The Exploit Bulletin

Archives
Log in
Subscribe
October 1, 2026

The Exploit Bulletin — Thursday, October 1, 2026: 3 issues require action

Thursday, October 1, 2026 — 3 issues require action. If you run none of the software below, you are done.

Affects: Cisco Catalyst SD-WAN Manager · Zammad · MyPresta Google Merchant Center Feed for PrestaShop


1. URI-encoding bypass of API session authentication gives unauthenticated admin access to Cisco Catalyst SD-WAN Manager (CVE-2026-76504)

CISA KEV (due 2026-10-03) · AUTHENTICATION BYPASS · CRITICAL · CVSS 9.8

Cisco published the advisory and fix on 2026-09-30 after its PSIRT observed active exploitation, CISA added it to KEV the same day with a 2026-10-03 remediation deadline, and Cisco's own advisory doubles as a request-level write-up, so an unpatched Manager reachable by an attacker can be taken over as admin without credentials.

Cisco Catalyst SD-WAN Manager (formerly vManage) mishandles URI/hex encoding in HTTP requests, letting a request slip past an API authentication rule. An unauthenticated remote attacker can reach the Manager API with admin-user privileges, giving control over the SD-WAN fabric's management plane.

Affected: Cisco Catalyst SD-WAN Manager < 20.9.10.1; Cisco Catalyst SD-WAN Manager 20.12.x < 20.12.8.2; Cisco Catalyst SD-WAN Manager 20.15.x < 20.15.6.1; Cisco Catalyst SD-WAN Manager 20.18.x < 20.18.4.1; Cisco Catalyst SD-WAN Manager 26.1.x < 26.1.2.1; Cisco Catalyst SD-WAN Manager 26.2

How to Test: Check the running Catalyst SD-WAN Manager release against the affected ranges (anything below 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1, or a 26.2 build older than Cisco's first fixed 26.2 release is vulnerable; the flaw applies regardless of device configuration). To look for prior abuse, review Manager web/API access logs for requests to API endpoints whose paths contain unusual hex- or URI-encoded characters and that were served without a preceding login, audit for unexpected admin-user API sessions, new or modified user accounts, and configuration changes pushed to edge devices, and follow CISA's Forensics Triage Requirements referenced in the KEV entry if the Manager was exposed while unpatched.

How to Patch: Upgrade Catalyst SD-WAN Manager to the fixed release for your train: 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, or 26.1.2.1 (for the 26.2 train, upgrade to the first fixed 26.2 release named in Cisco's advisory). Cisco states there are no workarounds; until the upgrade is applied, restrict network access to the Manager's management/API interface to trusted administrative networks only.

Evidence: CISA KEV · VulnCheck KEV · Vendor confirmed · CISA SSVC: active · CISA adds CVE-2026-76504 to KEV based on evidence of active exploitation · Rapid7: API authentication bypass exploited in the wild

Full entry with sources →


2. Session hijack chained to remote code execution in Zammad ticketing (CVE-2026-102489)

REMOTE CODE EXECUTION · CRITICAL · CVSS 8.7

BleepingComputer reports that DIVD attributes a breach of its own network to a chain of two Zammad zero-days including this one, and VulnCheck added it to its KEV catalog on 2026-09-30; teams running an affected 6.x Zammad have an internet-facing helpdesk that attackers have already used to get code execution.

A session hijack flaw in Zammad 6.3.0 through 6.5.x can be chained with a second flaw (CVE-2026-102490) to run code as the zammad user on the server; Zammad 7.0.0–7.1.3 contain the flaw but are reported not exploitable due to environment conditions.

Affected: Zammad >= 6.3.0 < 6.5.4 (CVE record text describes 6.3.0 to 6.5.4 as vulnerable); Zammad 7.0.0–7.1.3 (flaw present, reported not exploitable due to environment conditions)

How to Test: Check the running Zammad version in the admin interface or from the installed package on the host; any 6.3.0 through 6.5.x deployment is in scope and 7.0.0–7.1.3 carries the flaw even if reported non-exploitable. Look for unexpected or hijacked agent/admin sessions, unfamiliar logins, and processes, cron entries or files created by the zammad OS user, and review DIVD's case page DIVD-2026-00015 for the indicators from the breach.

How to Patch: Upgrade Zammad to a release outside the affected range — the CVE record bounds the vulnerable 6.x line below 6.5.4 and reports 7.x as not exploitable, so move to the current Zammad release line. No vendor mitigation is given; if the upgrade must wait, restrict network access to the Zammad web interface to trusted sources.

Evidence: VulnCheck KEV

Full entry with sources →


3. Unauthenticated file write to PHP code execution in MyPresta Google Merchant Center Feed for PrestaShop (CVE-2026-85520)

REMOTE CODE EXECUTION · CRITICAL · CVSS 9.3

A working exploit is public in VulnCheck XDB and VulnCheck added the flaw to its KEV catalog on 2026-09-29; any shop still running a gmfeed release below 2.3.10 leaves a no-auth PHP write path exposed on its public storefront.

The module's feed.php endpoint lets an unauthenticated request control the output file name, path, extension and content when the catalog is generated by URL with Save to file enabled, so an attacker can drop a PHP file into the shop and execute arbitrary code on the server.

Affected: MyPresta Google Merchant Center Feed (gmfeed) for PrestaShop >= 1.9.1 <= 2.3.8 per the CVE record; vendor states anything below 2.3.10 is vulnerable

How to Test: In the PrestaShop Back Office open Modules → Module manager and check the installed Google Merchant Center Feed version; anything below 2.3.10 is vulnerable. Inspect modules/gmfeed/ for unexpected or recently modified PHP files — the vendor warns an in-place overwrite can leave the old public script on the server — and review web server logs for unauthenticated requests to the module's feed.php endpoint carrying file name, path or extension parameters, treating any such request as a possible webshell drop.

How to Patch: Uninstall the module via Modules → Module manager with 'delete the module files' checked so modules/gmfeed/ is actually removed, then install 2.4.1 from the product page or your MyPresta.eu order history (minimum safe version 2.3.10); do not reuse a 2.3.9 or older zip and do not overwrite files in place. Until the clean reinstall is done, stop generating the catalog by URL with Save to file enabled (the fixed release restricts that function to a trusted Back Office link).

Evidence: VulnCheck KEV · VulnCheck XDB public exploit for CVE-2026-85520

Full entry with sources →


Read on the web · Every past edition

The Exploit Bulletin is free and daily. It publishes only what security teams must act on today — nothing else. Forward it freely.

Spot an error, or an exploit we missed? Reply here or email [email protected].

Don't miss what's next. Subscribe to The Exploit Bulletin:
← Newer The Exploit Bulletin — Friday, October 2, 2026: 1 issue requires action Older → The Exploit Bulletin — Wednesday, September 30, 2026: 1 issue requires action
www.exploitbulletin.com
jbac.co
LinkedIn
Powered by Buttondown, the easiest way to start and grow your newsletter.