Cyber Risk Brief: 7 - 13 September 2026

CRB-2514 September 2026Sovereign GRC Intel26 min read

Disclaimer:This brief is governance commentary for leadership and risk teams, not incident notification, public attribution, legal advice, or quantitative risk analysis. Threat prioritization, framework mappings, attribution, and risk-zone groupings are informational only. Validate all technical claims against vendor advisories and internal telemetry before operational response.

Threat Intelligence Summary

Fourteen CISA KEV additions in seven days collapse to eleven register rows, plus PaperCut carrying an older KEV whose clock expires today, and one Canadian incident row that carries no CVE. Cisco FMC CVE-2026-20079 is the highest-EPSS item at 75.75%, confirmed exploited, deadline 12 September, passed. Adobe Commerce CVE-2026-75650, N-central CVE-2026-86218, NetScaler CVE-2026-19490, FortiOS CVE-2025-25249, and MikroTik CVE-2026-86060/67277 also carry passed clocks. GitLab CVE-2026-85706 and ScreenConnect CVE-2026-84869 are due 14 September. Chrome CVE-2026-87491 (due 23 September) and Windows CVE-2026-85880/81963 (due 22 September) are the BlueMoon kit; Artifactory CVE-2026-42018/42016 (due 25 September) is the backdoor chain that continues last week's CVE-2026-82329. Every CVE row is IMMEDIATE. PaperCut CVE-2026-81578/82078 carries the same 14 September clock as GitLab and ScreenConnect, and Arctic Wolf names Canada among the countries its education-sector campaign targeted. The Canadian Centre for Cyber Security issued an Alert or advisory naming the CVE on all eleven, including two Alerts: AL26-019 for NetScaler and AL26-020 for MikroTik RouterOS. T12 is the week's one confirmed Canadian-victim incident, the C-Track Canada court-records breach affecting Ontario's three courts, and it is the only row where PIPEDA applies. Direct KEV reconciliation found three Sheet misses: Artifactory CVE-2026-42016 and CVE-2026-42018, and ScreenConnect CVE-2026-84869.

