Cyber Risk Brief: 14 - 20 September 2026
CRB-2621 September 2026Sovereign GRC Intel20 min read
Disclaimer:This brief is governance commentary for leadership and risk teams, not incident notification, public attribution, legal advice, or quantitative risk analysis. Threat prioritization, framework mappings, attribution, and risk-zone groupings are informational only. Validate all technical claims against vendor advisories and internal telemetry before operational response.
Threat Intelligence Summary
Nine rows for 14 to 20 September. Two Canadian incidents open the register with no patch to apply: account takeover at Telus (T1) and an insider data export at Communauto (T2). Four KEV deadlines have already passed: Cisco Secure Email Gateway and ISE (T3, T4), ScreenConnect (T5), and vCenter (T6), the last two carrying propagation and ransomware evidence. The Linux kernel trio (T8) is due today. T7 Orkes Conductor and T9 Azure AI Foundry close the week on the AI platform layer. Sort by KEV date and exploitation evidence, not CVSS alone. One Canadian story sits outside the register: US identity-verification vendor IDScan.net says customer data, including driver's-licence fields, may have been copied from its cloud from around 1 September. The RCMP is monitoring the FBI-led inquiry as of 15 September, and the Privacy Commissioner said on 18 September that it is engaged with the company. Canadian exposure is unverified, and PIPEDA accountability sits with the organizations that contracted IDScan, not with a patch cycle.
Threat Register
| Threat | |||||
|---|---|---|---|---|---|
T1Canadian victim: Telus consumer telecom subscribers. PIPEDA applies. | Telus Consumer Account Takeover (no CVE) • Unauthorized access to Telus consumer accounts using compromised credentials, February 2025 through June 2026.
• Data accessed: names, account numbers, billing address, phone, email, last four card digits, subscription and payment history.
• Attackers used account data to pitch competitor switches and changed some services without authorization.
• Telus reset credentials, notified Vancouver Police and the Privacy Commissioner; victim count not stated.
• SecurityWeek reported customer notifications on 14 September 2026. Distinct from the March 2026 Telus Digital/ShinyHunters incident. | — | — | High | Post-incident |
T2Canadian victim: Communauto members in Canada (Montreal-based car-share operator). PIPEDA applies. | Communauto Insider Data Export (no CVE) • Communauto disclosed unusual access to member records on the night of 3–4 September 2026.
• An employee used an unauthorized automated script to access and download customer records.
• About 2% of members (a few thousand accounts) may be affected; passwords and payment data were not accessed.
• Exposed fields may include name, address, date of birth, phone, driver's licence details, emergency contacts, and uploaded ID documents or photos.
• Montreal Police notified; search warrant executed. CTV reported the disclosure on 14 September 2026. | — | — | High | Post-incident |
T3 | Cisco Secure Email Gateway RCE (CVE-2026-76461) • CVSS 3.1 9.8 unauthenticated SQL injection in the email parsing of Cisco AsyncOS for Secure Email Gateway; Cisco confirms active exploitation.
• Crafted email sent through the gateway can lead to root command execution on the appliance.
• CISA KEV added 14 September 2026; federal due date 17 September 2026 (passed before this brief publishes).
• Fixed AsyncOS builds: 15.5.5-014 (15.5 and earlier), 16.0.4-302 (16.0), 16.5.0-780 (16.5). No workarounds. Cisco advisory cisco-sa-esa-inj-2bLVGmhX.
• CCCS published AV26-921 on 14 September 2026. | Critical | 17 Sep · passed | ||
T4 | Cisco ISE Authentication Bypass (CVE-2026-76460) • CVSS 3.1 10.0 authentication bypass on a Cisco ISE API endpoint; Cisco PSIRT confirms active exploitation.
• Unauthenticated remote attacker can bypass the web management interface and may obtain root command execution.
• Affects Cisco ISE and ISE-PIC in all configurations. CISA KEV added 16 September 2026; due 19 September 2026 (passed on publication day 21 September).
