Daily briefing · October 1, 2026
FortiMail Path Traversal and Apache HTTP Server Triple Critical Flaws Dominate October 1 Bulletin
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — attention2 seen before CISA
October 1 brings a WATCH-level verdict: two vulnerabilities are confirmed under active exploitation and two were spotted by VulnCheck before any official CISA acknowledgment, underscoring the intelligence gap between early warning signals and formal advisories. A total of 378 new CVEs were published, with 41 rated critical, headlined by a zero-day-speed path traversal in FortiMail already backed by a proof of concept on day one of disclosure, and a perfect-CVSS-10 flaw in Teledyne FLIR's Aware2 robotic software. Three concurrent critical flaws in Apache HTTP Server amplify the urgency for teams running any version through 2.4.68.
Today’s brief
- FortiMail path traversal (CVSS 9.8) was armed on the same day it was disclosed and detected by VulnCheck before CISA — patch or mitigate immediately.
- Three critical Apache HTTP Server CVEs (mod_ssl, mod_http2, mod_rewrite) affect all versions 2.4.0–2.4.68 and should be treated as a cluster requiring a single urgent patch cycle.
- BackupSheep WordPress plugin (CVSS 10.0) allows unauthenticated full-site backup download including password hashes — exposure is trivially exploitable.
- Brazil is under heavy ransomware pressure: seven victims identified recently across government, manufacturing, retail, and technology sectors.
Critical highlights
1
A path traversal in FortiMail 7.2–8.0 allows an unauthenticated attacker to write arbitrary files on the host via crafted HTTP/HTTPS requests; VulnCheck flagged active exploitation before CISA, and a proof of concept was available on day zero — this combination makes it the highest-urgency item in today's bulletin.
2
CVE-2024-58388◆ VulnCheckHIGH 8.7PoCaffects Multiple Multifunction Printers Sharp and Toshiba Tec multifunction printers expose an unauthenticated local file inclusion endpoint where directory traversal sequences in the path parameter let remote attackers read arbitrary files; VulnCheck observed exploitation before CISA, and the wide installed base of these devices in corporate environments raises the blast radius considerably.
3
A perfect CVSS 10.0 path traversal in Teledyne FLIR Aware2 (all versions through 6.9.0.2 for PackBot and 1.7.9 for FirstLook) lets unauthenticated remote attackers read configuration and security parameters on physical robots — a compromise here can have direct operational and physical-safety consequences.
4
The BackupSheep WordPress plugin through version 1.8 treats a blank integration key as valid, enabling any unauthenticated attacker to download a complete site backup including the database with hashed passwords, and to delete arbitrary server files — a straightforward path to full site takeover.
5
An authenticated attacker with low-level permissions in Red Hat Satellite 6.16 (Foreman) can escape the safemode templating sandbox by appending unauthorized functions to the allowed execution list, achieving remote code execution on the server — privilege escalation to RCE in an infrastructure management tool is a serious lateral movement risk.
6
BoKS Manager generates Active Directory service-account passwords from a pseudo-random sequence seeded by the Unix timestamp, making them reproducible if an attacker knows the service principal and can estimate the password-change window — an offline dictionary attack against a limited candidate set is feasible.
7
Improper privilege management in Apache HTTP Server's mod_ssl via SSLRequire and file-related expressions affects all versions 2.4.0 through 2.4.68, and when chained with the other two Apache CVEs disclosed today it significantly raises the attack surface for any exposed web server.
8
A use-after-free in Apache HTTP Server's mod_http2 caused by shared session->bbtmp re-entrancy can lead to memory corruption and potential code execution on all versions 2.4.0–2.4.68; this is one of three concurrent critical Apache flaws that should be patched in a single coordinated update.
9
A use-after-free in Apache HTTP Server's mod_rewrite when processing lookahead expressions (%{LA-U:HTTP:...}) creates an exploitable memory corruption condition across all 2.4.x versions — teams relying on complex rewrite rules are particularly exposed.
10
CVE-2026-12627CVSS 9.8affects Fortra's Core Privileged Access Manager (BoKS) A stack-based buffer overflow in Fortra BoKS boks_autoregisterd allows a remote, unauthenticated attacker with network access to the autoregistration service to trigger memory corruption during client response processing, potentially enabling arbitrary code execution in a privileged access management platform.
Ransomware today
Several Brazilian organizations were recently hit by ransomware across diverse sectors: FUNAP (a São Paulo state prison education foundation, Government & Defense) was claimed by Booba Project; Terca and Engefitas (Manufacturing) were struck by ransomhouse and Vexy Ransomware respectively; camorim.com.br (Retail) was listed by lockbit5; latitudesubro.com (Manufacturing) by BrainCipher; somasolucoes.com (Professional Services) by m3rx; and Amazon Informatica (Technology) by emperador. Among the most active groups over the past 30 days, thegentlemen leads with seven attacks, all targeting Brazil, followed by lockbit5, emperador, akira, Vexy Ransomware, and BrainCipher.