Threat Register

Threat
T1
Cisco Secure FMC Authentication Bypass to Root (CVE-2026-20079)
CVE-2026-20079 is a CVSS 3.1 10.0 authentication bypass in Cisco Secure Firewall Management Center. An unauthenticated attacker who sends crafted HTTP requests to the web interface can execute scripts and commands as root. Cisco confirmed in a 9 September advisory update that PSIRT became aware of active exploitation in August. CISA added the CVE to KEV on 9 September with a 12 September deadline, now passed. Its EPSS score of 75.75% is the highest in this register.
Critical
12 Sep · passed
T2
Adobe Commerce StyleSmuggler Unauthenticated RCE (CVE-2026-75650)
CVE-2026-75650 is a CVSS 3.1 10.0 template-engine injection in Adobe Commerce, Adobe Commerce B2B, and Magento Open Source. Sansec named it StyleSmuggler and reported unauthenticated remote code execution with attacks starting 4 September, three days before Adobe released hotfix VULN-39341 on 7 September. CISA added the CVE to KEV on 8 September with an 11 September deadline, now passed. CCCS advisory AV26-888 states Adobe indicates the CVE is exploited in the wild.
Critical
11 Sep · passed
T3
N-able N-central Pre-Authentication RCE (CVE-2026-86218)
CVE-2026-86218 is a CVSS 4.0 10.0 static code injection flaw that N-able describes as pre-authenticated remote code execution on the N-central server. N-able released Hotfix 4, build 2026.3.1.14, on 5–6 September. CISA added the CVE to KEV on 8 September with an 11 September deadline, now passed. N-able's public hotfix notes say production exploitation is unconfirmed; CISA's catalog entry is the exploitation authority used here. This CVE is distinct from CVE-2026-18577 and CVE-2026-18556, covered on 10 August.
Critical
11 Sep · passed
T4Canadian impact: CCCS Alert AL26-019 covers this CVE. An Alert is the Cyber Centre tier above a routine advisory, issued for threats that may impact Canadian cyber information assets.
Citrix NetScaler Authentication Bypass (CVE-2026-19490)
CVE-2026-19490 is a CVSS 4.0 9.3 authentication bypass using an alternate path or channel in NetScaler ADC and NetScaler Gateway. Citrix says an unauthenticated attacker can bypass authentication on appliances configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or as an AAA virtual server, with version-specific SAML preconditions. CISA added it to KEV on 9 September with a 12 September deadline, now passed. Singapore CSA states a public proof-of-concept exists and exploitation attempts have been observed. This CVE is distinct from CVE-2026-8452, covered on 31 August.
Critical
12 Sep · passed
T5
Fortinet FortiOS Heap Overflow, PivotC2 RAT (CVE-2025-25249)
CVE-2025-25249 is a CVSS 3.1 8.1 heap-based buffer overflow in the FortiOS and FortiSwitchManager cw_acd daemon. Fortinet says a remote unauthenticated attacker may execute code or commands via crafted requests. SecurityWeek reports SOCRadar observed exploitation to deploy PivotC2, a Node.js RAT, and CISA added the CVE to KEV on 9 September with a 12 September deadline, now passed. Fortinet patched the issue in January 2026.
Critical
12 Sep · passed
T6Canadian impact: CCCS Alert AL26-020 covers this CVE. An Alert is the Cyber Centre tier above a routine advisory, issued for threats that may impact Canadian cyber information assets.
MikroTik RouterOS MikroTrick SSH Takeover (CVE-2026-86060 / CVE-2026-67277)
CISA added CVE-2026-86060 (CVSS 4.0 9.2) and CVE-2026-67277 (CVSS 4.0 8.8) to KEV on 10 September with a 13 September deadline, now passed. CERT Polska and BleepingComputer report the actively exploited MikroTrick chain is CVE-2026-67276 plus CVE-2026-86060, which together give unauthenticated administrative control of RouterOS devices with SSH on the internet. CVE-2026-67276 is the chain partner; it is not a window KEV addition. CVE-2026-67277 is a separate bandwidth-test memory-disclosure and crash flaw that CISA did list. ShadowServer counted 122,500 MikroTik devices with exposed SSH as of 5 September; the vulnerable subset is not stated.
Critical
13 Sep · passed
T7
GitLab Unauthenticated Path Traversal (CVE-2026-85706)
CVE-2026-85706 is a CVSS 3.1 10.0 path-traversal flaw in the GitLab repository commits API that lets an unauthenticated user read arbitrary files from the GitLab server. GitLab patched CE and EE in 19.1.8, 19.2.6, and 19.3.2 on 10 September. SecurityWeek reports watchTowr observed in-the-wild probes one day later. CISA added the CVE to KEV on 11 September with a 14 September deadline. This CVE is distinct from CVE-2026-19478, the GraphQL code-injection flaw covered on 24 August, which is not KEV-listed.
