PDF briefing studio

Prepare a decision-ready brief.

Select a reporting window. Top cyber news, vulnerabilities and CISA ICS advisories are ranked automatically.

OT Daily BriefIndustrial cyber intelligence
Source-groundedweek decision brief
OT / ICS / BAS intelligenceDecision brief / 2026.10.09
Intelligence for industrial defenders

Weekly
cyber risk brief.

October 3, 2026 — October 9, 2026

This edition / priority focus

ProFTPD Improper Access Control Vulnerability

Threat posture36 active signals
Scope15 selected signals
Source-grounded intelligence / selected reporting windowEvidence / exposure / operational context
Analyzed159Feed items
Selected15Relevant signals
Critical41Priority items
Active36Exploitation signals
Sources2Referenced
Vendor concentrationWithin vendors
Citrix3
Zammad GmbH2
ProFTPD1
Apache1
Technology concentrationWithin technologies
NetScaler3
Zammad2
ProFTPD1
Struts1
Period pulseLatest reporting movement
03040506070809
High / Critical / Active exploitation
Editorial movementLatest 4 selected editions
Active threat: ProFTPD Improper Access Control Vulnerability

6 confirmed active-exploitation signals, 6 critical items, and 6 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.

25 analyzed
Active threat: Zammad GmbH Zammad Session Fixation Vulnerability

3 confirmed active-exploitation signals, 9 critical items, and 3 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.

21 analyzed
Active threat: Fortinet FortiMail Path Traversal Vulnerability

4 confirmed active-exploitation signals, 8 critical items, and 4 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.

29 analyzed
Active threat: Fortinet FortiMail Path Traversal Vulnerability

5 confirmed active-exploitation signals, 7 critical items, and 5 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.

21 analyzed

ProFTPD Improper Access Control Vulnerability

13 items have authoritative exploitation evidence and should move first through exposure validation. Current concentration is around ProFTPD, Apache, ISC; use the product context in the queue to compare it with the asset inventory.

13 active exploitation signals2 critical items7 editions reviewed
Now
Validate active exposure

Confirm asset, version, reachability and compensating controls for ProFTPD.

Next window
Plan safe remediation

Review maintenance constraints and vendor guidance for CVE-2026-63692: Dell Container Storage Modules, versions prior to 1.18.0, contain(s) a Missing Authentication for Critical Function vulnerability.

Active threat: ProFTPD Improper Access Control Vulnerability

6 confirmed active-exploitation signals, 6 critical items, and 6 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.

Active threat: Zammad GmbH Zammad Session Fixation Vulnerability

3 confirmed active-exploitation signals, 9 critical items, and 3 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.

Active threat: Fortinet FortiMail Path Traversal Vulnerability

4 confirmed active-exploitation signals, 8 critical items, and 4 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.

01
ACTIVECVEOT relevance 15%EPSS 96.8%

CVE-2015-3306: ProFTPD Improper Access Control Vulnerability

ProFTPD contains an improper access control vulnerability that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

ProFTPD / ProFTPDCISA KEV
02
ACTIVECVEOT relevance 15%EPSS 93.4%

CVE-2016-3081: Apache Struts Command Injection Vulnerability

Apache Struts contains a command injection vulnerability that could allow remote attackers to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Apache / StrutsCISA KEV
03
ACTIVECVEOT relevance 15%EPSS 91.3%

CVE-2015-5477: ISC BIND Data Processing Errors Vulnerability

ISC BIND contains a data processing errors vulnerability that could allow remote attackers to cause a denial of service via TKEY queries. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

ISC / BINDCISA KEV
04
ACTIVECVEOT relevance 15%EPSS 8.2%

CVE-2021-3199: ONLYOFFICE Docs Server Path Traversal Vulnerability

ONLYOFFICE Docs contains a path traversal vulnerability that can occur when JWT is used, via a /.. sequence in an image upload parameter and could allow for remote code execution. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

