Cyber Risk Brief: 7 - 13 September 2026
CRB-2514 September 2026Sovereign GRC Intel26 min read
Disclaimer:This brief is governance commentary for leadership and risk teams, not incident notification, public attribution, legal advice, or quantitative risk analysis. Threat prioritization, framework mappings, attribution, and risk-zone groupings are informational only. Validate all technical claims against vendor advisories and internal telemetry before operational response.
Threat Intelligence Summary
Fourteen CISA KEV additions in seven days collapse to eleven register rows, plus PaperCut carrying an older KEV whose clock expires today, and one Canadian incident row that carries no CVE. Cisco FMC CVE-2026-20079 is the highest-EPSS item at 75.75%, confirmed exploited, deadline 12 September, passed. Adobe Commerce CVE-2026-75650, N-central CVE-2026-86218, NetScaler CVE-2026-19490, FortiOS CVE-2025-25249, and MikroTik CVE-2026-86060/67277 also carry passed clocks. GitLab CVE-2026-85706 and ScreenConnect CVE-2026-84869 are due 14 September. Chrome CVE-2026-87491 (due 23 September) and Windows CVE-2026-85880/81963 (due 22 September) are the BlueMoon kit; Artifactory CVE-2026-42018/42016 (due 25 September) is the backdoor chain that continues last week's CVE-2026-82329. Every CVE row is IMMEDIATE. PaperCut CVE-2026-81578/82078 carries the same 14 September clock as GitLab and ScreenConnect, and Arctic Wolf names Canada among the countries its education-sector campaign targeted. The Canadian Centre for Cyber Security issued an Alert or advisory naming the CVE on all eleven, including two Alerts: AL26-019 for NetScaler and AL26-020 for MikroTik RouterOS. T12 is the week's one confirmed Canadian-victim incident, the C-Track Canada court-records breach affecting Ontario's three courts, and it is the only row where PIPEDA applies. Direct KEV reconciliation found three Sheet misses: Artifactory CVE-2026-42016 and CVE-2026-42018, and ScreenConnect CVE-2026-84869.
Threat Register
| Threat | |||||
|---|---|---|---|---|---|
T1 | Cisco Secure FMC Authentication Bypass to Root (CVE-2026-20079) CVE-2026-20079 is a CVSS 3.1 10.0 authentication bypass in Cisco Secure Firewall Management Center. An unauthenticated attacker who sends crafted HTTP requests to the web interface can execute scripts and commands as root. Cisco confirmed in a 9 September advisory update that PSIRT became aware of active exploitation in August. CISA added the CVE to KEV on 9 September with a 12 September deadline, now passed. Its EPSS score of 75.75% is the highest in this register. | Critical | 12 Sep · passed | ||
T2 | Adobe Commerce StyleSmuggler Unauthenticated RCE (CVE-2026-75650) CVE-2026-75650 is a CVSS 3.1 10.0 template-engine injection in Adobe Commerce, Adobe Commerce B2B, and Magento Open Source. Sansec named it StyleSmuggler and reported unauthenticated remote code execution with attacks starting 4 September, three days before Adobe released hotfix VULN-39341 on 7 September. CISA added the CVE to KEV on 8 September with an 11 September deadline, now passed. CCCS advisory AV26-888 states Adobe indicates the CVE is exploited in the wild. | Critical | 11 Sep · passed | ||
T3 | N-able N-central Pre-Authentication RCE (CVE-2026-86218) CVE-2026-86218 is a CVSS 4.0 10.0 static code injection flaw that N-able describes as pre-authenticated remote code execution on the N-central server. N-able released Hotfix 4, build 2026.3.1.14, on 5–6 September. CISA added the CVE to KEV on 8 September with an 11 September deadline, now passed. N-able's public hotfix notes say production exploitation is unconfirmed; CISA's catalog entry is the exploitation authority used here. This CVE is distinct from CVE-2026-18577 and CVE-2026-18556, covered on 10 August. | Critical | 11 Sep · passed | ||