Critical
14 Sep
T8
ConnectWise ScreenConnect Unauthorized File Execution (CVE-2026-84869)
CVE-2026-84869 is a CVSS 3.1 9.9 missing-authorization and improper-privilege-management condition in the ScreenConnect client. ConnectWise says files may be transferred and executed through an active remote session without authorization or host confirmation. Servers are not impacted. The 26.6.5 client patch shipped 8 September. CISA added the CVE to KEV on 11 September with a 14 September deadline. SecurityWeek and Huntress describe worm-like propagation of modified clients that push a four-stage VBScript chain to newly connected hosts.
Critical
14 Sep
T9
Google Chrome V8 Sandbox-Escape Zero-Day (CVE-2026-87491)
CVE-2026-87491 is a CVSS 3.1 8.8 out-of-bounds write in Chrome's V8 engine. Google says an exploit exists in the wild and shipped the fix in Chrome 153.0.8010.36 (Linux) and 153.0.8010.36/.37 (Windows and macOS). CISA added the CVE to KEV on 9 September with a 23 September deadline. Proofpoint, reported by BleepingComputer on 10 September, identifies this CVE as the V8 sandbox-escape stage of the BlueMoon kit, chained after last week's CVE-2026-85046 and before Windows ALPC CVE-2026-85880. That is distinct from last week's standalone Chrome card.
Critical
23 Sep
T10
Windows ALPC and Update Stack Local Privilege Escalation (CVE-2026-85880 / CVE-2026-81963)
Microsoft's 8 September updates address two CVSS 3.1 7.8 local elevation-of-privilege flaws that MSRC marks Exploitation Detected. CVE-2026-85880 is a heap-based buffer overflow in Windows ALPC. CVE-2026-81963 is link-following in the Windows Update Stack. CISA added both to KEV on 8 September with a 22 September deadline. Proofpoint identifies CVE-2026-85880 as the kernel stage of BlueMoon and says the LPE DLL compilation timestamp is from 2025. CVE-2026-81963 is a separate Update Stack issue and is not in that chain.
Critical
22 Sep
T11
JFrog Artifactory Anonymous-Token to Admin Chain (CVE-2026-42018 / CVE-2026-42016)
CVE-2026-42018 is a CVSS 3.1 7.5 improper-authentication flaw that returns an internal anonymous-user JWT to an unauthenticated caller, including when anonymous access is disabled. CVE-2026-42016 is a CVSS 3.1 8.1 incorrect-authorization flaw that lets that token be exchanged for administrator scope. Wiz observed multiple actors chaining the two against self-hosted Artifactory between 15 August and 8 September, then dropping a Rust backdoor. CISA added both to KEV on 11 September with a 25 September deadline. Last week's CVE-2026-82329 remains a separate KEV; Wiz also saw it exploited in this window and it is campaign context, not a second row.
Critical
25 Sep
T12Canadian impact: Arctic Wolf and GreyNoise name Canada among the countries whose education sector this campaign targeted. The University of Toronto published its own advisory on 1 September.
PaperCut NG/MF Auth Bypass to RCE Chain (CVE-2026-81578 / CVE-2026-82078)
CVE-2026-81578 is a CVSS 4.0 8.8 improper-access-control flaw that lets unauthenticated remote requests trigger administrative backend actions before access validation completes. CVE-2026-82078 is a CVSS 4.0 9.4 unsafe dynamic class-loading flaw that executes arbitrary Java bytecode under the PaperCut server process. Chained, they are an unauthenticated full compromise. CISA added both to KEV on 31 August with a 14 September deadline, which is this brief's publication date. PaperCut has since replaced all three Emergency Patch Releases with maintenance releases 26.0.5, 25.0.13, and 24.1.10.
Critical
14 Sep
T13Canadian victim: records from the Court of Appeal for Ontario, the Ontario Superior Court of Justice, and the Ontario Court of Justice. The only row in this brief where PIPEDA applies.
C-Track Canada Court Records Breach, Ontario Courts (no CVE)
C-Track Canada, the court case management platform owned by Thomson Reuters Canada Limited, disclosed that an unauthorized party obtained court files in March 2026. C-Track Canada discovered the activity on 30 June 2026. The Court of Appeal for Ontario, the Ontario Superior Court of Justice, and the Ontario Court of Justice are the affected Canadian court systems. Ontario's three chief justices posted a public statement on 2 September and CBC News reported it on 9 September. No CVE has been assigned and the vendor has not said how access was obtained.
—
—
High
Post-incident
Select a row for narrative, affected systems, remediation, and sources.

