrix released a patch. Apple also fixed an iPhone, iPad and Mac flaw used in a targeted attack. A simple update covers it. If your network spans more than one site and is centrally managed, Cisco also fixed a critical flaw already under attack, worth a question to your IT provider. And if your business self-hosts the open-source Zammad helpdesk tool, take it offline or upgrade now: researchers found it being broken into in seconds flat.

  1. 1

    Filter email through FortiMail? Patch it today

    Businesses running Fortinet FortiMail (versions 7.2 through 8.0.1) as their email security gateway, usually set up and maintained by an IT provider rather than run in-house. If your IT provider manages a different email filtering product (Microsoft 365, Mimecast, or similar), this isn't your equipment.

    Fortinet FortiMail is an email security gateway many small and mid-sized businesses use to filter spam, phishing and malware out of email before it reaches staff inboxes. Fortinet has confirmed a critical flaw, rated 9.8 out of 10, that lets an attacker who hasn't logged in at all plant files on the device over an ordinary web request. Criminals are already using it to drop their own software onto affected systems. CISA (the US Cybersecurity and Infrastructure Security Agency, which tracks vulnerabilities under active attack) gave US federal agencies only three days to fix it, a sign of how urgent this is. A fix is available, and a quick workaround exists if patching takes longer.

    Do this

    Ask your IT provider: "Is our FortiMail updated to 7.4.9, 7.6.7, 8.0.2 or later, and if not, has the IBE feature been disabled as a stopgap?"

    Essential Eight: Patch applicationsISM: System patching

    Sources: CISA KEV: FortiMail path traversal flaw ↗ · Fortinet security advisory ↗CVE-2026-104286 · CWE-22 · CWE-158

  2. 2

    Staff connect in through Citrix NetScaler? Patch it today

    Businesses using Citrix NetScaler ADC or NetScaler Gateway for remote access (VPN, ICA Proxy or RDP Proxy), typically mid-sized businesses with their own network appliance rather than a simpler remote-access tool. This is a different, newer set of flaws to August's NetScaler patch, so being up to date on that one doesn't cover this. If the name Citrix NetScaler doesn't ring a bell, you're not running it.

    The Australian Cyber Security Centre (ACSC) has issued a critical alert after Citrix fixed eight vulnerabilities in NetScaler ADC and NetScaler Gateway, the appliance many mid-sized businesses use to let staff connect in remotely. Criminals were already using two of these flaws to break in before Citrix released a fix. One of those two lets an attacker take full control of the device over the internet, without a password, and affects every NetScaler ADC and Gateway regardless of how it's set up. The ACSC hasn't yet seen this used against an Australian organisation, but says every business running the software should patch immediately.

    Do this

    Ask your IT provider: "Are we running Citrix NetScaler ADC or Gateway, and has it been updated to 14.1-73.37, 13.1-64.23, or later?"

    Essential Eight: Patch applicationsISM: System patching

    Sources: ACSC critical alert ↗ · Citrix security bulletin ↗CVE-2026-88771 · CVE-2026-88772

  3. 3

    Own an iPhone, iPad or Mac? Update it this week

    Anyone using an iPhone 11 or newer, a recent iPad, or a Mac on macOS Tahoe or Sequoia (most small business owners and staff).

    Apple has fixed a flaw in CoreGraphics, the software that draws images and graphics on iPhones, iPads and Macs, after it was used in what Apple describes as an extremely sophisticated attack against specific targeted individuals. Opening a booby-trapped file could let an attacker run their own code on the device. The attack was narrow and targeted, not mass exploitation, but the fix is free, takes a few minutes, and CISA (the US Cybersecurity and Infrastructure Security Agency) has told US federal agencies to apply it by 2 October.

    Do this

    Update every work iPhone, iPad and Mac now: Settings > General > Software Update on iPhone/iPad (look for iOS/iPadOS 26.7.1), or Apple menu > System Settings > General > Software Update on Mac (macOS 26.7.1 or 15.8.1).

    Essential Eight: Patch operating systemsISM: System patching

    Sources: CISA KEV: Apple CoreGraphics flaw ↗ · Apple security advisory ↗CVE-2026-86950 · CWE-787

  4. 4

    Manage multiple sites with Cisco SD-WAN? Patch now

    Businesses with more than one office or site whose network is centrally managed using Cisco Catalyst SD-WAN Manager. This is normally set up by an IT provider, not run in-house. If you operate from a single office with an ordinary firewall or router, this isn't your equipment, but it's still worth checking with your IT provider in case they manage it for you.

    Cisco has fixed a critical flaw in Catalyst SD-WAN Manager, the software used to centrally manage internet and network connections across a business's multiple locations, usually set up and run by an IT provider rather than by business owners themselves. The flaw lets an attacker disguise part of a web request to slip past a login check entirely, gaining full administrator access without a password. Cisco says criminals are already using it, and it's rated critical: 9.8 out of 10. A fix is available, and there is no other way to protect against it.

    Do this

    Ask your IT provider: "Do we run Cisco Catalyst SD-WAN Manager anywhere in our network, and has it been updated to fix CVE-2026-76504?"

    Essential Eight: Patch applicationsISM: System patching

    Sources: CISA KEV: Cisco Catalyst SD-WAN Manager flaw ↗ · Cisco security advisory ↗CVE-2026-76504 · CWE-177

  5. 5

    Self-host the Zammad helpdesk tool? Take it offline or upgrade now

    Businesses that self-host the open-source Zammad platform for support tickets, a deliberate setup choice, not something an IT provider installs by default. If your support tickets run through Zendesk, Freshdesk, Microsoft, or a similar hosted service, this isn't your software.

    Zammad is an open-source helpdesk and customer-support ticketing system that some small and mid-sized businesses run themselves instead of paying for a hosted service like Zendesk. The Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit that researches security flaws, found two Zammad bugs chained together to hijack a logged-in user's session, run commands as the Zammad system account, then jump to full administrator (root) control of the server. DIVD says the break-in was carried out automatically by an AI tool and took only seconds. DIVD discovered the chain because it was used against DIVD's own systems on 21 September.

    Do this

    Ask your IT provider: "Are we running Zammad anywhere, and if so, has it been upgraded to version 7, or should it be taken offline until that's done?"

    Essential Eight: Patch applicationsISM: System patching

    Sources: CISA KEV: Zammad session fixation flaw ↗ · CISA KEV: Zammad privilege escalation flaw ↗ · DIVD case report ↗CVE-2026-102489 · CVE-2026-102490 · CWE-384 · CWE-269

Beyond this week's news

Reading about threats is step one. Knowing where you stand is step two.

See whether the security products you already pay for cover the basics (free, in about three minutes), or get a fixed-price, plain-English review of your whole setup.

Prefer LinkedIn? Follow TERESEC: the briefing lands there every Monday.

Latest ISM release: ISM September 2026: What Changed and What to Check →What the ISM is and how we assess it →