CRITICAL 11 min read 1 Oct 2026

Cisco Catalyst SD-WAN Manager: API Authentication Bypass Leads Today's Security Review

Threat Level: Critical Tags: cve-2026-76504, cwe-177, catalyst-sd-wan-manager, cve-2026-86219, cwe-294, cve-2026-73570, cwe-78, cve-2025-43510, cwe-667, cve-2026-93659

Key findings
01
Cisco Catalyst SD-WAN Manager: API Authentication Bypass
CRITICAL
A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user.
02
Authen::SASL: Authentication Bypass by Capture-replay
CRITICAL
It was discovered that Authen::SASL, a Perl authentication library, did not properly validate login attempts. An attacker could possibly use this issue to gain unauthorized access. The assigned identifier is CVE-2026-86219.
03
Zimbra: OS Command Injection
HIGH
Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from the Microsoft Security Research team.
04
Vulnerability in Apple iOS, iPadOS and macOS
HIGH
A malicious application may cause unexpected changes in memory shared between processes. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1.
05
Concrete CMS Community Store: Cross-site Scripting
HIGH
Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views. Unauthenticated attackers can store script payloads in billing name, email, or phone fields that execute in authenticated manager sessions to create rogue accounts or exfiltrate data.
06
Multiple vulnerabilities in OpenVPN
HIGH
It was discovered that OpenVPN had a use-after-free vulnerability in its TLS session handling. An attacker could possibly use this issue to cause OpenVPN to crash, resulting in a denial of service, or execute arbitrary code. The assigned identifier is CVE-2026-84732.
07
OpenStack Keystone: Incorrect Authorization
HIGH
Grzegorz Grasza discovered that OpenStack Keystone did not consistently enforce restrictions for delegated authentication tokens. An authenticated attacker could possibly use this issue to create credentials or delegations that outlasted the delegated token.
08
OpenSBI: Uncontrolled Resource Consumption
HIGH
It was discovered that OpenSBI did not properly validate the counter index mask in SBI PMU extension requests. An attacker could use this issue to cause a denial of service. The assigned identifier is CVE-2025-63913.
09
Angular Server-Side Rendering (SSR): Denial of Service via Numeric URL Matrix Parameters
HIGH
GitHub Advisory Database published GHSA-ff3f-86qr-9cv3 for CVE-2026-101896 (Angular Server-Side Rendering): Uncontrolled Resource Consumption, CVSS v4.0 8.2; affected: @angular/router >=22.0.0 and <22.2.0; >=21.0.0 and <21.2.24; >=20.0.0 and <20.3.32; and <=19.2.25.
10
Multiple vulnerabilities in jackson-databind
HIGH
jackson-databind carries 2 CVEs across 2 advisories: Uncontrolled Resource Consumption. CVE coverage: CVE-2026-91777, CVE-2026-91776.
11
@grpc/grpc-js: Improper Certificate Validation
HIGH
CVE coverage: CVE-2026-101916, CVE-2026-101915. GitHub Advisory Database published GHSA-m9gg-hp2v-232j for CVE-2026-101916 (@grpc/grpc-js): Improper Certificate Validation, CVSS v3.1 7.4.
12
Multiple vulnerabilities in WatchGuard FireWare OS
HIGH
CVE coverage: CVE-2026-18145, CVE-2026-13046. The cited advisories disclose: spamd statushdlr Stack-based Buffer Overflow Remote Code Execution Vulnerability; samld SAMLSession Deserialization of Untrusted Data Remote Code Execution Vulnerability.
13
Multiple vulnerabilities in ImageMagick
MEDIUM
It was discovered that ImageMagick did not correctly handle certain images. An attacker could possibly use this issue to cause a denial of service or obtain sensitive information. The assigned identifier is CVE-2026-56367.
14
LiteLLM: Server-Side Request Forgery
MEDIUM
GitHub Advisory Database published GHSA-3cv6-jpf6-8222 for CVE-2026-84377 (LiteLLM): Server-Side Request Forgery, CVSS v3.1 6.5; affected: Versions before 1.88.6 and versions from 1.89.0 to before 1.96.2.
15
DIVD says Zammad zero-days enabled AI-driven network breach
INFO
The Dutch Institute for Vulnerability Disclosure (DIVD) says that the breach of its network was possible by exploiting a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system. (Unconfirmed, single-source.)