Strategic context

Control-plane products dominate the passed-deadline set

  • Cisco FMC CVE-2026-20079, N-central CVE-2026-86218, NetScaler CVE-2026-19490, FortiOS CVE-2025-25249, and RouterOS CVE-2026-86060 are all administrative or enforcement planes whose KEV clocks expired on or before 13 September.
  • A patch ticket on the box is not the control. The control is evidence that the manager, RMM, gateway, firewall, or router was inventoried, upgraded, and hunted for the implant or account the sources named.

Last week's CVEs reappear as stages of this week's kits

  • BlueMoon chains last week's Chrome CVE-2026-85046 with this week's CVE-2026-87491 and Windows ALPC CVE-2026-85880. Wiz chains last week's Artifactory CVE-2026-82329 with CVE-2026-42018 and CVE-2026-42016 and then drops a Rust backdoor.
  • Closing last week's card does not close this week's. The reader who shipped Chrome 152 and Artifactory's first KEV still has two remaining stages on each kit.

The Canadian authority tracked every row in this register

  • The Cyber Centre issued two Alerts this week, its higher tier above a routine advisory, and both land on threats in this register: AL26-019 for NetScaler CVE-2026-19490 (4 September, updated 9 September) and AL26-020 for MikroTik RouterOS (10 September). It also carried an advisory naming the CVE on every other row.
  • An Alert is issued for threats that may impact Canadian cyber information assets, and the Cyber Centre offers direct assistance on its contents. For a Canadian organization the reportable position is not only the CISA KEV clock, it is whether the Cyber Centre's stated actions were performed and evidenced.

Threat Actor Profiling

Talos names UAT-11823 and UAT-12197 against Cisco FMC CVE-2026-20079, and attributes a third cluster, UAT-11988, to Qilin on the related static-credential CVE-2026-20316. Proofpoint and Volexity name JungleBamboo (APT31 / Violet Typhoon), UTA0560, UNK_LateNight, and UNK_DoubleCheck for BlueMoon (Chrome CVE-2026-87491 and Windows CVE-2026-85880). CERT Polska, Huntress, Wiz, and SOCRadar describe unattributed operators on RouterOS, ScreenConnect, Artifactory, and FortiOS. The remaining rows have no named actor. MITRE technique codes are shown as hover-to-define abbreviations.

ThreatsActorSectorsMITRE tradecraftKill chain
T1UAT-11823 (Talos: Sandworm-overlapping APT) and UAT-12197Enterprise, Critical Infrastructure, GovernmentInitial Access → Execution → Persistence → Credential Access
T9T10JungleBamboo (APT31 / Violet Typhoon), UTA0560, UNK_LateNight, UNK_DoubleCheckNGOs, Aerospace, Defense Industrial Base, ManufacturingDelivery → Exploitation → Privilege Escalation → Actions on Objectives
T11Unattributed actors in Wiz telemetrySoftware Development, Cloud, EnterpriseInitial Access → Privilege Escalation → Persistence
T5Unattributed PivotC2 operators observed by SOCRadarEnterprise, Network SecurityInitial Access → Installation → Command and Control
T6Unattributed MikroTrick operators (CERT Polska)Enterprise Networking, Internet ServiceInitial Access → Privilege Escalation → Persistence
T8Unattributed ScreenConnect operators observed by HuntressManaged Services, EnterpriseInitial Access → Execution → Persistence → Lateral Movement
T2T3T4T7Unattributed threat actorsE-commerce, Managed Services, Enterprise, Software DevelopmentInitial Access → Execution → Actions on Objectives
T12Suspected Russian-speaking actor reported by The Hacker News; activity attributed to 45.142.193[.]132 by GreyNoise, Blackpoint Cyber, and Arctic WolfEducation, Public SectorInitial Access → Execution → Credential Access → Discovery
T13Unattributed actor in the C-Track Canada incident; the vendor has not stated how access was obtained or who was responsibleJustice, Public Sector, Legal ServicesInitial Access → Collection → Exfiltration
▶Table methodology & sourcing notes
  • Qilin (UAT-11988) is sourced to CVE-2026-20316, not to this week's CVE-2026-20079 row. BlueMoon attribution is from Proofpoint and Volexity as reported by BleepingComputer. CVE-2026-81963 is not part of that kit.