FUNAP - Fundação "Prof. Dr. Manoel Pedro Pimentel" BRBooba Project · Government & Defense
Terca BRransomhouse · Other
Engefitas BRVexy Ransomware · Manufacturing
camorim.com.br BRlockbit5 · Retail & E-Commerce
latitudesubro.com BRBrainCipher · Manufacturing
somasolucoes.com BRm3rx · Professional Services
Amazon Informatica BRemperador · Technology
thegentlemen 7lockbit5 4emperador 3akira 3Vexy Ransomware 3BrainCipher 2
Active groups & APTs
Active or recently updated threat groups include ransomhouse, sinobi, spacebears, thegentlemen, funksec, and APT38 — the North Korean state-sponsored actor known for financially motivated operations including cryptocurrency theft and supply-chain intrusions. The presence of both financially driven ransomware groups and a sophisticated nation-state actor in the current threat landscape signals a broad and heterogeneous risk environment.
Brazil focus
Brazil is facing an unusually concentrated ransomware wave, with at least eight victims identified in recent days spanning government, manufacturing, retail, professional services, and technology sectors. The diversity of attacking groups — from lockbit5 and BrainCipher to arcusmedia and emperador — indicates that Brazilian organizations are being targeted simultaneously by multiple independent ransomware ecosystems, increasing the probability of opportunistic attacks against unpatched or poorly monitored infrastructure.
FUNAP - Fundação "Prof. Dr. Manoel Pedro Pimentel"Booba Project · Government & Defense
Tercaransomhouse · Other
EngefitasVexy Ransomware · Manufacturing
latitudesubro.comBrainCipher · Manufacturing
camorim.com.brlockbit5 · Retail & E-Commerce
somasolucoes.comm3rx · Professional Services
Amazon Informaticaemperador · Technology
Pantaneiro Capasarcusmedia · Manufacturing
Today’s recommendation: Security teams should prioritize patching FortiMail (CVE-2026-104286) and Apache HTTP Server 2.4.x (three concurrent critical CVEs) today, while immediately auditing exposure of the BackupSheep plugin and any Sharp/Toshiba Tec printers reachable from untrusted networks. Organizations using BoKS or Foreman should review access controls and logging for signs of unauthorized activity.
With path traversal, use-after-free, and privilege escalation flaws spanning network appliances, web servers, and access management platforms, now is the moment to validate which of these products are actually reachable in your environment — and whether compensating controls would stop exploitation before a patch can be applied.New vulnerabilities surface every day — does your defense keep up? Get a free initial review of your attack surface.Meet the Autonomous AI Pentest Agent →Previous briefings
October 5, 2026 — Multiple Critical RCE and Auth Bypass Flaws Emerge Across Routers, AI Platforms, and Open-Source ToolsOctober 4, 2026 — ZITADEL Authentication Bypasses and AhsayCBS RCE Headline a Calm but CVE-Heavy DayOctober 3, 2026 — WordPress Plugins and NASA Mission Software Headline a Calm but Patch-Worthy DayOctober 2, 2026 — Three CVEs Spotted by VulnCheck Before CISA, Eight WordPress and Cloud Flaws Round Out a High-Alert DayOctober 1, 2026 — FortiMail Path Traversal and Apache HTTP Server Triple Critical Flaws Dominate October 1 BulletinSeptember 30, 2026 — Cisco SD-WAN Zero-Day and Six Active Exploits Demand Immediate AttentionSeptember 29, 2026 — Two VulnCheck-Flagged SQL Injections, Six Chrome RCEs, and a Wave of Critical Unauthenticated Flaws Demand Immediate AttentionSeptember 28, 2026 — Apple Zero-Day and Netcore Router Cluster Top a High-Alert DaySeptember 27, 2026 — Citrix NetScaler Under Active Attack: Two Critical RCEs Hit KEV on Same DaySeptember 26, 2026 — WordPress and Joomla Plugins Dominate a Calm but Patch-Heavy Day With 18 Critical CVEsSeptember 25, 2026 — 742 New CVEs on a Calm Day, But Critical Flaws in Zimbra, MediaWiki and WordPress Demand AttentionSeptember 24, 2026 — Quiet CVE Day Masks Serious Risks: CVSS 10.0 Flaws and Heavy Ransomware Activity in BrazilSeptember 23, 2026 — Quiet CVE Day Masks Heavy GitLab, ManageEngine, and Ansible ExposureSeptember 22, 2026 — Triple KEV Alert: Check Point, VeloCloud, and F5 BIG-IP Under Active Exploitation as Adobe Campaign Classic Hit by Four Critical RCE Flawsview full archive →