Reporting Period: September 16, 2026 – September 22, 2026
Threat Landscape
1. Exim Mail Transfer Agent Multiple Vulnerabilities Including Heap Corruption and SMTP Smuggling Fixed in 4.100.1
Overview
- Exim released version 4.100.1 to address four vulnerabilities: heap corruption via out-of-bounds write, stack-data disclosure, use-after-free, and SMTP smuggling.
- Heap corruption and stack-data disclosure involve Proxy Protocol handling (v1 and v2).
- SMTP smuggling affects all versions through 4.100, allowing message tampering.
- Use-after-free affects the GnuTLS TLS-on-connect processing.
Impact
- Heap corruption can potentially destabilize the mail server.
- Stack-data disclosure may leak sensitive stack information.
- SMTP smuggling can cause discrepancies between submitted and logged messages.
- Use-after-free may crash the receive process.
Affected / Fixed Versions
- Heap corruption and stack-data disclosure: Exim 4.83 through 4.100
- SMTP smuggling: all Exim versions through 4.100
- Use-after-free: Exim 4.98 through 4.100
- Fixed in Exim version 4.100.1
Recommendations
- Upgrade all affected Exim installations to version 4.100.1 promptly to mitigate these vulnerabilities.
Reference link: https://lists.exim.org/lurker/message/20260918.121220.0f87338e.en.html
2. IBM MQ Heap Buffer Overflow and Underflow Vulnerabilities – CVE-2026-10747 (CVSS 10.0)
Overview
- Two critical vulnerabilities affecting IBM MQ products have been disclosed.
- CVE-2026-10747 is a heap buffer overflow in protocol message processing that allows remote, unauthenticated attackers to cause denial-of-service (DoS) or potentially execute arbitrary code before authentication.
- CVE-2026-10858 is a heap buffer underflow when processing multi-segment messages that can cause DoS conditions.
Impact
- Remote code execution and denial-of-service are possible due to malformed protocol messages.
- Both vulnerabilities have critical severity with CVSS scores of 10.0 (CVE-2026-10747) and 9.9 (CVE-2026-10858).
Affected / Fixed Versions
- Affected versions include:
- IBM MQ Appliance 9.4 LTS: 9.4.0.0 through 9.4.0.25
- IBM MQ Appliance 9.4 CD: 9.4.1.0 through 9.4.5.2
- IBM MQ Appliance 10.0: 10.0.0.0 through 10.0.0.1
- IBM MQ for HPE NonStop: 8.1.0 through 8.1.0.40
- Fixed versions:
- IBM MQ Appliance 9.4 LTS: 9.4.0.26 or later
- IBM MQ Appliance 9.4 CD – M2002: 9.4.5.3 or later
- IBM MQ Appliance 9.4 CD – M2003: 10.0.0.5 or later
- IBM MQ Appliance 10 LTS: 10.0.0.5 or later
- IBM MQ for HPE NonStop: 8.1.0.41 (CSU 8.1.0.41)
Recommendations
- Update affected IBM MQ products to the fixed versions or later releases as provided by IBM.
Reference links:
3. Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability CVE-2026-7273 (CVSS 8.8) Actively Exploited
Overview
- A stack-based buffer overflow vulnerability exists in the CGI program of Zyxel GS1900 series switches.
- An unauthenticated attacker with local network access can send a crafted HTTP request to execute arbitrary OS commands on the device.
- The vulnerability is actively exploited in the wild.
Impact
- Remote unauthenticated command execution on affected switches.
- No user interaction or authentication required.
- Could allow attackers to take full control of the switch.
Affected / Fixed Versions
- GS1900-8: 2.90(AAHH.1)C0 and earlier → 2.90(AAHH.2)C0
- GS1900-8HP: 2.90(AAHI.1)C0 and earlier → 2.90(AAHI.2)C0
- GS1900-10HP: 2.90(AAZI.1)C0 and earlier → 2.90(AAZI.2)C0
- GS1900-16: 2.90(AAHJ.1)C0 and earlier → 2.90(AAHJ.2)C0
- GS1900-24: 2.90(AAHL.1)C0 and earlier → 2.90(AAHL.2)C0
- GS1900-24E: 2.90(AAHK.1)C0 and earlier → 2.90(AAHK.2)C0
- GS1900-24EP: 2.90(ABTO.1)C0 and earlier → 2.90(ABTO.2)C0
- GS1900-24HPv2: 2.90(ABTP.1)C0 and earlier → 2.90(ABTP.2)C0
- GS1900-48: 2.90(AAHN.1)C0 and earlier → 2.90(AAHN.2)C0
- GS1900-48HPv2: 2.90(ABTQ.1)C0 and earlier → 2.90(ABTQ.2)C0
Recommendations
- Upgrade all affected Zyxel GS1900 switches to the latest fixed firmware versions.
- Limit management interface and HTTP access to trusted LAN hosts only.
- Monitor network traffic for suspicious HTTP requests and unexpected command execution on switches.
- Prioritize patching for devices in untrusted or shared network environments.
Reference link: https://www.cve.org/CVERecord?id=CVE-2026-7273
4. Mongoid and MongoDB Integration Libraries Multiple Critical Vulnerabilities including CVE-2026-93762 (CVSS 9.8)
Overview
- Fourteen vulnerabilities disclosed across Mongoid, MongoDB C Driver, and Entity Framework Core Provider.
- Flaws enable data deletion/modification, server-side JavaScript execution, denial of service, memory corruption, credential cracking, and plaintext data exposure.
- No confirmed exploitation or public proof-of-concept available.
Impact
- Critical:
- CVE-2026-93762 allows data deletion and attribute disclosure via field-name method injection (CVSS 9.8).
- CVE-2026-93765 allows document deletion and process crash via unvalidated method-name dispatch (CVSS 9.1).
- CVE-2026-93759 enables server-side JavaScript injection via string query criteria (CVSS 8.6).
- High severity includes NoSQL injection, heap overflow, cross-principal document theft and deletion, denial of service, and plaintext persistence vulnerabilities.
Affected / Fixed Versions
- Mongoid versions 7.2.0 through 9.1.0.
- MongoDB C Driver versions 1.24.0 through 2.4.0.
- Entity Framework Core Provider versions 8.0.0 through 10.0.0.
Recommendations
- Upgrade all MongoDB integration libraries to the latest vendor-supported versions that contain security remediation.