Executive assessment

Today's brief leads with Cisco Catalyst SD-WAN Manager: API Authentication Bypass. All 15 selected findings retain their own technical scope, action, observed status, and evidence limits.

Panel synthesis: Finding 01 should lead because it is a CRITICAL Cisco Catalyst SD-WAN Manager API authentication bypass with in-the-wild exploitation, fixed releases listed, and immediate access-control mitigations available. Patch order: Finding 01 (CRITICAL API authentication bypass with in-the-wild exploitation and fixed releases available); Finding 03 (HIGH severity with in-the-wild exploitation to deploy web shells and harvest authentication secrets; fixed in Zimbra Collaboration Suite 10.1.20); Finding 04 (HIGH severity memory corruption issue with in-the-wild exploitation; fixed version is unspecified, so use Lockdown Mode and hunt for the published DarkSword indicators if patching is not possible); Finding 02 (CRITICAL Authen::SASL vulnerability with a fixed release available, even though no exploitation is reported); Finding 07 (HIGH severity OpenStack Keystone vulnerabilities with PoC exploitation and fixed versions available).

Also today: 2 more GitPython CVEs (CVE-2026-87817, CVE-2026-87819) in the same disclosure wave as the GitPython card of 2026-09-17; none reported exploited; carried as a note rather than a finding.

Finding 01 — Cisco Catalyst SD-WAN Manager: API Authentication Bypass

What changed: A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint.

Technical evidence: CVE-2026-76504; CVSS v3.1 9.8; weakness CWE-177; technical confidence High.

Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.

Observed status: Observed in-the-wild exploitation is confirmed.

Analyst note: For on-premises deployments, block access from unsecured networks and, if internet access is required, allow only known, trusted hosts through a firewall. Audit web logs, including vmanage-server.log, for unexpected traffic and j_security_check calls from unknown or unauthorised IP addresses. Cisco PSIRT reports active exploitation in September 2026. ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU))

Affected: Cisco Catalyst SD-WAN Software releases earlier than 20.9; 20.9 before 20.9.10.1; 20.12 before 20.12.8.2; 20.15 before 20.15.6.1; 20.18 before 20.18.4.1; 26.1 before 26.1.2.1; and 26.2 before 26.2.1. ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU))

Fix: 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1; Cisco SD-WAN Cloud (Cisco Managed) 20.15.605. ([sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU))

Panel assessment: Patch now: active exploitation plus unauthenticated remote access to admin privileges makes any exposed Catalyst SD-WAN Manager a control-plane priority, not a routine edge-device update. The likely path is a URI-encoded HTTP request that bypasses the API session authentication rule and reaches the restricted endpoint as an admin user, giving the attacker management-level access to the SD-WAN manager rather than a low-privilege foothold. (priority: patch now)

Action: Map CVE-2026-76504 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: cisa.gov](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?vulnId=CVE-2026-76504)

Finding 02 — Authen::SASL: Authentication Bypass by Capture-replay

What changed: It was discovered that Authen::SASL, a Perl authentication library, did not properly validate login attempts. An attacker could possibly use this issue to gain unauthorized access.

Technical evidence: CVE-2026-86219; CVSS v3.1 9.8; weakness CWE-294; technical confidence High.

Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Affected: Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100. ([lists.security.metacpan.org](https://lists.security.metacpan.org/cve-announce/msg/43326063/))

Fix: Authen-SASL 2.2100 or later. ([lists.security.metacpan.org](https://lists.security.metacpan.org/cve-announce/msg/43326063/))

Action: Map CVE-2026-86219 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: ubuntu.com](https://ubuntu.com/security/notices/USN-8858-1)

Finding 03 — Zimbra: OS Command Injection

What changed: Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from the Microsoft Security Research team. The attack exploits CVE-2026-73570 (CVSS score: 8.9), an unauthenticated operating system command injection flaw that can lead to remote code execution when Simple Network Management Protocol.