• Emergency patches: ISE 3.1 P12, 3.2 P11, 3.3 P12, 3.4 P7, 3.5 P4 (per Cisco advisory cisco-sa-ISE-ABP-VNSW7Tn5). | Critical | 19 Sep · passed | ||
T5 | ConnectWise ScreenConnect File Execution (CVE-2026-84869) • CVSS 3.1 9.9 flaw in ScreenConnect allows sending and executing files through an active remote session without authorization.
• In-window development after CRB-25: SecurityWeek reported worm-like exploitation on 14 September 2026 — a modified ScreenConnect instance deploying four VBScript files that establish persistence and propagate to other clients. Huntress dates exploitation to 20 August.
• BleepingComputer reported on 16 September 2026 that over a thousand unpatched instances remain exposed.
• CISA KEV added 11 September 2026, federal due date 14 September 2026 (passed). Fixed in ScreenConnect 26.6.5; ConnectWise published interim mitigations on 7 September. | Critical | 14 Sep · passed | ||
T6 | VMware vCenter Syslog RCE (CVE-2026-59310) • CVSS 3.1 9.8 directory traversal in vCenter Syslog server → unauthenticated arbitrary code execution; Broadcom fixed 29 July 2026 (VMSA-2026-0006).
• CISA KEV since 18 August 2026; federal due 21 August 2026 (passed).
• In-window catalyst: BleepingComputer reported 15 September 2026 that CISA updated KEV to flag ransomware-gang use — new development for this brief week.
• EPSS ~50% on 19 September 2026 per verify-cve.py — the highest on this register by an order of magnitude. | Critical | 21 Aug · passed | ||
T7 | Orkes Conductor Workflow RCE (CVE-2026-58138) • Unauthenticated remote code execution in Orkes Conductor GraalVM workflow evaluators (INLINE, LAMBDA, DO_WHILE, SWITCH tasks). NVD carries CVSS 4.0 9.3 from the CNA; SecurityWeek reports 9.8 on CVSS 3.1. This register uses the NVD primary score.
• Attackers submit malicious JavaScript or Python inline workflow definitions to the workflow API; proof-of-concept code went public in early August and exploitation followed.
• Affects Orkes Conductor 3.21.21 before 3.30.2. Default deployments may expose the workflow API without authentication.
• Fixed in Conductor 3.30.2 (June 2026). Not on CISA KEV as of 19 September 2026. EPSS ~9.3% on 19 September 2026. | Critical | Immediate | ||
T8 | Linux Kernel KEV Trio (CVE-2026-53266 / CVE-2025-39682 / CVE-2025-39964) • CISA added three Linux kernel flaws to KEV on 18 September 2026 with a federal due date of 21 September 2026 (publication day for this brief).
• CVE-2026-53266 (NVD CVSS 3.1 8.8, the highest of the three): out-of-bounds write in the ebtables SNAT ARP rewrite — local privilege escalation or DoS.
• CVE-2025-39682 (NVD CVSS 3.1 7.1): mishandled zero-length records on the TLS receive path — local authenticated memory disclosure or DoS.
• CVE-2025-39964 (NVD CVSS 3.1 5.5): concurrent writes to the same AF_ALG socket — availability impact only; NVD scores no integrity impact.
• All three are local-attacker flaws: none is remotely reachable without a foothold. Secondary reporting has circulated higher scores (9.8 / 8.8 / 7.8); this register uses the NVD primary metrics.
• Red Hat updated advisories on 19 September 2026 to acknowledge active exploitation; chain details are not public. | High | 21 Sep | ||
T9 | Microsoft Azure AI Foundry Privilege Escalation (CVE-2026-85889) • CVSS 3.1 10.0 missing authentication for a critical function in Azure AI Foundry; Microsoft patched the cloud service.
• The Hacker News reported 18 September 2026 that Microsoft stated no customer action is required for the cloud fix.
• Register row is for governance visibility — teams using Azure AI Foundry should confirm tenant exposure and monitor Microsoft security communications.