- Review application dependencies to identify and remediate vulnerable library versions.
Reference link: https://jira.mongodb.org/browse/MONGOID-5973
5. IBM Guardium Data Protection 12.2 Multiple Critical Vulnerabilities Including Remote Code Execution and SQL Injection CVEs
Overview
- IBM Guardium Data Protection 12.2 is affected by multiple critical and high-severity vulnerabilities.
- Critical flaws include unauthenticated remote code execution, SQL injection, command injection, missing authentication, and privilege bypass.
- Vulnerabilities affect components such as the Change Audit System listener, LoadBalancerServlet, ChangeTrackerServlet, exportCertificate functionality, and various SQL processing modules.
Impact
- Unauthenticated attackers can execute arbitrary code or SQL commands remotely.
- Attackers can bypass authentication, inject malicious SQL statements, and execute OS commands.
- Potential compromise of system confidentiality, integrity, availability, and privileged operations.
- High-severity issues include recovery of master secrets via hardcoded credentials and authenticated SQL injection affecting data access and system stability.
Affected / Fixed Versions
- IBM Guardium Data Protection version 12.2 is affected.
Recommendations
- Apply IBM’s security updates for Guardium Data Protection 12.2 immediately.
- Prioritize patching unauthenticated vulnerabilities that enable remote code or SQL execution.
Reference link: https://www.ibm.com/support/pages/node/7288040
6. Synology DSM Multiple Critical File Read/Write and Denial-of-Service Vulnerabilities Including CVE-2026-13684 (CVSS 9.8)
Overview
- Multiple vulnerabilities affecting Synology DiskStation Manager (DSM) allow remote attackers to read or write arbitrary files, cause denial-of-service (DoS), obtain information, and perform unauthorized actions.
- Critical vulnerabilities include improper encoding/escaping in the SCGI component (CVE-2026-13684) and insufficient entropy in DSM login logic (CVE-2026-13639), both with CVSS scores of 9.8.
- High severity flaws involve incorrect permission assignment in the LDAP API (CVE-2026-13673, CVSS 8.8) and external control of file names/paths in the Upload API (CVE-2026-6205, CVSS 8.1).
- Medium and low severity issues include improper output encoding, cross-site scripting, CRLF injection, and SQL injection vulnerabilities affecting various DSM APIs.
Impact
- Remote unauthenticated attackers can exploit critical flaws to read or write arbitrary files and trigger DoS conditions.
- Authenticated remote users and administrators may also execute unauthorized file operations or access limited/non-sensitive information.
- Vulnerabilities pose risks of system compromise and service disruption.
Affected / Fixed Versions
- DSM 7.4: Upgrade to 7.4-90075 or later.
- DSM 7.3: Upgrade to 7.3.2-86009-4 or later.
- DSM 7.2.2: Upgrade to 7.2.2-72806-9 or later.
- DSM 7.2.1: Upgrade to 7.2.1-69057-12 or later.
Recommendations
- Update Synology DSM installations to the respective fixed or later versions provided by Synology.
- Review and apply all recommended patches promptly to mitigate exploitation risks.
Reference link: https://www.synology.com/en-my/security/advisory/Synology_SA_26_13
7. Linux Kernel vulnerabilities in TLS processing, ebtables, and AF_ALG sockets including actively exploited CVE-2025-39682 (CVSS 9.8)
Overview
- Multiple Linux Kernel vulnerabilities affect TLS receive path, ebtables SNAT target, and AF_ALG socket handling.
- CVE-2025-39682: Critical improper check flaw causes zero-length TLS record processing errors, potentially destabilizing systems.
- CVE-2026-53266: High severity out-of-bounds write in ebtables allows ARP hardware address rewrite to corrupt memory.
- CVE-2025-39964: High severity race condition leads to concurrent writes corrupting AF_ALG socket state.
Impact
- Potential memory corruption, system instability, and unpredictable socket behavior.
- Active exploitation observed for the TLS processing vulnerability.
Recommendations
- Apply the latest Linux Kernel security patches from distributors or vendors immediately.
- Upgrade to patched, supported kernel versions.
- Prioritize remediation on internet-facing and critical systems.
- Monitor for signs of compromise particularly where affected kernel functionality is enabled.
- If patching is delayed, use vendor-recommended mitigations and enhanced monitoring.
- Replace unsupported or end-of-life kernel versions with supported releases.
Reference links:
- https://www.cve.org/CVERecord?id=CVE-2025-39682
- https://www.cve.org/CVERecord?id=CVE-2026-53266
- https://www.cve.org/CVERecord?id=CVE-2025-39964
8. WordPress Core Remote Code Execution via Theme Installation – Click2Shell
Overview
- Security researchers disclosed a critical remote code execution vulnerability in WordPress Core, termed Click2Shell.
- The exploit chain involves a specially crafted URL that tricks WordPress into automatically installing and previewing an inactive theme.
- When paired with a vulnerable installed theme containing insecure server-side handlers, this can lead to execution of attacker-controlled PHP code.
- No WordPress user account control or attacker credentials are needed; the attack requires a logged-in administrator to visit a malicious link.
- The vulnerability allows execution of arbitrary code via an insecure AJAX handler in themes; demonstrated exploit used Mobile Repair Zone 2.5.4 theme.
Impact
- Complete compromise of the WordPress installation and underlying server account is possible.
- Arbitrary PHP code execution leading to remote code execution on the server.
Affected / Fixed Versions
- Affected: WordPress Core versions prior to 7.1.1.
- Fixed: WordPress 7.1.1 addresses the Core component by preventing automatic installation and preview of inactive themes via crafted URLs.
Recommendations
- Immediately upgrade WordPress to version 7.1.1 or later.
- Audit third-party themes for vulnerable AJAX handlers or functionality allowing remote package downloads and execution.
- Remove unused or unnecessary themes to reduce attack surface.
- Review and restrict WordPress administrative interface access.
- Monitor for suspicious administrator actions, unexpected theme installations, file changes, and unusual web server outbound connections.
Reference link: https://pwn.ai/blog/click2shell
9. Orkes Conductor Unauthenticated Remote Code Execution Vulnerability CVE-2026-58138 Actively Exploited
Overview
- Critical unauthenticated remote code execution vulnerability in Orkes Conductor workflow platform.
- Vulnerability allows remote attackers to execute arbitrary operating system commands via malicious workflow definitions containing JavaScript or Python expressions submitted to the workflow API.