Technical evidence: CVE-2026-73570; CVSS v3.1 8.9; weakness CWE-78; technical confidence High.

Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.

Observed status: Observed in-the-wild exploitation is confirmed.

Analyst note: If patching is not possible, uninstall the zimbra-snmp package, disable SNMP notifications, and restrict SNMP and SMTP access to trusted hosts. CISA reports evidence of active exploitation. ([thehackernews.com](https://thehackernews.com/2026/09/attackers-exploit-zimbra-flaw-to-deploy.html), [cisa.gov](https://www.cisa.gov/news-events/alerts/2026/08/21/cisa-adds-one-known-exploited-vulnerability-catalog), [services.nvd.nist.gov](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-73570), +1 more)

Affected: Zimbra Collaboration versions before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. ([services.nvd.nist.gov](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-73570))

Fix: Zimbra Collaboration Suite 10.1.20. ([blog.zimbra.com](https://blog.zimbra.com/2026/07/patch-release-update-zimbra-10-1-20/))

Panel assessment: Patch now: this is unauthenticated remote code execution with confirmed active exploitation, and the observed blast radius includes web shell persistence, mailbox access, and authentication secret harvesting. The likely path is command injection through Zimbra's optional SNMP notification path when zimbra-snmp is installed and enabled, giving attackers command execution on the Zimbra host and access to mail data. (priority: patch now)

Action: Map CVE-2026-73570 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: thehackernews.com](https://thehackernews.com/2026/09/attackers-exploit-zimbra-flaw-to-deploy.html)

Finding 04 — Vulnerability in Apple iOS, iPadOS and macOS

What changed: A malicious application may cause unexpected changes in memory shared between processes. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS Tahoe 26.1, tvOS 26.1, visionOS 26.1, watchOS 26.1.

Technical evidence: CVE-2025-43510; CVSS v3.1 7.8; weakness CWE-667; technical confidence High.

Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.

Observed status: Observed in-the-wild exploitation is confirmed.

Analyst note: If patching is not possible, enable Lockdown Mode. Hunt for the published DarkSword indicators of compromise. Google Threat Intelligence Group reports CVE-2025-43510 was used in the DarkSword chain by multiple commercial surveillance vendors and suspected state-sponsored actors. ([cloud.google.com](https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain/))

Affected: Observed DarkSword exploit-chain support: iOS 18.4 through 18.7. ([cloud.google.com](https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain/))

Action: Map CVE-2025-43510 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2025-43510)

Finding 05 — Concrete CMS Community Store: Cross-site Scripting

What changed: Concrete CMS Community Store before 2.7.8 renders customer-supplied order fields without HTML escaping in checkout and admin views. Unauthenticated attackers can store script payloads in billing name, email, or phone fields that execute in authenticated manager sessions to create rogue accounts or exfiltrate data.

Technical evidence: CVE-2026-93659; CVSS v4.0 8.6; weakness CWE-79; technical confidence Medium.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: CISA ADP reports no exploitation. ([cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-93659))

Affected: Community Store versions from 0 to before 2.7.8. ([cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-93659))

Fix: Version 2.7.8. ([cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-93659))

Action: Map CVE-2026-93659 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-93659)

Finding 06 — Multiple vulnerabilities in OpenVPN

What changed: It was discovered that OpenVPN had a use-after-free vulnerability in its TLS session handling. An attacker could possibly use this issue to cause OpenVPN to crash, resulting in a denial of service, or execute arbitrary code.

Technical evidence: CVE-2026-84732; CVSS v4.0 8.7; weakness CWE-190; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Affected: CVE-2026-84732 affects OpenVPN through versions 2.6.22 and 2.7.6. ([ubuntu.com](https://ubuntu.com/security/CVE-2026-84732))

Action: Map CVE-2026-84732 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

[Evidence source: ubuntu.com](https://ubuntu.com/security/notices/USN-8852-1)

Finding 07 — OpenStack Keystone: Incorrect Authorization

What changed: Grzegorz Grasza discovered that OpenStack Keystone did not consistently enforce restrictions for delegated authentication tokens. An authenticated attacker could possibly use this issue to create credentials or delegations that outlasted the delegated token.

