Threat Brief — 2026-10-02 — SWIFT middleware RCE, FortiMail hits CISA KEV
Executive summary: A remote code execution vulnerability in SWIFT-linked banking and government middleware surfaces, urging patches to prevent hardware MFA bypass in high-sensitivity environments. Separately, CISA formally adds Fortinet FortiMail CVE-2026-104286KEV to its Known Exploited Vulnerabilities catalog, confirming active in-the-wild exploitation of the path traversal flaw first disclosed yesterday. Most other major stories from the past 48 hours — GitLab AI Gateway RCE, Dell CSM criticals, the Antino backdoor campaign, and the Pentagon DMDC breach — remain active but without new developments.
Top items
- SWIFT banking and government middleware vulnerable to RCE — A remote code execution flaw in middleware used by SWIFT banking and government systems could enable attackers to exploit hardware-based MFA mechanisms in ultra-sensitive environments. Affected organisations should prioritise patching immediately. (src: DarkReading)
- CISA adds Fortinet FortiMail CVE-2026-104286KEV to Known Exploited Vulnerabilities catalog — The path traversal and NULL-byte injection vulnerability in FortiMail, which allows unauthenticated attackers to write arbitrary files to the target system, has been formally added to CISA's KEV catalog. This confirms active exploitation in the wild. The flaw was first reported on 2026-10-01 by BleepingComputer; the KEV listing is the new development. (src: CISA KEV)
- Kiteworks and Citrix zero-day responses highlight divergent disclosure practices — A comparative analysis notes that Kiteworks advised customers to power down its data-protection platform during a nine-hour patching window, while Citrix remained silent on reported active attacks before releasing a patch. Both stories were previously covered individually (Kiteworks first reported 2026-09-25 by BleepingComputer; Citrix first reported 2026-10-02 by SecurityLab); the new element is the side-by-side critique of incident response transparency. (src: DarkReading)
- Browser-based attacks evade endpoint detection and response telemetry — Analysis describes three categories of browser attacks — session theft, extension abuse, and user manipulation — that operate without generating the endpoint artefacts EDR is designed to catch, reinforcing the case for browser-layer monitoring. (src: BleepingComputer)
Themes
Exploited-in-wild catalog momentum. CISA's KEV addition for FortiMail CVE-2026-104286KEV follows a pattern this week of freshly disclosed critical vulnerabilities moving rapidly to confirmed exploitation, compressing the window between advisory and active threat.
Zero-day response transparency under scrutiny. The Kiteworks/Citrix comparison underscores that patch timing is only half the equation — communication during the gap between discovery and fix release shapes customer risk exposure.