T4Canadian impact: CCCS Alert AL26-019 covers this CVE. An Alert is the Cyber Centre tier above a routine advisory, issued for threats that may impact Canadian cyber information assets. | Citrix NetScaler Authentication Bypass (CVE-2026-19490) CVE-2026-19490 is a CVSS 4.0 9.3 authentication bypass using an alternate path or channel in NetScaler ADC and NetScaler Gateway. Citrix says an unauthenticated attacker can bypass authentication on appliances configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or as an AAA virtual server, with version-specific SAML preconditions. CISA added it to KEV on 9 September with a 12 September deadline, now passed. Singapore CSA states a public proof-of-concept exists and exploitation attempts have been observed. This CVE is distinct from CVE-2026-8452, covered on 31 August. | Critical | 12 Sep · passed | ||
T5 | Fortinet FortiOS Heap Overflow, PivotC2 RAT (CVE-2025-25249) CVE-2025-25249 is a CVSS 3.1 8.1 heap-based buffer overflow in the FortiOS and FortiSwitchManager cw_acd daemon. Fortinet says a remote unauthenticated attacker may execute code or commands via crafted requests. SecurityWeek reports SOCRadar observed exploitation to deploy PivotC2, a Node.js RAT, and CISA added the CVE to KEV on 9 September with a 12 September deadline, now passed. Fortinet patched the issue in January 2026. | Critical | 12 Sep · passed | ||
T6Canadian impact: CCCS Alert AL26-020 covers this CVE. An Alert is the Cyber Centre tier above a routine advisory, issued for threats that may impact Canadian cyber information assets. | MikroTik RouterOS MikroTrick SSH Takeover (CVE-2026-86060 / CVE-2026-67277) CISA added CVE-2026-86060 (CVSS 4.0 9.2) and CVE-2026-67277 (CVSS 4.0 8.8) to KEV on 10 September with a 13 September deadline, now passed. CERT Polska and BleepingComputer report the actively exploited MikroTrick chain is CVE-2026-67276 plus CVE-2026-86060, which together give unauthenticated administrative control of RouterOS devices with SSH on the internet. CVE-2026-67276 is the chain partner; it is not a window KEV addition. CVE-2026-67277 is a separate bandwidth-test memory-disclosure and crash flaw that CISA did list. ShadowServer counted 122,500 MikroTik devices with exposed SSH as of 5 September; the vulnerable subset is not stated. | Critical | 13 Sep · passed | ||
T7 | GitLab Unauthenticated Path Traversal (CVE-2026-85706) CVE-2026-85706 is a CVSS 3.1 10.0 path-traversal flaw in the GitLab repository commits API that lets an unauthenticated user read arbitrary files from the GitLab server. GitLab patched CE and EE in 19.1.8, 19.2.6, and 19.3.2 on 10 September. SecurityWeek reports watchTowr observed in-the-wild probes one day later. CISA added the CVE to KEV on 11 September with a 14 September deadline. This CVE is distinct from CVE-2026-19478, the GraphQL code-injection flaw covered on 24 August, which is not KEV-listed. | Critical | 14 Sep | ||
T8 | ConnectWise ScreenConnect Unauthorized File Execution (CVE-2026-84869) CVE-2026-84869 is a CVSS 3.1 9.9 missing-authorization and improper-privilege-management condition in the ScreenConnect client. ConnectWise says files may be transferred and executed through an active remote session without authorization or host confirmation. Servers are not impacted. The 26.6.5 client patch shipped 8 September. CISA added the CVE to KEV on 11 September with a 14 September deadline. SecurityWeek and Huntress describe worm-like propagation of modified clients that push a four-stage VBScript chain to newly connected hosts. | Critical | 14 Sep | ||
T9 | Google Chrome V8 Sandbox-Escape Zero-Day (CVE-2026-87491) CVE-2026-87491 is a CVSS 3.1 8.8 out-of-bounds write in Chrome's V8 engine. Google says an exploit exists in the wild and shipped the fix in Chrome 153.0.8010.36 (Linux) and 153.0.8010.36/.37 (Windows and macOS). CISA added the CVE to KEV on 9 September with a 23 September deadline. Proofpoint, reported by BleepingComputer on 10 September, identifies this CVE as the V8 sandbox-escape stage of the BlueMoon kit, chained after last week's CVE-2026-85046 and before Windows ALPC CVE-2026-85880. That is distinct from last week's standalone Chrome card. | Critical | 23 Sep | ||