• Not on CISA KEV as of 19 September 2026. | Critical | 7 days | ||
| Select a row for narrative, affected systems, remediation, and sources. | |||||
Threat Actor Profiling
Canadian rows (T1–T2) are unattributed or insider-led; Cisco and infrastructure rows (T3–T6) follow vendor-confirmed active exploitation; T7–T8 are opportunistic or local-attacker paths per cited reporting; T9 is Microsoft-managed cloud remediation. MITRE technique codes are hover-to-define abbreviations.
| Threats | Actor | Sectors | MITRE tradecraft | Kill chain |
|---|---|---|---|---|
| T1 | Unattributed actors in the Telus incident; Telus has not named a group or confirmed credential source | Telecommunications, Consumer Services | Credential Access → Initial Access → Collection → Impact | |
| T2 | Malicious insider (Communauto employee); Montreal Police investigation, search warrant executed | Mobility, Consumer Services | Initial Access (insider) → Discovery → Collection → Exfiltration | |
| T3T4 | Opportunistic and targeted exploit actors against Cisco SEG and ISE (vendor confirms active exploitation; no named APT) | Cross-sector, Managed Security, Telecommunications | Initial Access → Privilege Escalation → Defense Evasion → Lateral Movement | |
| T6 | Ransomware and extortion affiliates targeting VMware vCenter (CISA campaign flag, September 2026) | Cross-sector, Healthcare, Financial Services | Initial Access → Execution → Impact | |
| T5 | Opportunistic actors exploiting ScreenConnect sessions; worm-like propagation reported | MSP, IT Services, Cross-sector | Initial Access → Execution → Lateral Movement | |
| T7 | Opportunistic actors scanning for internet-exposed Orkes Conductor workflow APIs; Fortinet telemetry recorded ~1,300 attempts on 8–9 September 2026 | Technology, Financial Services, AI / Platform Engineering | Reconnaissance → Initial Access → Execution → Persistence | |
| T8 | Unattributed exploitation of Linux kernel flaws per CISA KEV; local authenticated and local attacker paths per advisory text | Cross-sector, Cloud Infrastructure, Linux Server Estates | Privilege Escalation → Impact | |
| T9 | Not applicable — reported by a security researcher and remediated by Microsoft in the managed service; MSRC states no evidence of exploitation in the wild | Cloud Services, AI / Machine Learning | — (no observed tradecraft; asserting techniques for an unexploited flaw would be speculation) | — |
▶Table methodology & sourcing notes
- T1 uses T1110.004 for credential reuse on the Telus portal; T2 uses insider collection and automated exfiltration tradecraft per Communauto's disclosure.
- T3–T4 group opportunistic exploitation of Cisco mail and NAC appliances; T6 follows CISA ransomware-campaign messaging; T7–T8 are workflow-orchestration and kernel KEV rows without sovereign attribution; T9 has no customer-facing actor per MSRC.
Control Deficiency & Framework Mapping
| Threat | Control gaps | ISO 27001 | NIST CSF 2.0 | CIS Controls | Privacy Act / PIPEDA | ITSG-33 | OSFI B-13 | ISO 42001 |
|---|---|---|---|---|---|---|---|---|
T1Telus Consumer Account Takeover (no CVE) |
| — | ||||||
T2Communauto Insider Data Export (no CVE) |
| — | ||||||
T3Cisco Secure Email Gateway RCE (CVE-2026-76461) |
| — | — | |||||
T4Cisco ISE Authentication Bypass (CVE-2026-76460) |
| — | — | |||||
T5ConnectWise ScreenConnect File Execution (CVE-2026-84869) |
| — | — | |||||
T6VMware vCenter Syslog RCE (CVE-2026-59310) |
| — | — | |||||
T7Orkes Conductor Workflow RCE (CVE-2026-58138) |
| — | ||||||
T8Linux Kernel KEV Trio (CVE-2026-53266 / CVE-2025-39682 / CVE-2025-39964) |
| — | — | |||||
T9Microsoft Azure AI Foundry Privilege Escalation (CVE-2026-85889) |
| — |
Privacy Act / PIPEDA & OSFI: T1 and T2 are Canadian victim rows — PIPEDA s.10.1 and Principle 4.7 sit with Telus and Communauto respectively. The IDScan.net landscape note above is third-party processor exposure under Principle 4.1.3 for any Canadian org that used that vendor for ID verification — not an additional register row. CVE rows (T3–T9) do not by themselves establish a PIPEDA breach for your organization; CCCS AV26-921 covers T3 and AL26-021 covers T4 active exploitation, not confirmed Canadian victim incidents. T9 maps to ISO 42001 A.6.2.6 (operation and monitoring) and A.10.3 (suppliers) for Azure AI Foundry consumers — the obligation is to evidence vendor assurance, not to document a system you do not build. T7 carries A.6.2.6 only where Conductor orchestrates AI agents; a workflow engine that does not is outside an AI management system and should be left unmapped. Federally regulated institutions should map T3–T8 against B-13 patch and access-control evidence on mail gateways, NAC, MSP remote access, virtualization, workflow orchestration, and Linux estates.