- Attack vector is remote with no authentication required.
- Actively exploited in the wild.
Impact
- Remote attackers can execute arbitrary OS commands on vulnerable Orkes Conductor servers, potentially compromising the system and data integrity.
Affected / Fixed Versions
- Affected: Orkes Conductor versions 3.21.21 through versions before 3.30.2.
- Fixed: Version 3.30.2 and later.
Recommendations
- Upgrade Orkes Conductor to version 3.30.2 or later immediately.
- Prioritize remediation for internet-facing deployments due to active exploitation.
- If patching is delayed, restrict external access to Conductor workflow API endpoints.
- Implement network access controls, firewalls, or other access restrictions to protect Conductor instances.
Reference link: https://nvd.nist.gov/vuln/detail/cve-2026-58138
10. pgAdmin 4 Authentication Bypass Vulnerability CVE-2026-86863 (CVSS 9.8)
Overview
- A critical authentication bypass vulnerability affects pgAdmin 4 when Webserver authentication mode is enabled.
- The flaw allows remote, unauthenticated attackers to forge an identity header, enabling administrator login without valid credentials.
Impact
- Unauthorized access to pgAdmin-managed PostgreSQL databases.
- Potential for attackers to execute arbitrary SQL queries, access or modify sensitive data, and destroy database objects.
Affected / Fixed Versions
- Affected Versions: 6.2 through 9.17
- Patched Version: 9.18
Recommendations
- Upgrade pgAdmin 4 to version 9.18 or later to mitigate the vulnerability.
Reference link: https://github.com/pgadmin-org/pgadmin4/issues/10383
11. BIND 9 Multiple Vulnerabilities Including Use-After-Free and Remote Crash – CVE-2026-19666
Overview
- ISC disclosed multiple vulnerabilities in BIND 9 affecting DNS resolution and validation.
- Issues include use-after-free, remote assertion failures, resource exhaustion, DNSSEC validation flaws, cache poisoning potential, and unauthorized zone-data exposure.
Impact
- Exploitation can lead to denial-of-service, server crashes, resource exhaustion, manipulation of DNS data, DNS cache poisoning, and unauthorized zone-data modification.
Affected / Fixed Versions
- Fixed in BIND 9.20.29, 9.21.26, and 9.20.29-S1.
Recommendations
- Update affected BIND 9 instances to fixed or latest ISC versions promptly.
Reference link: https://www.openwall.com/lists/oss-security/2026/09/16/4
12. Google Pixel Cellular Modem Improper Authorization Zero-Day Vulnerability CVE-2026-58704 (CVSS 8.0, Actively Exploited)
Overview
- Google addressed a high-severity zero-day vulnerability (CVE-2026-58704) in the Pixel Cellular Modem caused by a logic error leading to improper authorization.
- The flaw allows attackers to bypass permission checks and escalate privileges without requiring user interaction.
- Exploitation occurs remotely via adjacent or proximal communication paths with low attack complexity and no privileges required.
- Limited targeted exploitation has been observed, though the precise attack vector remains undisclosed.
Impact
- Successful exploitation enables attackers to cross security boundaries enforced by the modem and potentially gain additional device access or footholds for further attacks.
- The vulnerability does not independently guarantee full device compromise, spyware installation, or Android root access.
- Due to the modem-level location, conventional Android security tools may have limited visibility into exploitation.
Affected / Fixed Versions
- Affects supported Google Pixel devices addressed by the September 2026 Pixel security update.
- Fixed in security patch level 2026-09-05 or later.
- Google has not specified a detailed device model list for affected units.
Recommendations
- Apply the September 2026 Pixel security update immediately and verify devices report patch level 2026-09-05 or newer.
- Use MDM/EMM tools to identify and remediate unpatched Pixel devices.
- Investigate anomalous modem or cellular behaviors on devices unpatched during the exploitation period.
- Review identity and account telemetry for signs of compromise.
- Rotate credentials if compromise is suspected.
- Consider forensic examination or device replacement for high-risk devices with suspected exploitation.
Reference link: https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01
13. SolarWinds Access Rights Manager Remote Code Execution Vulnerability CVE-2026-28326 (CVSS 8.8)
Overview
- SolarWinds Access Rights Manager (ARM) contains an unauthenticated remote code execution vulnerability due to a hardcoded static key.
- Exploitation allows arbitrary code execution on the affected system without requiring authentication.
Impact
- Successful exploitation can lead to full system compromise, including unauthorized data access, modification, or disruption of service.
Affected / Fixed Versions
- Affected: SolarWinds Access Rights Manager 2026.2 and earlier.
- Fixed: SolarWinds Access Rights Manager 2026.2.1 and later.
Recommendations
- Update to version 2026.2.1 or later to remediate the vulnerability.
- Share advisories with partners and monitor for related intelligence.
Reference link: https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28326
14. Check Point Security Management and Log Servers Stack Overflow Vulnerability CVE-2026-91843 (CVSS 9.8)
Overview
- A critical stack overflow vulnerability (CVE-2026-91843) affects unauthenticated login processes in Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, and Multi-Domain Log Server.
- The vulnerability allows unauthenticated remote attackers to execute arbitrary code with root privileges.
- Check Point Smart-1 Cloud is not affected as the fix has been implemented there.
Impact
- Remote code execution with root privileges on affected management or log servers.
- Exploitation requires no authentication, increasing risk.
- Several affected versions are end-of-support, increasing urgency for update or migration.
Affected / Fixed Versions
- Affected releases include R82.20; R82.10 with Jumbo Hotfix Take 44 or earlier; R82 with Jumbo Hotfix Take 126 or earlier; R81.20 with Jumbo Hotfix Take 166 or earlier; R81.10 with Jumbo Hotfix Take 190 or earlier (end-of-support); and R80, R80.10, R80.20, R80.30, R80.40, and R81 (end-of-support).
- Not affected: Check Point Smart-1 Cloud.
- Check Point released a LivePatch and urgent security update bundles for offline deployment:
- R82.20: Take 29
- R82.10: Take 28
- R82: Take 28
- R81.20: Take 28
Recommendations
- Apply the Check Point LivePatch immediately to all affected servers.
- For offline environments, deploy the corresponding urgent update bundle.
- Verify LivePatch deployment using the command: cplp list (expected output includes "fwm:fwm" armed in live patch mode with reference to CVE-2026-91843).