T10 | Windows ALPC and Update Stack Local Privilege Escalation (CVE-2026-85880 / CVE-2026-81963) Microsoft's 8 September updates address two CVSS 3.1 7.8 local elevation-of-privilege flaws that MSRC marks Exploitation Detected. CVE-2026-85880 is a heap-based buffer overflow in Windows ALPC. CVE-2026-81963 is link-following in the Windows Update Stack. CISA added both to KEV on 8 September with a 22 September deadline. Proofpoint identifies CVE-2026-85880 as the kernel stage of BlueMoon and says the LPE DLL compilation timestamp is from 2025. CVE-2026-81963 is a separate Update Stack issue and is not in that chain. | Critical | 22 Sep | ||
T11 | JFrog Artifactory Anonymous-Token to Admin Chain (CVE-2026-42018 / CVE-2026-42016) CVE-2026-42018 is a CVSS 3.1 7.5 improper-authentication flaw that returns an internal anonymous-user JWT to an unauthenticated caller, including when anonymous access is disabled. CVE-2026-42016 is a CVSS 3.1 8.1 incorrect-authorization flaw that lets that token be exchanged for administrator scope. Wiz observed multiple actors chaining the two against self-hosted Artifactory between 15 August and 8 September, then dropping a Rust backdoor. CISA added both to KEV on 11 September with a 25 September deadline. Last week's CVE-2026-82329 remains a separate KEV; Wiz also saw it exploited in this window and it is campaign context, not a second row. | Critical | 25 Sep | ||
T12Canadian impact: Arctic Wolf and GreyNoise name Canada among the countries whose education sector this campaign targeted. The University of Toronto published its own advisory on 1 September. | PaperCut NG/MF Auth Bypass to RCE Chain (CVE-2026-81578 / CVE-2026-82078) CVE-2026-81578 is a CVSS 4.0 8.8 improper-access-control flaw that lets unauthenticated remote requests trigger administrative backend actions before access validation completes. CVE-2026-82078 is a CVSS 4.0 9.4 unsafe dynamic class-loading flaw that executes arbitrary Java bytecode under the PaperCut server process. Chained, they are an unauthenticated full compromise. CISA added both to KEV on 31 August with a 14 September deadline, which is this brief's publication date. PaperCut has since replaced all three Emergency Patch Releases with maintenance releases 26.0.5, 25.0.13, and 24.1.10. | Critical | 14 Sep | ||
T13Canadian victim: records from the Court of Appeal for Ontario, the Ontario Superior Court of Justice, and the Ontario Court of Justice. The only row in this brief where PIPEDA applies. | C-Track Canada Court Records Breach, Ontario Courts (no CVE) C-Track Canada, the court case management platform owned by Thomson Reuters Canada Limited, disclosed that an unauthorized party obtained court files in March 2026. C-Track Canada discovered the activity on 30 June 2026. The Court of Appeal for Ontario, the Ontario Superior Court of Justice, and the Ontario Court of Justice are the affected Canadian court systems. Ontario's three chief justices posted a public statement on 2 September and CBC News reported it on 9 September. No CVE has been assigned and the vendor has not said how access was obtained. | — | — | High | Post-incident |
| Select a row for narrative, affected systems, remediation, and sources. | |||||
Strategic context
Control-plane products dominate the passed-deadline set
- Cisco FMC CVE-2026-20079, N-central CVE-2026-86218, NetScaler CVE-2026-19490, FortiOS CVE-2025-25249, and RouterOS CVE-2026-86060 are all administrative or enforcement planes whose KEV clocks expired on or before 13 September.
- A patch ticket on the box is not the control. The control is evidence that the manager, RMM, gateway, firewall, or router was inventoried, upgraded, and hunted for the implant or account the sources named.
Last week's CVEs reappear as stages of this week's kits
- BlueMoon chains last week's Chrome CVE-2026-85046 with this week's CVE-2026-87491 and Windows ALPC CVE-2026-85880. Wiz chains last week's Artifactory CVE-2026-82329 with CVE-2026-42018 and CVE-2026-42016 and then drops a Rust backdoor.