Control Deficiency & Framework Mapping

ThreatControl gapsISO 27001NIST CSF 2.0CIS ControlsPrivacy Act / PIPEDAITSG-33OSFI B-13ISO 42001
T1Cisco Secure FMC Authentication Bypass to Root (CVE-2026-20079)
  • Firewall managers omitted from the internet-exposure register
  • Hot-fix evidence not collected per FMC version
  • license.tmp hunt not run before declaring the ticket closed
  • TAC not engaged when the Cisco indicator is present
  • Management interface still reachable from untrusted networks
—
—
T2Adobe Commerce StyleSmuggler Unauthenticated RCE (CVE-2026-75650)
  • Commerce instances not on an emergency hotfix inventory
  • Encryption-key rotation not tied to the hotfix
  • Stores live 4–7 September not treated as possibly implanted
  • Payment-reminder code paths not in the hunt playbook
  • Wrong VULN-39341 patch file applied for the installed branch
—
—
T3N-able N-central Pre-Authentication RCE (CVE-2026-86218)
  • On-premises N-central inventory is incomplete
  • Hotfix 3 treated as closure for this CVE
  • Hosted versus on-premises ownership is not assigned
  • RMM compromise hunt not defined after log rotation
  • MSP customer-notification trigger is not documented
—
—
T4Citrix NetScaler Authentication Bypass (CVE-2026-19490)
  • Build strings still cite the 31 August 14.1-72.61 or 13.1-63.18
  • SAML and Gateway preconditions not checked per appliance
  • AAA virtual servers omitted from the in-scope list
  • Filesystem hunt not required after the upgrade
—
—
T5Fortinet FortiOS Heap Overflow, PivotC2 RAT (CVE-2025-25249)
  • January FortiOS tickets closed without verifying the listed fixed release
  • FortiOS 6.4 still present with no migration plan
  • PivotC2 hunt not run before reboot
  • Fabric and CAPWAP-CONTROL exposure not reviewed
—
—
T6MikroTik RouterOS MikroTrick SSH Takeover (CVE-2026-86060 / CVE-2026-67277)
  • Internet-exposed SSH on RouterOS is not in the external-attack-surface register
  • ops account and -2 SSH artifacts not in the hunt
  • Firmware upgrade treated as proof of cleanliness
  • No rebuild standard for a compromised router
—
—
T7GitLab Unauthenticated Path Traversal (CVE-2026-85706)
  • Self-managed GitLab instances not inventoried as internet-reachable secrets stores
  • file.path commits-API hunting is absent
  • Token and deploy-key rotation not triggered by unauthenticated file-read exposure
  • 10 September builds not verified independently of the vendor release note
—
—
T8ConnectWise ScreenConnect Unauthorized File Execution (CVE-2026-84869)
  • Client version inventory stops at the ScreenConnect server
  • TransferFiles left enabled during the upgrade window
  • Guest-process VBScript execution not in the audit-log hunt
  • On-premises partners below 25.4 have no upgrade path plan
—
—
T9Google Chrome V8 Sandbox-Escape Zero-Day (CVE-2026-87491)
  • Browser fleet compliance measured as update available, not installed and restarted
  • Last week's Chrome 152 build treated as this week's closure
  • BlueMoon cluster indicators not in endpoint detection
  • Chrome 153 rollout not tied to the Windows ALPC update
—
—
T10Windows ALPC and Update Stack Local Privilege Escalation (CVE-2026-85880 / CVE-2026-81963)
  • Patch Tuesday KEVs left on the monthly cycle
  • ALPC update not prioritized on Chrome-running endpoints
  • Update Stack CVE-2026-81963 tracked as a duplicate of ALPC
  • BlueMoon %TEMP% curl loader not in the hunt
—
—
T11JFrog Artifactory Anonymous-Token to Admin Chain (CVE-2026-42018 / CVE-2026-42016)
  • Self-hosted Artifactory omitted from software supply-chain trust inventory
  • Only last week's CVE-2026-82329 patched, leaving the JWT chain open
  • Groovy plugins and minted admin tokens not audited
  • Cluster join keys not rotated after reachable exposure
  • Temporary directories not hunted for the Rust implant
—
—
T12PaperCut NG/MF Auth Bypass to RCE Chain (CVE-2026-81578 / CVE-2026-82078)
  • Print management is absent from the asset and internet-exposure register
  • Application Server web interface reachable from untrusted networks
  • Emergency patch treated as final rather than superseded by the maintenance release
  • PaperCut service account and directory credentials not rotated after exposure
  • Registry-hive and Meterpreter indicators not in the hunt
—
—
T13C-Track Canada Court Records Breach, Ontario Courts (no CVE)
  • Court and legal records held in a vendor platform are not on the third-party register
  • Breach-notification duty is not assigned per processor agreement
  • No contractual notification clock to measure the 23 July notice against
  • Sealed and redacted material carries no handling standard above ordinary personal information
  • Processor incident response is not exercised where the data owner is not the breached party
—

