Monday, October 5, 2026 Newsletter Advertise
Breaking
Top 10

Top 10 vulnerabilities of the week (Sep 29–Oct 5, 2026): 6 actively exploited

This week's 10 most urgent vulnerabilities, including 6 CISA confirmed as actively exploited, ranked from CISA and NIST data.

Top 10 vulnerabilities, 6 actively exploited, Sep 29–Oct 5, 2026

The 10 vulnerabilities from the past seven days that most need attention, ranked by a fixed rule: flaws CISA confirmed as actively exploited come first (those used in ransomware at the top, then newest first), followed by the highest-scoring Critical CVEs published by NIST’s National Vulnerability Database.

# CVE What it affects Why it ranks Date
1 CVE-2026-88779 Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability Actively exploited (CISA KEV) October 4, 2026
2 CVE-2026-102490 Zammad GmbH Zammad Improper Privilege Management Vulnerability Actively exploited (CISA KEV) October 2, 2026
3 CVE-2026-102489 Zammad GmbH Zammad Session Fixation Vulnerability Actively exploited (CISA KEV) October 2, 2026
4 CVE-2026-104286 Fortinet FortiMail Path Traversal Vulnerability Actively exploited (CISA KEV) October 1, 2026
5 CVE-2026-76504 Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability Actively exploited (CISA KEV) September 30, 2026
6 CVE-2026-86950 Apple Multiple Products Out-of-Bounds Write Vulnerability Actively exploited (CISA KEV) September 29, 2026
7 CVE-2026-105285 A security vulnerability has been detected in Totolink A3002MU 1.0.0-B20230403.1455. This affects an unknown function of the file /boafrm/formIpQoS of the component QoS Rule Handler. The manipulation of the argument add… CVSS 10 Critical (NVD) October 5, 2026
8 CVE-2026-105284 A weakness has been identified in Totolink A3002MU 1.0.0-B20230403.1455. The impacted element is the function sub_40FCFC of the file /bin/boa of the component Authentication Check. Executing a manipulation can lead to i… CVSS 10 Critical (NVD) October 5, 2026
9 CVE-2026-105134 A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects unknown code of the file /rps/api/json/UpdateReceivers.do of the component Replication Receiver. Executing a manipulation of the argument … CVSS 10 Critical (NVD) October 4, 2026
10 CVE-2026-105135 A vulnerability has been found in InternLM MindSearch 0.1.0. This issue affects the function ExecutionAction.run of the file mindsearch/agent/graph.py of the component Planner Agent. The manipulation of the argument inp… CVSS 10 Critical (NVD) October 4, 2026

Descriptions are quoted from CISA and NVD. Always confirm fixed versions in the vendor’s own advisory before prioritizing.

The TechUpscale Brief

The day's cyber, AI and tech news in one short email, every weekday morning. Free. Unsubscribe anytime.

I'm most interested in

More Top 10