- Closing last week's card does not close this week's. The reader who shipped Chrome 152 and Artifactory's first KEV still has two remaining stages on each kit.
The Canadian authority tracked every row in this register
- The Cyber Centre issued two Alerts this week, its higher tier above a routine advisory, and both land on threats in this register: AL26-019 for NetScaler CVE-2026-19490 (4 September, updated 9 September) and AL26-020 for MikroTik RouterOS (10 September). It also carried an advisory naming the CVE on every other row.
- An Alert is issued for threats that may impact Canadian cyber information assets, and the Cyber Centre offers direct assistance on its contents. For a Canadian organization the reportable position is not only the CISA KEV clock, it is whether the Cyber Centre's stated actions were performed and evidenced.
Threat Actor Profiling
Talos names UAT-11823 and UAT-12197 against Cisco FMC CVE-2026-20079, and attributes a third cluster, UAT-11988, to Qilin on the related static-credential CVE-2026-20316. Proofpoint and Volexity name JungleBamboo (APT31 / Violet Typhoon), UTA0560, UNK_LateNight, and UNK_DoubleCheck for BlueMoon (Chrome CVE-2026-87491 and Windows CVE-2026-85880). CERT Polska, Huntress, Wiz, and SOCRadar describe unattributed operators on RouterOS, ScreenConnect, Artifactory, and FortiOS. The remaining rows have no named actor. MITRE technique codes are shown as hover-to-define abbreviations.
| Threats | Actor | Sectors | MITRE tradecraft | Kill chain |
|---|---|---|---|---|
| T1 | UAT-11823 (Talos: Sandworm-overlapping APT) and UAT-12197 | Enterprise, Critical Infrastructure, Government | Initial Access → Execution → Persistence → Credential Access | |
| T9T10 | JungleBamboo (APT31 / Violet Typhoon), UTA0560, UNK_LateNight, UNK_DoubleCheck | NGOs, Aerospace, Defense Industrial Base, Manufacturing | Delivery → Exploitation → Privilege Escalation → Actions on Objectives | |
| T11 | Unattributed actors in Wiz telemetry | Software Development, Cloud, Enterprise | Initial Access → Privilege Escalation → Persistence | |
| T5 | Unattributed PivotC2 operators observed by SOCRadar | Enterprise, Network Security | Initial Access → Installation → Command and Control | |
| T6 | Unattributed MikroTrick operators (CERT Polska) | Enterprise Networking, Internet Service | Initial Access → Privilege Escalation → Persistence | |
| T8 | Unattributed ScreenConnect operators observed by Huntress | Managed Services, Enterprise | Initial Access → Execution → Persistence → Lateral Movement | |
| T2T3T4T7 | Unattributed threat actors | E-commerce, Managed Services, Enterprise, Software Development | Initial Access → Execution → Actions on Objectives | |
| T12 | Suspected Russian-speaking actor reported by The Hacker News; activity attributed to 45.142.193[.]132 by GreyNoise, Blackpoint Cyber, and Arctic Wolf | Education, Public Sector | Initial Access → Execution → Credential Access → Discovery | |
| T13 | Unattributed actor in the C-Track Canada incident; the vendor has not stated how access was obtained or who was responsible | Justice, Public Sector, Legal Services | Initial Access → Collection → Exfiltration |
▶Table methodology & sourcing notes
- Qilin (UAT-11988) is sourced to CVE-2026-20316, not to this week's CVE-2026-20079 row. BlueMoon attribution is from Proofpoint and Volexity as reported by BleepingComputer. CVE-2026-81963 is not part of that kit.