Privacy Act / PIPEDA & OSFI: These rows are vulnerability disclosures and do not independently establish a Canadian privacy breach or a PIPEDA notification obligation. CCCS AV26-888 is a Canadian advisory for Adobe Commerce, not a confirmed PIPEDA incident. Assess any incident evidence against the organization's own data map, regulatory footprint, and contractual notification duties.

Risk Triage

Threats are assigned to primary zones based on their dominant organizational risk characteristic. A threat may appear in a secondary zone when it presents a materially distinct compounding risk dimension.

Exposure Velocity

Active exploitation or weaponized capability with immediate organizational exposure if unaddressed.

  • T1
    Cisco FMC CVE-2026-20079, EPSS 75.75%, KEV deadline passed

    Unauthenticated root on the firewall manager. Apply the matching Cisco hot fix, remove internet exposure of the management plane, and hunt /var/tmp/license.tmp before closing the ticket.

  • T2
    Adobe Commerce CVE-2026-75650, exploited 4 September, hotfix 7 September

    Three days of unauthenticated RCE before VULN-39341. Apply the hotfix, then rotate the encryption key and every credential it protected.

  • T3
    N-central CVE-2026-86218, Hotfix 3 is not this fix

    Pre-auth RCE on the RMM plane. Upgrade on-premises servers to 2026.3.1.14. Last weekend's auth-bypass hotfix does not cover this CVE.

  • T4
    NetScaler CVE-2026-19490, distinct from the 31 August CVE-2026-8452

    Need 14.1-73.32 or 13.1-63.21, not the 31 August builds. Confirm Gateway, AAA, or SAML preconditions per appliance.

  • T6
    MikroTik CVE-2026-86060, 122,500 SSH-exposed devices counted by ShadowServer

    Update to 7.24.2, 7.23.4, 7.25beta3, or 6.49.21 and hunt the ops and -2 artifacts. The vulnerable subset of that 122,500 is not stated.

  • T7
    GitLab CVE-2026-85706, probes one day after disclosure, due 14 September

    Upgrade self-managed CE/EE to 19.1.8, 19.2.6, or 19.3.2 and hunt file.path on the commits API.

  • T12
    PaperCut CVE-2026-81578 / CVE-2026-82078, due 14 September, Canada named in the targeting

    Move to 26.0.5, 25.0.13, or 24.1.10, not an emergency patch. Take the Application Server off the public internet and rotate the service account.

  • T9
    Chrome CVE-2026-87491, BlueMoon sandbox escape, distinct from CVE-2026-85046

    Install 153.0.8010.36/.37 and restart. Last week's 152 build is stage 1 of the same kit, not this closure.

Incident Pressure

Confirmed campaign or large-scale exposure with direct impact on organizations or their data.

  • T5
    FortiOS CVE-2025-25249, PivotC2 RAT, January patch now a KEV

    Upgrade to the FG-IR-25-084 fixed releases and hunt the implant before reboot. FortiOS 6.4 has no on-branch fix.