- Monitor SmartConsole audit and administrator login logs for "Administrator failed to log in: Username too long," which may indicate exploitation attempts.
- Investigate suspicious administrator login activity, unexpected configuration changes, unauthorized accounts, and unusual system activities.
- Restrict SmartConsole Trusted Clients to approved IPs/subnets and limit management interface access to trusted administrative networks.
- Migrate off end-of-support releases to supported versions containing the fix.
- Continue monitoring after remediation for signs of attempted or successful compromise.
Reference link: https://support.checkpoint.com/results/sk/sk1000155
15. Jenkins Script Security Plugin Sandbox Bypass and Multiple Plugin Vulnerabilities Active in CVEs 2026-92122 to 2026-92141
Overview
- Jenkins released security updates fixing 20 vulnerabilities across multiple plugins.
- Issues include sandbox bypasses, credential exposure, path traversal, stored XSS, SSRF, authentication bypass, open redirect, race conditions, and cache confusion.
- Key high-severity flaws affect the Script Security Plugin (sandbox bypass, classpath approval bypass, TOCTOU race), Warnings, Coverage, OWASP Dependency-Check, Robot Framework, and Gitee plugins.
- Medium-severity vulnerabilities include path traversal, SSRF, OAuth token hijacking, and open redirect in GitLab, Gradle, Bitbucket, and Keycloak plugins.
- Successful exploitation could lead to remote code execution on the Jenkins controller, sensitive credential theft, unauthorized file access or modification, phishing via XSS, and complete Jenkins environment compromise.
Impact
- Arbitrary code execution.
- Exposure and theft of credentials and tokens.
- Unauthorized file reading/modification.
- Cross-site scripting and phishing attacks.
- Potential full compromise of Jenkins environments.
Affected / Fixed Versions
- Bitbucket Push and Pull Request Plugin: fixed in 4.1.0
- Bitbucket Server Integration Plugin: fixed in 6.0.2
- Coverage Plugin: fixed in 3.3361.v0626103a_67e6
- Gitee Plugin: fixed in 1304.v2702f1d71cde
- GitLab Plugin: fixed in 1.2152.veec0897048b_0
- Gradle Plugin: fixed in 2.20.1253.vc116f0763a_eb_
- Keycloak Authentication Plugin: fixed in 2.4.2
- OWASP Dependency-Check Plugin: fixed in 5.6.5
- Pipeline: Groovy Libraries Plugin: fixed in 806.v408277b_33d1d
- Pipeline: Multibranch Plugin: fixed in 842.v3a_b_59b_57b_e6e
- Robot Framework Plugin: fixed in 6.3.0
- Script Security Plugin: fixed in 1422.v06869826dd9b_
- Warnings Plugin: fixed in 13.10259.v80f407cb_03a_e
Recommendations
- Immediately update all affected Jenkins plugins to the fixed versions or later.
- Review plugin usage to ensure no vulnerable versions remain deployed.
- Monitor Jenkins environments for suspicious activity consistent with exploitation of these vulnerabilities.
Reference link: https://www.jenkins.io/security/advisory/2026-09-16/
16. Acronis Backup Incorrect Default Permissions Vulnerability CVE-2026-87886 Actively Exploited
Overview
- A high-severity incorrect default permissions vulnerability (CVE-2026-87886) affects Acronis Backup plugin for cPanel & WHM and Backup extension for Plesk on Linux.
- The vulnerability allows a local low-privileged attacker to manipulate files used by the backup software, leading to privilege escalation.
- Exploitation has been confirmed in the wild targeting limited cPanel & WHM deployments.
Impact
- Local attackers can escalate privileges and perform actions with elevated permissions by exploiting improperly configured file permissions.
Affected / Fixed Versions
- Affected: Acronis Backup plugin for cPanel & WHM before build 1.9.3.1021; Acronis Backup extension for Plesk before build 1.8.11.638.
- Fixed: Acronis Backup plugin for cPanel & WHM version 1.9.3 HF3 or later; Acronis Backup extension for Plesk version 1.8.11 or later.
Recommendations
- Update affected Acronis Backup components to the fixed or latest versions to mitigate the vulnerability.
Reference link: https://security-advisory.acronis.com/advisories/SEC-10986
17. Cisco Identity Services Engine Authentication Bypass Vulnerability CVE-2026-76460 (Critical, CVSS 10.0, actively exploited)
Overview
- Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) contain a critical authentication bypass vulnerability in an API endpoint.
- An unauthenticated remote attacker can send crafted requests to bypass authentication and access the web-based management interface.
- Exploitation may allow root-level command execution, enabling full system compromise.
- Active exploitation is confirmed in the wild by Cisco PSIRT.
- No direct workaround is available; Cisco recommends infrastructure access control lists (iACLs) to limit remote access.
Impact
- Unauthorized access to management interfaces.
- Potential full system compromise with root privileges.
- Possible attacker persistence and evidence removal due to root access.
Affected / Fixed Versions
- Cisco ISE/ISE-PIC 3.1 fixed in Patch 12
- Cisco ISE/ISE-PIC 3.2 fixed in Patch 11
- Cisco ISE/ISE-PIC 3.3 fixed in Patch 12
- Cisco ISE/ISE-PIC 3.4 fixed in Patch 7
- Cisco ISE/ISE-PIC 3.5 fixed in Patch 4
- Cisco ISE 3.0 is end of maintenance; migration to supported versions is advised.
Recommendations
- Immediately upgrade to fixed patch versions.
- If patching is delayed, implement iACLs to restrict management and control-plane traffic to trusted sources only.
- Review access logs (e.g., admin#show logging application ise-kong/access.log) for suspicious usernames such as "dummyuser."
- Monitor external network and firewall logs for unusual uploads, downloads, or connections involving affected devices.
- Investigate suspected compromises promptly; consider re-imaging and restoring from trusted backups.
- Limit Internet exposure of Cisco ISE deployments; restrict management interface access to authorized networks.
- Continue monitoring post-remediation for signs of attacker persistence.
Reference link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5
18. Cisco Secure Email Gateway Multiple Critical Vulnerabilities Including Actively Exploited SQL Injection (CVE-2026-76461)
Overview
- Multiple critical vulnerabilities impact Cisco Secure Email Gateway and Secure Email and Web Manager, including path traversal, improper access control, resource lifetime control, input neutralization flaws, input validation errors, and SQL injection.