Technical evidence: CVE-2026-80182; CVSS v4.0 7.6; weakness CWE-863; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: If OAuth1 authentication is not required, remove 'oauth1' from the [auth] methods configuration option in keystone.conf. Restrict access to the Keystone API to trusted networks via firewall rules. CISA ADP classifies exploitation as 'poc'. ([access.redhat.com](https://access.redhat.com/security/cve/CVE-2026-80182), [security.openstack.org](https://security.openstack.org/ossa/OSSA-2026-037.html), [cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-80182), +1 more)

Fix: OpenStack Keystone 27.0.3, 28.0.3, and 29.0.3. ([api.osv.dev](https://api.osv.dev/v1/vulns/CVE-2026-80182))

Panel assessment: Patch now where Keystone is deployed, especially if the Keystone API is reachable outside trusted networks, because PoC-level exploitation exists and the blast radius is the OpenStack identity plane rather than a single workload. (priority: patch now)

Action: Map CVE-2026-80182 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: ubuntu.com](https://ubuntu.com/security/notices/USN-8854-1)

Finding 08 — OpenSBI: Uncontrolled Resource Consumption

What changed: It was discovered that OpenSBI did not properly validate the counter index mask in SBI PMU extension requests. An attacker could use this issue to cause a denial of service.

Technical evidence: CVE-2025-63913; CVSS v3.1 7.5; weakness CWE-400; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: Until patched, do not permit untrusted software to control S-mode or HS-mode privileged supervisor execution. Monitor firmware console output for "csr_write_num: Unknown CSR 0xb3f". The RustSBI security team reports that its reproducer demonstrates the issue on OpenSBI v1.3. ([github.com](https://github.com/luojia65/opensbi-pmu2-crash), [ubuntu.com](https://ubuntu.com/security/notices/USN-8853-1))

Affected: OpenSBI 1.3 through 1.6. ([github.com](https://github.com/luojia65/opensbi-pmu2-crash))

Fix: OpenSBI 1.7 and later ([github.com](https://github.com/luojia65/opensbi-pmu2-crash), [ubuntu.com](https://ubuntu.com/security/notices/USN-8853-1))

Action: Map CVE-2025-63913 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: ubuntu.com](https://ubuntu.com/security/notices/USN-8853-1)

Finding 09 — Angular Server-Side Rendering (SSR): Denial of Service via Numeric URL Matrix Parameters

What changed: GitHub Advisory Database published GHSA-ff3f-86qr-9cv3 for CVE-2026-101896 (Angular Server-Side Rendering): Uncontrolled Resource Consumption, CVSS v4.0 8.2; affected: @angular/router >=22.0.0 and <22.2.0; >=21.0.0 and <21.2.24; >=20.0.0 and <20.3.32; and <=19.2.25.

Technical evidence: CVE-2026-101896; CVSS v4.0 8.2; weakness CWE-400, CWE-770; technical confidence Medium.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: At the edge or reverse proxy, reject or strip semicolons in request paths before forwarding them to Angular SSR. Also reject paths deeper than 20–30 segments. ([github.com](https://github.com/angular/angular/security/advisories/GHSA-ff3f-86qr-9cv3), [github.com](https://github.com/angular/angular/pull/70717))

Affected: @angular/router >=22.0.0 and <22.2.0; >=21.0.0 and <21.2.24; >=20.0.0 and <20.3.32; and <=19.2.25. ([github.com](https://github.com/angular/angular/security/advisories/GHSA-ff3f-86qr-9cv3))

Fix: @angular/router 22.2.0, 21.2.24 and 20.3.32. ([github.com](https://github.com/angular/angular/security/advisories/GHSA-ff3f-86qr-9cv3))

Action: Map CVE-2026-101896 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: github.com](https://github.com/advisories/GHSA-ff3f-86qr-9cv3)

Finding 10 — Multiple vulnerabilities in jackson-databind

What changed: jackson-databind carries 2 CVEs across 2 advisories: Uncontrolled Resource Consumption. CVE coverage: CVE-2026-91777, CVE-2026-91776.