ONLYOFFICE / DocsCISA KEV
05
ACTIVECVEOT relevance 15%EPSS 2.2%

CVE-2026-104286: Fortinet FortiMail Path Traversal Vulnerability

Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Fortinet / FortiMailCISA KEV
06
ACTIVECVEOT relevance 15%EPSS 1.7%

CVE-2023-22894: Strapi Cleartext Storage of Sensitive Information Vulnerability

Strapi contains a cleartext storage of sensitive information vulnerability that could allow attackers with access to the admin panel to discover sensitive user details via the query filter. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. This vulnerability can be chained with CVE-2023-22621 to achieve remote code execution. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Strapi / StrapiCISA KEV
07
ACTIVECVEOT relevance 15%EPSS 1.6%

CVE-2026-76504: Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability

Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Cisco / Catalyst SD-WAN ManagerCISA KEV
08
ACTIVECVEOT relevance 15%EPSS 1.4%

CVE-2026-102489: Zammad GmbH Zammad Session Fixation Vulnerability

Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Zammad GmbH / ZammadCISA KEV
09
ACTIVECVEOT relevance 15%EPSS 1.3%

CVE-2026-88772: Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Citrix / NetScalerCISA KEV
10
ACTIVECVEOT relevance 15%EPSS 1.2%

CVE-2026-86950: Apple Multiple Products Out-of-Bounds Write Vulnerability

Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Apple / Multiple ProductsCISA KEV
11
ACTIVECVEOT relevance 15%EPSS 1.1%

CVE-2026-88771: Citrix NetScaler Improper Input Validation Vulnerability

Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Citrix / NetScalerCISA KEV
12
ACTIVECVEOT relevance 15%EPSS 0.6%

CVE-2026-102490: Zammad GmbH Zammad Improper Privilege Management Vulnerability

Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Zammad GmbH / ZammadCISA KEV
CVECISA KEVActive signal

CVE-2015-3306: ProFTPD Improper Access Control Vulnerability

ProFTPD contains an improper access control vulnerability that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CISA KEV
CVECISA KEVActive signal

CVE-2016-3081: Apache Struts Command Injection Vulnerability

Apache Struts contains a command injection vulnerability that could allow remote attackers to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CISA KEV
CVECISA KEVActive signal

CVE-2015-5477: ISC BIND Data Processing Errors Vulnerability

ISC BIND contains a data processing errors vulnerability that could allow remote attackers to cause a denial of service via TKEY queries. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CISA KEV
Active threat: ProFTPD Improper Access Control Vulnerability6 confirmed active-exploitation signals, 6 critical items, and 6 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.25 analyzed
Active threat: Zammad GmbH Zammad Session Fixation Vulnerability3 confirmed active-exploitation signals, 9 critical items, and 3 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.21 analyzed
Active threat: Fortinet FortiMail Path Traversal Vulnerability4 confirmed active-exploitation signals, 8 critical items, and 4 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.29 analyzed
Active threat: Fortinet FortiMail Path Traversal Vulnerability5 confirmed active-exploitation signals, 7 critical items, and 5 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.21 analyzed
Active threat: Fortinet FortiMail Path Traversal Vulnerability6 confirmed active-exploitation signals, 3 critical items, and 6 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.19 analyzed
Active threat: Fortinet FortiMail Path Traversal Vulnerability5 confirmed active-exploitation signals, 3 critical items, and 5 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.18 analyzed
Active threat: Fortinet FortiMail Path Traversal Vulnerability7 confirmed active-exploitation signals, 5 critical items, and 7 high-severity items passed the OT relevance filter. Prioritization combines authoritative-source evidence, exploit status, CVSS and industrial context.26 analyzed
Methodology / transparent by design

Evidence first.
Context always.

A triage aid for exposure validation and operational review.

Exploit evidence
OT relevance
Severity
Source confidence
+10EPSS acceleratorMaximum additional points
100-point base model + up to 10 predictive points. The score is not a percentage of plant risk.
Evidence standard

Active exploitation is reserved for authoritative confirmation. CVSS alone is never treated as operational risk; exposure, process context and safe remediation remain essential.