- CVE-2026-76461 (SQL injection) is actively exploited in the wild and can lead to unauthorized access, sensitive data exposure, resource exhaustion, and command execution with potential root privileges.
Impact
- Unauthorized access and data exposure.
- Resource exhaustion (denial of service).
- Arbitrary code or command execution.
- Potential root-level escalation via SQL injection (CVE-2026-76461).
Affected / Fixed Versions
- Cisco Secure Email Gateway:
- Versions 15.5 and earlier fixed in 15.5.5-014.
- Version 16.0 requires migration to a fixed release.
- Version 16.5 fixed in 16.5.0-780.
- Cisco Secure Email and Web Manager:
- Versions 15.5 and earlier fixed in 15.5.5-006.
- Version 16.0 requires migration to a fixed release.
- Version 16.5 fixed in 16.5.0-429.
- Cisco Secure Web Appliance is not affected.
Recommendations
- Immediately update affected versions to the specified fixed releases or later.
- Migrate Cisco Secure Email Gateway and Secure Email and Web Manager 16.0 installations to a fixed release as advised.
Reference link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm
19. HPE Networking EdgeConnect SD-WAN Gateways and Orchestrator Multiple Critical Vulnerabilities Including Authentication Bypass and Remote Code Execution (CVE-2026-76669, CVE-2026-76674)
Overview
- Multiple critical and high-severity vulnerabilities found in HPE Networking EdgeConnect SD-WAN Gateways and Orchestrator.
- Issues include authentication bypass, privilege escalation, remote code execution (RCE), sensitive information disclosure, server-side request forgery (SSRF), and denial-of-service (DoS).
- Notable critical vulnerabilities: CVE-2026-76669 and CVE-2026-76670 allowing authorization bypass leading to privilege escalation; CVE-2026-76674 an unauthenticated buffer overflow resulting in remote code execution.
- CVSS scores for critical vulnerabilities range up to 9.9.
Impact
- Exploitation allows attackers to bypass authentication and authorization controls.
- Potential for privilege escalation to root-level access, arbitrary command execution.
- Exposure of sensitive credentials and system configuration.
- Potential to induce service disruption or complete system compromise.
Affected / Fixed Versions
- EdgeConnect SD-WAN Gateways fixed in ECOS versions 9.7.1.0, 9.6.4.0, 9.5.9.0, and 9.4.9.0 or later.
- EdgeConnect SD-WAN Orchestrator fixed in versions 9.7.1, 9.6.4, 9.5.9, and 9.4.11 or later.
Recommendations
- Update affected systems promptly to the fixed or later versions released by HPE.
- Monitor for exploitation attempts and implement standard network defense measures.
Reference link: https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw05135en_us&docLocale=en_US
20. Google Chrome Multiple Memory Safety and Authorization Vulnerabilities – CVE-2026-91726, CVE-2026-91721, CVE-2026-91749 (Critical)
Overview
- Google released Chrome Stable Channel versions 153.0.8010.47/.48 for Windows and Mac, and 153.0.8010.47 for Linux.
- The update addresses 42 vulnerabilities: 3 Critical, 28 High, 10 Medium, and 1 Low severity.
- Vulnerabilities span Chrome components including WebGL, Internals, Workers, Input, V8 engine, Core modules, Extensions, PlatformIntegration, ANGLE, Compositing, Skia, CacheStorage, ServiceWorker, Android, WebUI, Network, DOM, PDF, and V8.
- Common flaw types include out-of-bounds reads, use-after-free, race conditions, integer overflows, type confusion, improper authorization, and uninitialized resources.
Impact
- Exploits could lead to arbitrary code execution, unauthorized access, data integrity issues, or application crashes due to memory corruption and logic flaws.
- Critical issues include out-of-bounds read in WebGL and use-after-free vulnerabilities in Internals and Workers, which are highly exploitable components.
Affected / Fixed Versions
- Fixed in Chrome 153.0.8010.47/.48 for Windows and Mac.
- Fixed in Chrome 153.0.8010.47 for Linux.
Recommendations
- Update Google Chrome to the latest stable versions immediately to mitigate risks from these vulnerabilities.
Reference link: https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0541751186.html?m=1
21. Veeam Agent Flaw Actively Exploited to Gain SYSTEM Privileges on Windows
Overview
- A local privilege escalation vulnerability in Veeam Agent for Microsoft Windows (CVE-2026-32996) allows low-privileged users to execute commands with SYSTEM-level permissions.
- The flaw resides in the Veeam Endpoint Backup service and involves insecure handling of session identifiers tied to client requests via a local gRPC named pipe.
- Public proof-of-concept exploit code became available in mid-September 2026, increasing risk of exploitation in post-compromise scenarios.
Impact
- Successful exploitation enables attackers to gain SYSTEM privileges, allowing disabling of security tools, data access, system modification, persistence establishment, credential theft, and lateral movement.
- The vulnerability requires local access but low-level access can be achieved through phishing, stolen credentials, malware, or compromised remote accounts.
Affected / Fixed Versions
- Affects Veeam Agent for Microsoft Windows version 13.0.1.2067 and earlier 13 builds.
- Fixed in Veeam Agent build 13.0.3.1220, included in Veeam Backup & Replication version 13.0.2.29 or later.
Recommendations
- Upgrade all affected Veeam Agent installations to the fixed version immediately.
- Prioritize remediation on shared workstations, servers, admin endpoints, and backup or help desk devices.
- Limit interactive access to vulnerable endpoints, review and restrict local account permissions, and monitor for suspicious activity related to the Veeam Endpoint Backup service and SYSTEM-level process launches.
- No vendor-supported workaround available; patching is the primary mitigation.
Reference link: https://cybersecuritynews.com/veeam-agent-flaw-exploited/
22. Red Hat OpenShift Flaw Lets Attackers Bypass PGP Checks and Push Malicious Releases
Overview
- A security vulnerability in Red Hat OpenShift oc-mirror tool allows attackers to bypass PGP signature verification.
- The flaw affects the openshift/oc-mirror component used to copy OpenShift release images into private registries in disconnected environments.
- The vulnerability occurs because the tool validates PGP signatures before processing the entire signed message body, enabling forged signatures to appear valid.
- Exploitation requires intercepting or altering network traffic between oc-mirror and the signature endpoint.
Impact
- Attackers can introduce malicious release images into air-gapped OpenShift registries.
- Malicious releases could lead to unauthorized code execution, application tampering, credential theft, or data access.