Technical evidence: CVE-2026-91777; CVSS v3.1 7.5; weakness CWE-400; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: Bound the size of JSON documents deserialised into @JsonIdentityInfo-enabled collections and maps, and cap the number of elements accepted for those types. Remove @JsonIdentityInfo from types reachable from attacker-influenced input and apply wall-clock timeouts to deserialisation. CISA ADP Vulnrichment reports proof-of-concept exploitation. ([github.com](https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24), [raw.githubusercontent.com](https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/91xxx/CVE-2026-91777.json), [cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-91776), +1 more)

Affected: com.fasterxml.jackson.core:jackson-databind 2.0.0–2.18.10, 2.19.0–2.21.6 and 2.22.0–2.22.2; tools.jackson.core:jackson-databind 3.0.0–3.1.6 and 3.2.0–3.2.2 ([github.com](https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24), [api.github.com](https://api.github.com/advisories/GHSA-wv8q-qhhj-9h54))

Fix: com.fasterxml.jackson.core:jackson-databind 2.18.11, 2.21.7 and 2.22.3; tools.jackson.core:jackson-databind 3.1.7 and 3.2.3 ([github.com](https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24), [cveawg.mitre.org](https://cveawg.mitre.org/api/cve/CVE-2026-91776))

Action: Map CVE-2026-91777 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: github.com](https://github.com/advisories/GHSA-cxp5-3px4-pw24)

Finding 11 — @grpc/grpc-js: Improper Certificate Validation

What changed: CVE coverage: CVE-2026-101916, CVE-2026-101915. GitHub Advisory Database published GHSA-m9gg-hp2v-232j for CVE-2026-101916 (@grpc/grpc-js): Improper Certificate Validation, CVSS v3.1 7.4.

Technical evidence: CVE-2026-101916; CVSS v3.1 7.4; weakness CWE-295; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-101916 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: fixed version or patch state unknown

[Evidence source: github.com](https://github.com/advisories/GHSA-m9gg-hp2v-232j)

Finding 12 — Multiple vulnerabilities in WatchGuard FireWare OS

What changed: CVE coverage: CVE-2026-18145, CVE-2026-13046. The cited advisories disclose: spamd statushdlr Stack-based Buffer Overflow Remote Code Execution Vulnerability; samld SAMLSession Deserialization of Untrusted Data Remote Code Execution Vulnerability.

Technical evidence: CVE-2026-18145; CVSS v4.0 8.6; weakness CWE-121; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Analyst note: WatchGuard reports that it is not aware of exploitation in the wild for either vulnerability. ([psirt.watchguard.com](https://psirt.watchguard.com/CVE-2026-18145), [psirt.watchguard.com](https://psirt.watchguard.com/CVE-2026-13046))

Affected: T15/T35 >= 12.0, < 12.5.21; EUCC >= 12.11, < 12.11.10 ([psirt.watchguard.com](https://psirt.watchguard.com/CVE-2026-18145), [psirt.watchguard.com](https://psirt.watchguard.com/CVE-2026-13046))

Fix: CVE-2026-18145: Fireware OS 2026.3.2, 2026.2.3, 12.12.3 and 12.5.21. CVE-2026-13046: Fireware OS 2026.2.3, 12.12.3 and 12.11.10. ([psirt.watchguard.com](https://psirt.watchguard.com/CVE-2026-18145), [psirt.watchguard.com](https://psirt.watchguard.com/CVE-2026-13046))

Action: Map CVE-2026-18145 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: zerodayinitiative.com](http://www.zerodayinitiative.com/advisories/ZDI-26-750/)

Finding 13 — Multiple vulnerabilities in ImageMagick

What changed: It was discovered that ImageMagick did not correctly handle certain images. An attacker could possibly use this issue to cause a denial of service or obtain sensitive information.