Risk Triage
Threats are assigned to primary zones based on their dominant organizational risk characteristic. A threat may appear in a secondary zone when it presents a materially distinct compounding risk dimension.
Active exploitation or weaponized capability with immediate organizational exposure if unaddressed.
- T3T4Cisco SEG and ISE — KEV deadlines passed 17 and 19 September
Root RCE on mail inspection and authentication bypass on network access control. Upgrade and hunt before closing tickets; Cisco documents active exploitation on both.
- T5ScreenConnect worm-like exploitation, reported 14 September
Unauthorized file execution through live MSP sessions. Client and server versions must match vendor-fixed builds; audit TransferFiles permissions.
- T6vCenter CVE-2026-59310 — EPSS ~50%, ransomware-gang flag
Federal KEV due passed in August; in-window catalyst is CISA ransomware-campaign messaging. Forensic triage on any late-patched vCenter.
- T7Orkes Conductor CVE-2026-58138 — workflow API RCE
Unauthenticated inline workflow scripts execute as Conductor. Upgrade to 3.30.2+ and remove internet exposure on the workflow API.
- T8Linux kernel triple KEV — due 21 September
Three actively exploited kernel flaws added 18 September, all requiring local access (NVD 8.8 / 7.1 / 5.5). Apply distro kernel or image updates, starting with hosts that run untrusted local workloads.
Confirmed campaign or large-scale exposure with direct impact on organizations or their data.
- T1Telus consumer accounts, February 2025 to June 2026
Billing data read and some services changed without authorization. Competitor-switch fraud used stolen account context. PIPEDA sits with Telus.
- T2Communauto insider export, ~2% of members
Driver's licence details and ID images downloaded by an employee script. Montreal Police notified; phishing risk persists even without payment data.
Structural control deficiencies revealed by the week's threats, independent of any single exploit.
- T1Customer portals lack step-up controls on account change
Credential reuse on a working login bypasses perimeter defences. Plan-change, port-out, and billing-contact updates need the same rigour as password reset.
- T2Insider automation against member PII is undetected
Legitimate access plus unsanctioned scripts defeats perimeter monitoring. Bulk export alerts and privileged-user behaviour analytics are mandatory for mobility operators.
- T3T4Mail and NAC appliances treated as operational, not tier-0
SEG and ISE failures are trust-anchor failures. Management-plane exposure and missing build-string evidence are governance gaps, not network-team backlog.
- T7T9AI orchestration and cloud AI control planes off the tier-0 inventory
Workflow engines that execute agent code and managed Azure AI services need the same ownership as identity and data platforms.
Cross-cutting pattern requiring board-level awareness and programme-level response.
- T1T2Canadian NO_PATCH week: privacy evidence, not patch tickets
Telus and Communauto put PIPEDA safeguards and breach response in the same briefing as Cisco KEV rows. Boards should ask for subscriber and member notification evidence, not only CVE counts.