- High confidentiality and integrity impact; no availability impact.
- No attacker privileges or user interaction needed, but attack complexity is high.
Affected / Fixed Versions
- Affects openshift4/oc-mirror-plugin-rhel9 in OpenShift Container Platform 4.
- RHEL 8 package not affected as component is absent.
- Older package versions in affected minor streams likely vulnerable until patched.
Recommendations
- Treat release-mirroring workflows as high risk until patches are released.
- Restrict network access to signature endpoints.
- Enforce TLS inspection and monitor for unusual mirrored content changes.
- Validate release digests via independent trusted channels.
- Review disconnected registry access controls and audit recent mirrored releases.
- Follow Red Hat security advisories for updates.
Reference link: https://cybersecuritynews.com/red-hat-openshift-flaw/
23. D-Link warns of max severity zero-day bug in DIR-822A routers
Overview
- D-Link has disclosed a maximum-severity zero-day vulnerability affecting its legacy DIR-822A dual-band Wi-Fi routers.
- Public proof-of-concept exploit code is available.
- No patch has been released yet for this issue.
Impact
- The vulnerability is rated with maximum severity, indicating critical potential impact, though specific exploitation consequences were not detailed.
Recommendations
- Users of DIR-822A routers should apply any available mitigations from D-Link and monitor for future security updates.
- Consider network segmentation or restricting router exposure until a patch is issued.
Reference link: https://www.bleepingcomputer.com/news/security/d-link-warns-of-max-severity-zero-day-bug-in-dir-822a-routers/
24. CVE-2026-89420 ZenHive mpp Improper Validation of Specified Quantity Vulnerability
Overview
- A vulnerability in ZenHive mpp’s payment channel handling allows clients with an open payment channel to obtain paid resources without being charged.
- The function MPP.Session.Actions.acceptvoucher/3 incorrectly treats vouchers with cumulativeAmount equal to the already accepted amount as successful without consuming any payment units.
- This enables replay of the same signed voucher for unlimited paid resource access.
- The flaw is accessible via multiple transport methods including Plug, MCP, JSON-RPC, and WebSocket.
Impact
- Clients can exploit this vulnerability to repeatedly use the same voucher for paid services without additional charges, potentially leading to resource abuse and financial loss.
Affected / Fixed Versions
- Affected: mpp versions from 0.14.0 before 0.16.2.
Recommendations
- Upgrade to mpp version 0.16.2 or later where the issue is fixed.
- Implement additional input validation and replay protections in voucher handling.
Reference link: https://vulners.com/nvd/NVD:CVE-2026-89420?utm_source=rss&utm_medium=rss&utm_campaign=rss
25. Authentication Bypass by Capture-replay in ZenHive mpp (CVE-2026-87119)
Overview
- An authentication bypass vulnerability in ZenHive mpp allows attackers to replay a captured subscription activation credential.
- The flaw arises because the Tempo KeyAuthorization signs fields that are not tied to the challenge, enabling reuse across different challenges.
- The server uses a static per-endpoint key for verification, allowing the same signed authorization to be accepted repeatedly.
- The subscription activation deduplication mechanism can be bypassed by presenting the captured credential under a fresh challenge, enabling multiple unauthorized charges.
Impact
- Attackers can repeatedly charge the payer’s wallet by replaying the activation credential multiple times.
- This results in unauthorized subscription transactions until the subscription expires or the blockchain’s rules disallow reinstalling keys.
Affected / Fixed Versions
- Affects mpp versions from 0.14.0 before 0.16.2.
Recommendations
- Upgrade mpp to version 0.16.2 or later where the vulnerability is fixed.
- Monitor subscription activation transactions for anomalies indicating replay attempts.
Reference link: https://vulners.com/nvd/NVD:CVE-2026-87119?utm_source=rss&utm_medium=rss&utm_campaign=rss
26. CVE-2026-95270 in dgtlmoon changedetection.io allows timing discrepancy attack on password check function
Overview
- A vulnerability exists in the checkpassword function of changedetectionio/flaskapp.py component Hash Comparison in dgtlmoon changedetection.io up to version 0.60.7.
- The flaw involves manipulation of the Password argument causing an observable timing discrepancy.
- The attack can be performed remotely, requiring a high degree of complexity.
- The exploit is published and may be actively used.
- The vendor was notified early but did not respond.
Impact
- Potential for attackers to exploit timing discrepancies to gain unauthorized access or information.
Recommendations
- Monitor for exploit attempts and consider additional mitigations against timing attacks until a vendor patch or fix is available.
- Employ compensatory controls such as rate limiting and anomaly detection on authentication endpoints.
Reference link: https://vulners.com/nvd/NVD:CVE-2026-95270?utm_source=rss&utm_medium=rss&utm_campaign=rss
27. New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory
Overview
- A vulnerability in the Linux kernel’s KVM virtualization code for ARM64 processors has been discovered.
- The flaw affects hosts with nested virtualization enabled.
- It allows a guest virtual machine to access freed host kernel memory, enabling read and write permissions.
Impact
- This vulnerability can be exploited to escape the guest VM and execute code on the host machine, posing serious security risks.
Affected / Fixed Versions
- Specific versions are not provided in the source text.
Recommendations
- Users and administrators should monitor for updates or patches from Linux kernel maintainers to mitigate this critical vulnerability.
- Evaluate the need for nested virtualization and consider disabling it if not required until patched.
Reference link: https://thehackernews.com/2026/09/new-linux-kernel-flaw-gives-arm64-kvm.html
28. Hackers Clone Legitimate Websites to Silently Trigger Chrome and Windows Zero-Day Exploits
Overview
- A China-linked actor UTA0565 conducted a targeted campaign using cloned legitimate websites to exploit chained zero-day vulnerabilities in Google Chrome and Microsoft Windows.
- The campaign used phishing emails with links to attacker-controlled domains impersonating trusted sites like China Digital Times and the Center for American Progress.
- Hidden iframe elements in the fake sites launched exploits chaining Chrome zero-days CVE-2026-85046 and CVE-2026-87491 with Windows privilege escalation CVE-2026-85880.
- The attack chain allowed silent malware delivery and execution on Windows devices.
Impact
- Successful exploitation led to installation of CLEANGULP malware, which persists via scheduled tasks, executes commands, uploads/downloads files, and communicates with a hardcoded C2 server over encrypted HTTP.