Control Deficiency & Framework Mapping
| Threat | Control gaps | ISO 27001 | NIST CSF 2.0 | CIS Controls | Privacy Act / PIPEDA | ITSG-33 | OSFI B-13 | ISO 42001 |
|---|---|---|---|---|---|---|---|---|
T1Cisco Secure FMC Authentication Bypass to Root (CVE-2026-20079) |
| — | — | |||||
T2Adobe Commerce StyleSmuggler Unauthenticated RCE (CVE-2026-75650) |
| — | — | |||||
T3N-able N-central Pre-Authentication RCE (CVE-2026-86218) |
| — | — | |||||
T4Citrix NetScaler Authentication Bypass (CVE-2026-19490) |
| — | — | |||||
T5Fortinet FortiOS Heap Overflow, PivotC2 RAT (CVE-2025-25249) |
| — | — | |||||
T6MikroTik RouterOS MikroTrick SSH Takeover (CVE-2026-86060 / CVE-2026-67277) |
| — | — | |||||
T7GitLab Unauthenticated Path Traversal (CVE-2026-85706) |
| — | — | |||||
T8ConnectWise ScreenConnect Unauthorized File Execution (CVE-2026-84869) |
| — | — | |||||
T9Google Chrome V8 Sandbox-Escape Zero-Day (CVE-2026-87491) |
| — | — | |||||
T10Windows ALPC and Update Stack Local Privilege Escalation (CVE-2026-85880 / CVE-2026-81963) |
| — | — | |||||
T11JFrog Artifactory Anonymous-Token to Admin Chain (CVE-2026-42018 / CVE-2026-42016) |
| — | — | |||||
T12PaperCut NG/MF Auth Bypass to RCE Chain (CVE-2026-81578 / CVE-2026-82078) |
| — | — | |||||
T13C-Track Canada Court Records Breach, Ontario Courts (no CVE) |
| — |
Privacy Act / PIPEDA & OSFI: These rows are vulnerability disclosures and do not independently establish a Canadian privacy breach or a PIPEDA notification obligation. CCCS AV26-888 is a Canadian advisory for Adobe Commerce, not a confirmed PIPEDA incident. Assess any incident evidence against the organization's own data map, regulatory footprint, and contractual notification duties.
Risk Triage
Threats are assigned to primary zones based on their dominant organizational risk characteristic. A threat may appear in a secondary zone when it presents a materially distinct compounding risk dimension.
Active exploitation or weaponized capability with immediate organizational exposure if unaddressed.
- T1Cisco FMC CVE-2026-20079, EPSS 75.75%, KEV deadline passed
Unauthenticated root on the firewall manager. Apply the matching Cisco hot fix, remove internet exposure of the management plane, and hunt /var/tmp/license.tmp before closing the ticket.
- T2Adobe Commerce CVE-2026-75650, exploited 4 September, hotfix 7 September
Three days of unauthenticated RCE before VULN-39341. Apply the hotfix, then rotate the encryption key and every credential it protected.
- T3N-central CVE-2026-86218, Hotfix 3 is not this fix
Pre-auth RCE on the RMM plane. Upgrade on-premises servers to 2026.3.1.14. Last weekend's auth-bypass hotfix does not cover this CVE.
- T4NetScaler CVE-2026-19490, distinct from the 31 August CVE-2026-8452
Need 14.1-73.32 or 13.1-63.21, not the 31 August builds. Confirm Gateway, AAA, or SAML preconditions per appliance.
- T6MikroTik CVE-2026-86060, 122,500 SSH-exposed devices counted by ShadowServer
Update to 7.24.2, 7.23.4, 7.25beta3, or 6.49.21 and hunt the ops and -2 artifacts. The vulnerable subset of that 122,500 is not stated.
- T7GitLab CVE-2026-85706, probes one day after disclosure, due 14 September
Upgrade self-managed CE/EE to 19.1.8, 19.2.6, or 19.3.2 and hunt file.path on the commits API.
- T12PaperCut CVE-2026-81578 / CVE-2026-82078, due 14 September, Canada named in the targeting
Move to 26.0.5, 25.0.13, or 24.1.10, not an emergency patch. Take the Application Server off the public internet and rotate the service account.
- T9Chrome CVE-2026-87491, BlueMoon sandbox escape, distinct from CVE-2026-85046
Install 153.0.8010.36/.37 and restart. Last week's 152 build is stage 1 of the same kit, not this closure.
Confirmed campaign or large-scale exposure with direct impact on organizations or their data.
- T5FortiOS CVE-2025-25249, PivotC2 RAT, January patch now a KEV
Upgrade to the FG-IR-25-084 fixed releases and hunt the implant before reboot. FortiOS 6.4 has no on-branch fix.