Technical evidence: CVE-2026-56367; CVSS v4.0 6.3; weakness CWE-125; technical confidence Medium.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Analyst note: Until patching is complete, configure ImageMagick's security policy to deny all external delegates and coders except a small subset of required web-safe image types. CISA ADP Vulnrichment reports "Exploitation: none" for all six CVEs. ([imagemagick.org](https://imagemagick.org/security-policy/), [github.com](https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-273h-m46v-96q4), [github.com](https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-3rjr-534c-8v67), +10 more)

Affected: CVE-2026-56367: ImageMagick <7.1.2-15 and 6.x <6.9.13-40, on 32-bit builds only. CVE-2026-93586 through CVE-2026-93589: <7.1.2-31 and 6.x <6.9.13-56. CVE-2026-93590: <7.1.2-31. ([github.com](https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-273h-m46v-96q4), [github.com](https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-3rjr-534c-8v67), [github.com](https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-89wq-f8f6-2j2v), +3 more)

Fix: CVE-2026-56367: 7.1.2-15 and 6.9.13-40. CVE-2026-93586 through CVE-2026-93589: 7.1.2-31 and 6.9.13-56. CVE-2026-93590: 7.1.2-31. ([github.com](https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-273h-m46v-96q4), [github.com](https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-3rjr-534c-8v67), [github.com](https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-89wq-f8f6-2j2v), +3 more)

Action: Map CVE-2026-56367 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: ubuntu.com](https://ubuntu.com/security/notices/USN-8859-1)

Finding 14 — LiteLLM: Server-Side Request Forgery

What changed: GitHub Advisory Database published GHSA-3cv6-jpf6-8222 for CVE-2026-84377 (LiteLLM): Server-Side Request Forgery, CVSS v3.1 6.5; affected: Versions before 1.88.6 and versions from 1.89.0 to before 1.96.2.

Technical evidence: CVE-2026-84377; CVSS v3.1 6.5; weakness CWE-918; technical confidence Medium.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Analyst note: Set general_settings.allow_client_side_credentials to false and restrict proxy keys to trusted callers. Block api_base, base_url, model_list, fallbacks and provider credential fields at a reverse proxy or API gateway. CISA Coordinator reports no exploitation. ([api.osv.dev](https://api.osv.dev/v1/vulns/GHSA-3cv6-jpf6-8222), [services.nvd.nist.gov](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-84377))

Affected: Versions before 1.88.6 and versions from 1.89.0 to before 1.96.2. ([services.nvd.nist.gov](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-84377))

Fix: 1.88.6, 1.89.7, 1.90.7, 1.91.5, 1.92.2, 1.93.2, 1.94.3, 1.95.1 and 1.96.2. ([api.osv.dev](https://api.osv.dev/v1/vulns/GHSA-3cv6-jpf6-8222))

Action: Map CVE-2026-84377 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

[Evidence source: github.com](https://github.com/advisories/GHSA-3cv6-jpf6-8222)

Finding 15 — DIVD says Zammad zero-days enabled AI-driven network breach

What changed: The Dutch Institute for Vulnerability Disclosure (DIVD) says that the breach of its network was possible by exploiting a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system. (Unconfirmed, single-source.)

Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.

Observed status: The cited source reports active in-the-wild exploitation; independent corroboration (CISA KEV or grounded vendor data) is not yet available.

Action: Review the cited source, validate exposure of the affected technology in owned environments, apply available vendor guidance, and retain evidence of the exposure decision.

Evidence limits: grounded severity unavailable

exploitation reported by the source, not independently corroborated

fixed version or patch state unknown

[Evidence source: bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/divd-says-zammad-zero-days-enabled-ai-driven-network-breach/)

catalyst-sd-wan-managercve-2025-43510cve-2025-63913cve-2026-101896cve-2026-101916cve-2026-18145cve-2026-56367cve-2026-73570cve-2026-76504cve-2026-80182

Act on this brief

Map detection coverage gaps for the techniques above, or generate Sigma rules from the named CVEs.