Secret CISO 10/5: Cisco ISE Auth Bypass, FTAPI Ransomware, PeopleSoft WAF Trick, FortiMail 0-day

Today’s theme is “control-plane trust.” One stolen user mailbox, one unauth API endpoint, one edge appliance feature, and one WAF rule gap are all it takes to turn “we’re fine” into “we’re filing notices.”

Share
Cisco ISE authentication bypass (CVE-2026-76460)

Some days the attackers bring new magic. Today they just bring receipts for things we told ourselves were “contained”: control planes, admin APIs, and one user who can see everything.

Today's Top 5

  1. Cisco ISE auth bypass: An unauthenticated API path can let attackers bypass authentication in Cisco ISE, and it is the kind of “your NAC is now your attacker’s NAC” problem. Source
  2. FTAPI confirms ransomware: Secure file transfer vendor FTAPI says ransomware hit a single internal server after a leak-site listing, but the customer-facing implications are still the uncomfortable question. Source
  3. PeopleSoft WAF bypass returns: A “patch later” strategy meets an encoded-path trick that slips past string-matching WAF rules, and attackers get back to the same old high-privilege servlet. Source
  4. FortiMail exploited bug: Fortinet warns CVE-2026-104286 is actively exploited, with a mitigation-first posture that forces teams to choose between features and exposure. Source
  5. Law firm social engineered: One attorney, one “sophisticated” lure, and suddenly client documents are out the door even while the firm insists its network was not compromised. Source

Why today matters: The common pattern is not malware, it is authority. Attackers are targeting the places where a single success grants organization-wide leverage: NAC admin planes, appliance web portals, privileged servlets, and “one user” in a high-trust firm. If you run identity, email security, or enterprise admin consoles, assume you are the shortest path, not a separate system.

Alright. Let’s get specific.

Data Breaches

Sheppard Mullin social engineering breach notice
  1. Sheppard, Mullin, Richter & Hampton LLP breach notice: A California filing says a single attorney was hit by a social engineering event on August 31, 2026, leading to unauthorized disclosure of certain documents to an unknown third party. The firm states the incident was limited to the individual and that there was no compromise of its systems or network, which is exactly why high-risk document access needs its own controls. Source: California DOJ (filing page)
  2. Fragomen breach notice (immigration services law firm): A California-posted notice states an unauthorized party gained remote access to a single user account on May 5, 2026 as part of a social engineering campaign, then accessed and copied a subset of files. If your “one user” can export client packets, your DLP boundary is imaginary. Source: California DOJ (notice PDF)
  3. FTAPI ransomware incident (vendor confirmation): FTAPI, a German secure data-exchange provider, confirmed ransomware affected one internally operated server after a leak-site listing, per summaries citing FTAPI’s statements to press. Even when the blast radius is “one box,” vendor trust questions land on every customer risk register at once. Source: CyberBreaches incident writeup
  4. Dodo Pizza cyberattack disclosure: Dodo Pizza said attackers breached its IT systems and may have accessed customer data during an attack spanning September 27 to 28, 2026, while larger alleged data volumes circulated separately and were not confirmed by the company. This is the modern comms trap: the claim spreads faster than the confirmation. Source: This Info
  5. States Industries extortion claim: The Storm ransomware group posted an extortion note claiming an attack against States Industries on October 3, 2026 and threatened a future leak. Treat it as unverified until the company confirms, but use the time to hunt for the usual pre-ransomware tradecraft: credential theft and remote access tooling. Source: DeXpose