- T8ScreenConnect CVE-2026-84869, worm-like client propagation
Upgrade clients to 26.6.5, constrain TransferFiles until then, and hunt guest-process VBScript in session logs.
- T13C-Track Canada, Ontario court records taken in March, disclosed in September
The only confirmed Canadian-victim incident in the window. Sealed and redacted material is inside the affected set. PIPEDA s.10.1 sits with Thomson Reuters Canada Limited, not with the courts.
- T11Artifactory CVE-2026-42018 / CVE-2026-42016, Rust backdoors
Wiz saw admin-scoped tokens and Groovy plugins between 15 August and 8 September. Patching last week's CVE-2026-82329 is not this chain.
Structural control deficiencies revealed by the week's threats, independent of any single exploit.
- T10Windows CVE-2026-85880 / CVE-2026-81963, local EoP with Exploitation Detected
ALPC is BlueMoon's kernel stage. Update Stack CVE-2026-81963 is a separate KEV. Neither belongs on the monthly cycle.
- T3T8MSP tooling is customer-estate access
N-central and ScreenConnect fail as third-party access controls when the on-premises inventory, client version, or TransferFiles permission is not evidenced.
Cross-cutting pattern requiring board-level awareness and programme-level response.
- T9T10T11Last week's CVEs are stages of this week's kits
BlueMoon chains CVE-2026-85046 with CVE-2026-87491 and CVE-2026-85880. Wiz chains CVE-2026-82329 with CVE-2026-42018 and CVE-2026-42016. Direct KEV reconciliation found three Sheet misses.
Remediation Actions
Consolidated actions across all thirteen threats, organized by time horizon. T-badges indicate which threat each action addresses.
0 – 24 hours
Immediate response
- T1T2T3T4T5T6Confirm the vendor-fixed build on every FMC, Commerce/Magento, N-central, NetScaler, FortiOS/FortiSwitchManager, and RouterOS instance whose KEV deadline has passed.
- T7T8T12Upgrade GitLab to 19.1.8, 19.2.6, or 19.3.2, ScreenConnect clients to 26.6.5, and PaperCut to 26.0.5, 25.0.13, or 24.1.10. All three clocks are 14 September.
- T9T10Deploy Chrome 153.0.8010.36/.37 with a restart, and the 8 September Windows updates for CVE-2026-85880 and CVE-2026-81963.
7 days
Short-term hardening
- T5Hunt PivotC2 on any FortiOS or FortiSwitchManager device that was still on a vulnerable branch, before reboot. Plan the FortiOS 6.4 migration; that branch has no on-branch fix.
- T11Patch both Artifactory JWT CVEs on the branch in use, then audit Groovy plugins, minted admins, and last week's CVE-2026-82329 state.
- T1T2T6Run the sourced hunts: license.tmp on FMC, Sansec implant indicators on Commerce, ops and -2 on RouterOS.
14 – 30 days
Programme remediation
- T1T3T4T6Classify firewall managers, RMM, Gateways, and internet-SSH routers as control-plane assets in the emergency-patch SLA.
- T9T10T11Tie Chrome 153, Windows ALPC, and Artifactory JWT evidence together so last week's cards cannot close this week's kits.
Ongoing
Structural controls
- T1T2T3T4T5T6Measure emergency remediation by verified deployed version and investigation evidence, not by the existence of a patch ticket.
- T7T8T9T10T11Keep direct CISA KEV reconciliation, self-managed GitLab and ScreenConnect inventories, and browser-plus-kernel kit tracking in the recurring control review.
- T13Put every legal, court, and regulated-records processor on the third-party register with a named breach-notification owner and a contractual notification clock, then test that clock against the 23 July precedent in the C-Track Canada incident.
Provenance
Intelligence Sources
Cadence
Published weekly. Each issue distills the week's most material threats from primary security reporting and vendor advisories, cross-referenced against authoritative sources (CVE/NVD, CISA KEV, and MITRE ATT&CK) and mapped to the compliance obligations that govern your response. Use Subscribe or Share on any issue to join the distribution list.
See how this week's threats map to your control gaps.
Book a briefing →