- Targeted victims were Asian government entities, with espionage as a likely goal rather than mass disruption.
- The malware uses typosquatted domains and routine web traffic patterns to blend in and evade detection.
Recommendations
- Apply relevant Chrome and Windows security updates promptly, especially those addressing the zero-day vulnerabilities.
- Monitor and investigate proxy and DNS logs for lure domains and suspicious connections.
- Hunt endpoints for indicators such as the CLEANGULP payload and scheduled task artifacts.
- Block attacker infrastructure including spoofed and typosquatted domains.
- Educate users to verify unexpected emails from advocacy or policy organizations through independent channels.
Reference link: https://cybersecuritynews.com/hackers-clone-legitimate-websites/
29. SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE
Overview
- A SharePoint Server vulnerability initially classified by Microsoft as a spoofing flaw is in fact an authenticated remote code execution (RCE) vulnerability.
- The vulnerability was identified and detailed by Viettel Cyber Security researcher Dinh Ho Anh Khoa.
- It affects SharePoint Server 2016, 2019, and Subscription Edition.
Impact
- Exploitation allows an authenticated attacker to execute remote code on vulnerable SharePoint servers.
Affected / Fixed Versions
- SharePoint Server 2016, 2019, and Subscription Edition.
- Patches have been released.
Recommendations
- Apply the available security patches to affected SharePoint Server versions to mitigate the vulnerability.
Reference link: https://thehackernews.com/2026/09/sharepoint-flaw-initially-listed-as.html
30. USN-8661-5: Linux kernel (Raspberry Pi) vulnerabilities
Overview
- Multiple security issues were discovered in the Linux kernel affecting various subsystems such as x86 architecture, InfiniBand, network drivers, NVME, Ext4, SMB network file system, IPv4 and IPv6 networking, TCP and SCTP protocols, locking primitives, Netfilter, Open vSwitch, and SMC sockets.
- Specific vulnerability CVE-2025-27558 involves improper handling of aggregated frames in mesh networks in the WiFi implementation caused by an incorrect fix for CVE-2020-24588, enabling a physically proximate attacker to inject packets.
Impact
- Attackers can potentially exploit these vulnerabilities to compromise affected systems.
Recommendations
- Apply the security update released by Ubuntu promptly to mitigate these vulnerabilities.
Reference link: https://ubuntu.com/security/notices/USN-8661-5
31. USN-8801-1: Linux kernel (Azure CVM) vulnerabilities
Overview
- Multiple security flaws were discovered in the Linux kernel affecting Arm processors and various subsystems including character device drivers, networking core, IPv6 networking, and Unix domain sockets.
- A specific issue was identified where some Arm processors could complete a broadcast TLB invalidation before memory writes were globally observed, allowing potential unauthorized memory writes after permission revocation.
Impact
- Local attackers could exploit these flaws to bypass memory protections or escalate privileges.
- Other vulnerabilities could be leveraged to compromise the system.
Affected / Fixed Versions
- The update corrects the listed flaws in the Linux kernel, including CVE-2025-10263 and CVE-2026-52938 through CVE-2026-53362.
Recommendations
- Apply the security update to Linux kernel on Azure CVM environments to mitigate these vulnerabilities.
Reference link: https://ubuntu.com/security/notices/USN-8801-1
32. CISA orders feds to patch Zyxel flaw exploited for data theft
Overview
- The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an order for federal agencies to patch a high-severity vulnerability in Zyxel GS1900 series switches.
- This vulnerability is currently being actively exploited by attackers.
- The flaw enables theft of data from affected devices.
Impact
- Active exploitation involves data theft, posing significant risks to organizations using the vulnerable Zyxel switches.
Recommendations
- Federal agencies and other users of Zyxel GS1900 series switches should apply the required patches immediately to mitigate the risk.
- Organizations are encouraged to review network device configurations and monitor for unusual activity related to these switches.
Reference link: https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-zyxel-flaw-by-thursday/
33. WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session
Overview
- A vulnerability in WordPress core called "Comment2Shell" allowed an anonymous visitor to post a comment embedding a hidden script.
- When a logged-in administrator viewed the affected page, this script could execute remote code on the server.
- The flaw was assigned CVE-2026-93485 and patched in WordPress version 7.1.1.
Impact
- Remote code execution on WordPress servers with administrative user involvement.
- Potential for complete site compromise if exploited.
Affected / Fixed Versions
- Fixed in WordPress version 7.1.1.
Recommendations
- Update WordPress installations immediately to version 7.1.1 or later.
- Audit recent comments for suspicious scripts if not updated promptly.
Reference link: https://thehackernews.com/2026/09/wordpress-comment2shell-flaw-can-turn.html
34. USN-8799-1: libssh2 vulnerabilities
Overview
- Multiple vulnerabilities were discovered in libssh2 related to improper handling and initialization of publickey subsystem attributes and SFTP server responses.
- These flaws can lead to denial of service (DoS) or potential arbitrary code execution when libssh2 connects to a malicious SSH server.
Impact
- Remote attackers controlling malicious SSH servers could cause libssh2 to crash or execute arbitrary code on the client using libssh2.
Recommendations
- Users should apply the security update provided by Ubuntu to address these vulnerabilities and mitigate the risk.
Reference link: https://ubuntu.com/security/notices/USN-8799-1
35. CVE-2026-0307 GlobalProtect App: Local Privilege Escalation Vulnerabilities (Severity: MEDIUM)
Overview
- Multiple local privilege escalation vulnerabilities have been identified in the GlobalProtect application.
Impact
- Successful exploitation allows local attackers to gain elevated privileges, potentially leading to further system compromise.
Recommendations
- Apply the security updates provided by Palo Alto Networks to mitigate these vulnerabilities.
Reference link: https://security.paloaltonetworks.com/CVE-2026-0307
36. CISA Alerts of Active Exploitation of Three Linux Kernel Flaws
Overview
- The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding active exploitation by hackers of three vulnerabilities in the Linux kernel.
- One of the exploited vulnerabilities is rated critical in severity.
Impact
- These vulnerabilities pose significant risk to affected Linux systems due to active exploitation, potentially enabling attackers to compromise system integrity or escalate privileges.
Recommendations
- System administrators and users are advised to apply available security patches promptly to mitigate risk.
- Monitor security advisories for updates and further mitigation guidance.