- T5T6Management-plane debt compounds across MSP and virtualization
ScreenConnect and vCenter are how operators touch every customer or every VM. Deferred upgrades on those planes are enterprise-wide risk acceptance.
- T7T8T9Late-week KEV and AI-platform rows stress patch breadth
Kernel due dates, workflow RCE, and cloud AI CVEs land in the same board week as Cisco emergencies — capacity planning is part of the risk story.
Remediation Actions
Consolidated actions for all nine threats, organized by time horizon. T-badges indicate which threat each action addresses. Horizons follow the urgency of the action itself, which is why the two NO_PATCH Canadian rows appear in the first column: the action there is customer verification and fraud watch, not a patch.
0 – 24 hours
Immediate response
- T3Upgrade Cisco Secure Email Gateway to AsyncOS 15.5.5-014, 16.0.4-302, or 16.5.0-780 (cisco-sa-esa-inj-2bLVGmhX, CCCS AV26-921); no workarounds exist. Hunt for compromise before closure.
- T4Apply the emergency ISE/ISE-PIC patch for your release train; restrict management access with infrastructure ACLs until verified.
- T5Upgrade ScreenConnect server and clients to 26.6.5 or later; until then apply ConnectWise's interim mitigation and disable TransferFiles permissions.
- T6Upgrade vCenter to a VMSA-2026-0006.2 fixed release and begin forensic triage on any instance patched after the ransomware-campaign flag.
- T7Upgrade Orkes Conductor to 3.30.2 or later; block internet access to workflow API endpoints and hunt for malicious INLINE workflow submissions.
- T8Apply vendor kernel or image updates remediating CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964 before the 21 September KEV due date.
- T1If you received a Telus notification, verify through Telus directly, review bills and plan changes, and enroll in Telus Guardian by 30 November 2026 if offered.
- T2Communauto members who received notice: follow direct instructions, watch for phishing using licence or account details, and report suspicious contact to Communauto and police.
7 days
Short-term hardening
- T3T4Produce build-string and patch evidence for every SEG and ISE node; remove internet exposure on management interfaces.
- T5Audit active ScreenConnect sessions across MSP customer tenants; hunt partner estates for lateral movement if exploitation was possible pre-patch.
- T1Test credential-stuffing detection and rate limits on every customer portal that stores billing or subscription data.
- T2Alert on bulk member-record exports and off-hours scripted queries against customer APIs.
- T7Inventory Conductor and workflow-orchestration deployments; require authentication on workflow APIs in every non-production and production environment.
- T8Reconcile container host and VM image kernel versions against distro security advisories for the triple KEV drop.
- T9Record Microsoft attestation for CVE-2026-85889; confirm whether your Azure AI Foundry subscriptions are in scope and file the MSRC notice in ISO 42001 evidence.
14 – 30 days
Programme remediation
- T1T2Exercise PIPEDA s.10.1 playbooks for subscriber and member incidents, including OPC notification timing and customer outreach templates.
- T4Correlate external firewall and network logs for suspicious transfers involving ISE management IPs; Cisco warns attackers may delete appliance logs.
- T6Isolate vCenter management networks and document immutable restore paths before the next ransomware test.
Ongoing
Structural controls
- T1T2Treat Canadian consumer-account and member-data incidents as standing privacy and fraud programmes, not one-off headlines.
- T3T4T5T6T7T8Tier-0 evidence: mail gateways, NAC, MSP remote access, virtualization, workflow orchestration, and Linux kernel baselines inherit the same board reporting as identity controls.
- T9Include managed cloud AI CVEs in ISO 42001 risk reviews even when the vendor states no customer action is required.
- T1Require step-up authentication before plan changes, port-outs, or payment-method updates on customer portals.
Provenance
Intelligence Sources
Cadence
Published weekly. Each issue distills the week's most material threats from primary security reporting and vendor advisories, cross-referenced against authoritative sources (CVE/NVD, CISA KEV, and MITRE ATT&CK) and mapped to the compliance obligations that govern your response. Use Subscribe or Share on any issue to join the distribution list.
See how this week's threats map to your control gaps.
Book a briefing →