  • T8
    ScreenConnect CVE-2026-84869, worm-like client propagation

    Upgrade clients to 26.6.5, constrain TransferFiles until then, and hunt guest-process VBScript in session logs.

  • T13
    C-Track Canada, Ontario court records taken in March, disclosed in September

    The only confirmed Canadian-victim incident in the window. Sealed and redacted material is inside the affected set. PIPEDA s.10.1 sits with Thomson Reuters Canada Limited, not with the courts.

  • T11
    Artifactory CVE-2026-42018 / CVE-2026-42016, Rust backdoors

    Wiz saw admin-scoped tokens and Groovy plugins between 15 August and 8 September. Patching last week's CVE-2026-82329 is not this chain.

Governance & Control Gaps

Structural control deficiencies revealed by the week's threats, independent of any single exploit.

  • T10
    Windows CVE-2026-85880 / CVE-2026-81963, local EoP with Exploitation Detected

    ALPC is BlueMoon's kernel stage. Update Stack CVE-2026-81963 is a separate KEV. Neither belongs on the monthly cycle.

  • T3T8
    MSP tooling is customer-estate access

    N-central and ScreenConnect fail as third-party access controls when the on-premises inventory, client version, or TransferFiles permission is not evidenced.

Strategic Posture

Cross-cutting pattern requiring board-level awareness and programme-level response.

  • T9T10T11
    Last week's CVEs are stages of this week's kits

    BlueMoon chains CVE-2026-85046 with CVE-2026-87491 and CVE-2026-85880. Wiz chains CVE-2026-82329 with CVE-2026-42018 and CVE-2026-42016. Direct KEV reconciliation found three Sheet misses.

Remediation Actions

Consolidated actions across all thirteen threats, organized by time horizon. T-badges indicate which threat each action addresses.

0 – 24 hours

Immediate response

  • T1T2T3T4T5T6Confirm the vendor-fixed build on every FMC, Commerce/Magento, N-central, NetScaler, FortiOS/FortiSwitchManager, and RouterOS instance whose KEV deadline has passed.
  • T7T8T12Upgrade GitLab to 19.1.8, 19.2.6, or 19.3.2, ScreenConnect clients to 26.6.5, and PaperCut to 26.0.5, 25.0.13, or 24.1.10. All three clocks are 14 September.
  • T9T10Deploy Chrome 153.0.8010.36/.37 with a restart, and the 8 September Windows updates for CVE-2026-85880 and CVE-2026-81963.

7 days

Short-term hardening

  • T5Hunt PivotC2 on any FortiOS or FortiSwitchManager device that was still on a vulnerable branch, before reboot. Plan the FortiOS 6.4 migration; that branch has no on-branch fix.
  • T11Patch both Artifactory JWT CVEs on the branch in use, then audit Groovy plugins, minted admins, and last week's CVE-2026-82329 state.
  • T1T2T6Run the sourced hunts: license.tmp on FMC, Sansec implant indicators on Commerce, ops and -2 on RouterOS.

14 – 30 days

Programme remediation

  • T1T3T4T6Classify firewall managers, RMM, Gateways, and internet-SSH routers as control-plane assets in the emergency-patch SLA.
  • T9T10T11Tie Chrome 153, Windows ALPC, and Artifactory JWT evidence together so last week's cards cannot close this week's kits.

Ongoing

Structural controls

  • T1T2T3T4T5T6Measure emergency remediation by verified deployed version and investigation evidence, not by the existence of a patch ticket.
  • T7T8T9T10T11Keep direct CISA KEV reconciliation, self-managed GitLab and ScreenConnect inventories, and browser-plus-kernel kit tracking in the recurring control review.
  • T13Put every legal, court, and regulated-records processor on the third-party register with a named breach-notification owner and a contractual notification clock, then test that clock against the 23 July precedent in the C-Track Canada incident.

See how this week's threats map to your control gaps.

Book a briefing →