← Back to trending CVEs

Week of October 5, 2026

Trending* CVEs over the last 7 days (from September 28, 2026 to October 5, 2026)

1
CVE-2026-88771Citrix / Netscaler
KEV
SYRN Score94
CVSS9.5
Activity130
Published09/27/2026
StatusHighly Active

Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.

2
CVE-2026-88772Citrix / Netscaler
KEV
SYRN Score93
CVSS9.5
Activity118
Published09/27/2026
StatusHighly Active

Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service

3
CVE-2026-86950Apple / Ipados
NewKEV
SYRN Score89
CVSS8.8
Activity113
Published09/28/2026
StatusHighly Active

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.

4
CVE-2026-104286Fortinet / Fortimail
NewKEV
SYRN Score93
CVSS9.8
Activity110
Published10/01/2026
StatusHighly Active

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

5
CVE-2026-76504Cisco Systems / Catalyst Sd-Wan Manager
NewKEV
SYRN Score93
CVSS9.8
Activity104
Published09/30/2026
StatusHighly Active

A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.

6
CVE-2026-88779Citrix / Netscaler
NewKEV
SYRN Score88
CVSS8.7
Activity79
Published10/04/2026
StatusHighly Active

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS, and before 13.1-37.282; Gateway: before 14.1-73.41 and before 13.1-64.28.

7
CVE-2026-90970Gitlab / Gitlab Ai Gateway
New
SYRN Score60
CVSS9.9
Activity41
Published10/02/2026
StatusHighly Active

GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a specially crafted flow configuration, resulting in arbitrary command execution on the AI Gateway.

8
CVE-2026-73570Synacor / Zimbra Collaboration Suite
KEV
SYRN Score92
CVSS8.9
Activity41
Published08/13/2026
StatusHighly Active

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

9
CVE-2026-102489Docker / Docker Container Platform
NewKEV
SYRN Score86
CVSS8.7
Activity31
Published09/30/2026
StatusHighly Active

Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as the zammad user. The vulnerability is also present in version 7.0.0 to version 7.1.3, but not exploitable due to environment conditions.

10
CVE-2026-102490Docker / Docker Container Platform
NewKEV
SYRN Score80
CVSS8.5
Activity26
Published09/30/2026
StatusHighly Active

All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.

* Trending is based on the number of sightings collected from SYRN's threat intelligence sources over the given period.

Monitor these vulnerabilities and get alerted when new threats target your stack.

Get Started Free