Security Research

FTAPI confirms ransomware on internal server
  1. Cisco ISE authentication bypass (CVE-2026-76460): Cisco warns an unauthenticated remote attacker can bypass authentication due to an API issue in Identity Services Engine. For many orgs, ISE sits on the “who can talk to what” choke point, so compromise is a network-wide policy rewrite, not just a box-level incident. Source: Cisco advisory
  2. Fortinet FortiMail exploited vulnerability (CVE-2026-104286): CERT-FR summarizes Fortinet’s bulletin FG-IR-26-175 and notes Fortinet reports active exploitation. The operational takeaway is ugly but practical: if your mitigation is “disable the feature,” your risk is tied to business workflow, not just patch cadence. Source: CERT-FR
  3. Rejetto HFS exploitation observed (CVE-2026-61500): VulnCheck reports exploitation observed as of October 1, 2026 for an unauthenticated issue enabling session forgery and admin impersonation. Internet-facing file servers remain the gift that keeps on giving to initial access brokers. Source: VulnCheck Initial Access
  4. Oracle PeopleSoft exploitation revival via WAF bypass: Reporting highlights attackers bypassing certain WAF mitigations to resume exploiting CVE-2026-35273, with the reminder that WAF rules are not a substitute for Oracle’s patch. If you still have PSEMHUB exposed, you do not have a perimeter, you have an invitation. Source: TechRadar
  5. YARA-X 1.21.0 release: SANS ISC notes the YARA-X 1.21.0 release with improvements and bugfixes. This is small, but it matters if you are standardizing on YARA-X in pipelines and want fewer footguns in CLI automation. Source: SANS ISC

Top CVEs

Fortinet FortiMail CVE-2026-104286 exploited
  1. CVE-2026-76460: Cisco Identity Services Engine (ISE) API authentication bypass that can allow unauthenticated remote access. If ISE is your network policy brain, treat this like domain admin exposure and patch like it. Source
  2. CVE-2026-104286: Fortinet FortiMail vulnerability reported as actively exploited, with vendor mitigations and patch timelines driving near-term exposure decisions. Watch for indicators and apply vendor guidance immediately, especially on internet-facing appliances. Source
  3. CVE-2026-61500: Rejetto HTTP File Server (HFS) unauthenticated session-forgery leading to admin access and observed exploitation per VulnCheck reporting. If HFS exists anywhere you forgot about, assume attackers already found it. Source
  4. CVE-2026-93616: Check Point management pre-auth vulnerability with vendor-confirmed exploitation in the wild. Management planes are soft targets because they often sit “behind the firewall” and therefore behind your monitoring. Source
  5. CVE-2026-35273: Oracle PeopleSoft PeopleTools critical vulnerability previously patched by Oracle, with current reporting focused on bypassing WAF-only mitigations to keep exploitation going. The only durable fix is patching and disabling unneeded components like Environment Management Hub. Source

Podcasts & Talks

SANS Stormcast on ScreenConnect abuse and ClickFix
  1. SANS Stormcast (Oct 2, 2026): This episode links together abuse of legitimate remote admin tooling and attacker use of ChatGPT surfaces for ClickFix-style delivery. A CISO should care because your controls need to distinguish “allowed tool” from “allowed outcome.” Listen: SANS ISC

Final Words

Today’s underlying pattern is authority abuse through the softest possible interfaces: an API endpoint, a web portal feature, an encoded path, and a human who can be convinced. The threat model shift is that “internal” admin systems are now externally reachable through tiny mistakes. The uncomfortable implication most coverage skips is this: your monitoring and change control on admin planes is probably weaker than on endpoints, even though the blast radius is bigger.

This week, do three things:

  • Patch or isolate Cisco ISE for CVE-2026-76460, then review ISE admin access paths and log retention for authentication anomalies tied to the advisory window.
  • Apply Fortinet’s mitigations for FortiMail CVE-2026-104286 immediately, and validate whether IBE or other exposed web features are enabled on any internet-facing FortiMail instance.
  • Run an exposure hunt for Rejetto HFS and patch CVE-2026-61500, then block inbound access to any HFS host that is not explicitly business-critical and monitored.

Your turn: Honestly, if your NAC brain (ISE) got popped tomorrow, do you have a tested “network safe mode” that keeps the business running without trusting the compromised policy engine? Hit reply with your one-sentence answer, or drop a comment on the web version. I read every reply.

Know someone who still treats ISE as “just another appliance” and patches it quarterly? Forward them this issue, it costs 30 seconds and the alternative costs a lot more. For forwarded and web readers, subscribe free at secretciso.org.

Stay vigilant, stay informed, and see you in the next edition of Secret CISO!