October 1, 2026 opens with one of the most concentrated single-day critical vulnerability disclosures in recent memory. Four distinct product families — Cisco Catalyst SD-WAN Manager, MikroTik RouterOS, Citrix NetScaler, and the Zammad open-source ticketing platform — are all carrying critical, actively exploited flaws simultaneously. The common thread is alarming: every one of these vulnerabilities either bypasses authentication entirely or enables unauthenticated remote code execution, meaning attackers do not need a foothold inside your environment to begin doing serious damage. For SOC teams and security leaders, today is a triage day.

The most immediately urgent item is CVE-2026-76504, a critical authentication bypass in Cisco Catalyst SD-WAN Manager that CISA has already added to its Known Exploited Vulnerabilities catalog. Active exploitation is confirmed. The flaw, described as a hex encoding vulnerability, allows a remote attacker with zero credentials to authenticate as an administrator. SD-WAN Manager is the centralized control plane for Cisco SD-WAN deployments, meaning a successful compromise gives an attacker visibility into and potential control over the routing and policy fabric of an entire enterprise WAN. If your organization runs Cisco Catalyst SD-WAN, this patch is not optional and not deferrable. Restrict management-plane access to trusted IP ranges immediately as a compensating control while patching is coordinated.

Running in parallel is a critical pre-authentication memory overflow in Citrix NetScaler, tracked as CVE-2026-88772, carrying a CVSS score of 9.5. The vulnerability exists in the DTLS handling component and is being actively exploited in the wild to achieve unauthenticated remote code execution via shellcode delivery. NetScaler appliances sit at the perimeter of countless enterprise environments as load balancers and application delivery controllers, making them high-value targets. Organizations should apply Citrix patches immediately, and where patching cannot happen within hours, consider taking affected NetScaler instances offline or placing them behind strict network access controls that block untrusted DTLS traffic at the perimeter.

CISA is also warning of a critical pre-authentication remote code execution vulnerability in MikroTik RouterOS. MikroTik devices are extraordinarily common in branch offices, ISP infrastructure, and small-to-medium enterprise environments, and their management interfaces are frequently exposed to the internet. A pre-auth RCE in RouterOS means an attacker can compromise the device without knowing any credentials, potentially pivoting into the network behind it or enrolling the device into a botnet. MikroTik administrators should update RouterOS to the latest stable release immediately, disable Winbox and web management interfaces from internet-facing interfaces, and audit firewall rules to ensure management ports are not publicly reachable.

Finally, the DIVD disclosure about Zammad deserves serious attention from any organization running this open-source ticketing system. Attackers chained two zero-day vulnerabilities in Zammad to breach the DIVD's own network — a sobering reminder that even security-focused organizations are not immune. The breach was reportedly AI-assisted in its execution, suggesting increasing attacker sophistication in vulnerability chaining. Ticketing systems are particularly dangerous targets because they aggregate sensitive communications, credentials, and incident data. Organizations running Zammad should apply any available patches immediately, review access logs for anomalous API or session activity, and consider whether the system is unnecessarily internet-exposed.

Defensive priorities for today:

- Patch CVE-2026-76504 in Cisco Catalyst SD-WAN Manager immediately; treat this as a P1 emergency given active exploitation and CISA KEV listing
- Restrict SD-WAN Manager access to management VLANs or jump hosts with MFA enforced; block all direct internet access to the management interface
- Patch CVE-2026-88772 in Citrix NetScaler or isolate affected appliances; monitor for anomalous DTLS traffic and unexpected process spawning on NetScaler nodes
- Update MikroTik RouterOS across all devices; audit and close any internet-exposed management interfaces (Winbox port 8291, HTTP port 80/443 on management plane)
- Inventory all Zammad instances, apply patches, and review authentication logs for unusual access patterns or privilege escalation events
- Hunt in SIEM and EDR for lateral movement originating from any of these device classes, particularly new admin sessions, unexpected outbound connections, or configuration changes made outside change windows
- Brief incident response teams now so escalation paths are clear if exploitation is detected

The convergence of these four critical disclosures on a single day underscores a broader trend: network infrastructure and management-plane software are primary targets for sophisticated threat actors, and the window between public disclosure and active exploitation continues to shrink. Organizations that treat patch management as a weekly or monthly cadence will find that cadence insufficient for the current threat environment.

This briefing is informational and does not substitute for official vendor advisories and guidance from Cisco, Citrix, MikroTik, the Zammad project, and CISA.