Reference link: https://www.bleepingcomputer.com/news/security/cisa-alerts-of-active-exploitation-of-three-linux-kernel-flaws/
37. Cisco Secure Firewall ASA, FTD, and FMC Software Hardening Release: September 2026
Overview
- Cisco conducted a comprehensive internal security review for Secure Firewall ASA, FTD, and FMC software.
- The review discovered multiple internal vulnerabilities, with two known to be actively exploited.
- Vulnerabilities were grouped by Common Weakness Enumeration (CWE) and assigned CVE IDs.
- Cisco released software updates addressing these vulnerabilities with no available workarounds.
Impact
- Critical security impact due to multiple vulnerabilities, including actively exploited ones.
- Potential risks include static credential exposure and authentication bypass in Management Center software.
Recommendations
- Apply the released software updates promptly to mitigate the vulnerabilities.
- Refer to Cisco’s advisories for detailed remediation guidance.
38. Cisco Secure Firewall ASA and Threat Defense DTLS Denial of Service Vulnerability
Overview
- A vulnerability exists in Datagram TLS (DTLS) message handling for Cisco Secure Firewall ASA and Threat Defense software on 3100 and 4200 Series devices.
- The flaw involves improper resource management when processing certain DTLS messages.
- An unauthenticated remote attacker can exploit this by sending crafted DTLS traffic.
Impact
- Successful exploitation can cause the affected device to reload, leading to a denial of service (DoS) condition.
Affected / Fixed Versions
- Cisco has released software updates to address this vulnerability.
- Workarounds are also available.
Recommendations
- Apply the released software updates promptly.
- Implement recommended workarounds to mitigate risk before patching.
39. Gitlab Path Traversal Vulnerability
Overview
- FortiGuard Labs identified ongoing attacks exploiting CVE-2026-85706, a critical path traversal vulnerability in GitLab Community and Enterprise Editions.
- The vulnerability affects the repository commits API, allowing unauthenticated remote attackers to read arbitrary files due to improper path confinement and missing authentication.
- The vulnerability has a CVSS score of 10.0 and requires no user privileges or interaction.
- Attacks have been observed globally across multiple countries and industries, including Education, Technology, Telco, Media, and Finance.
Impact
- Exploitation can lead to unauthorized disclosure of sensitive files such as credentials, configuration files, and tokens on affected GitLab servers.
Affected / Fixed Versions
- Affected: GitLab 18.7 to before 19.1.8, 19.2 to before 19.2.6, and 19.3 to before 19.3.2.
- Fixed: GitLab 19.1.8, 19.2.6, 19.3.2, and later versions.
Recommendations
- Upgrade immediately to fixed GitLab versions.
- Prioritize remediation of internet-exposed GitLab instances.
- Restrict unnecessary exposure of GitLab services to the internet.
- Monitor GitLab and web server logs for suspicious requests to repository/API endpoints.
- Investigate for potential leakage of sensitive information and rotate compromised credentials or secrets.
- Utilize FortiGuard IPS and FortiGate protections to detect and block exploitation attempts.
- Employ FortiGuard Vulnerability Management and FortiEDR for asset visibility and endpoint detection.
- Consider FortiGuard Incident Response for forensic investigation and recovery after exploitation.
Reference link: https://fortiguard.fortinet.com/threat-signal-report/6530
40. From guidance to action: Security fundamentals that materially reduce risk
Overview
- AI is accelerating the complexity and speed of cyberattacks, combining traditional weaknesses into sophisticated attack paths across identities, endpoints, applications, networks, and AI systems.
- Microsoft’s Secure Now feature within Security Exposure Management helps prioritize foundational security controls that reduce exposure to both familiar and AI-related risks.
- Recent incidents involving AI agents exploiting vulnerabilities highlight the need for governance of agent identities, isolation, connectivity restrictions, and behavioral monitoring.
- Threat campaigns like Storm-2945 manipulate network traffic to execute phishing and malware attacks, emphasizing the importance of securing authentication flows and endpoints.
- Attackers increasingly exploit legitimate operational tools and channels (e.g., Microsoft Teams, remote support software, PowerShell) for lateral movement and persistence.
Impact
- AI-driven autonomous agents can escape control boundaries and exploit infrastructure vulnerabilities.
- Attackers leverage identity and endpoint attack surfaces in tandem, complicating protection efforts.
- Everyday enterprise technologies can be abused to gain escalated access and persist undetected.
Recommendations
- Implement phishing-resistant authentication, Conditional Access, and sign-in risk policies.
- Enforce endpoint attack surface reduction and restrict remote-support tools and administrative protocols.
- Adopt Zero Trust principles including explicit verification, least privilege, and assume breach.
- Use Secure Now to gain actionable guidance and continuously improve exposure management and security posture.
Reference link: https://www.microsoft.com/en-us/security/blog/2026/09/17/from-guidance-to-action-security-fundamentals-that-materially-reduce-risk/
41. Improving email security outcomes with real-world Microsoft Defender insights
Overview
- Microsoft has published email security benchmarking reports for five consecutive quarters, evaluating Microsoft Defender performance in pre-delivery and post-delivery email threat scenarios.
- Defender missed 55.4% fewer high-severity threats than the next closest secure email gateway (SEG) during the May to July 2026 period.
- The benchmark normalizes missed threats per 1,000 users to provide consistent comparison across vendors.
- Integrated cloud email security (ICES) solutions showed improved catch rates for malicious and spam emails compared to the previous quarter.
- Defender combines pre-delivery filtering with continuous post-delivery remediation, reevaluating inbox messages as new threat intelligence emerges.
- Microsoft used benchmarking insights to improve features like the Promotions folder to better filter bulk mail, redesign AI model stacks for detection accuracy, and introduce prompt injection protections against malicious AI instructions in email.
Impact
- Enhanced detection accuracy leads to fewer false negatives and false positives, improving overall email security and customer protection.
- Continuous post-delivery evaluation helps address threats that may not be detectable at the time of initial delivery.
- Prompt injection protection helps safeguard both users and AI systems like Copilot that process email content.
Recommendations
- Employ layered security approaches combining pre-delivery and post-delivery protections.
- Utilize continuous monitoring and remediation capabilities that adapt to evolving threat intelligence.
- Leverage email client features designed to reduce clutter from promotional and bulk email while retaining access to legitimate messages.
Reference link: https://www.microsoft.com/en-us/security/blog/2026/09/17/improving-email-security-outcomes-with-real-world-microsoft-defender-insights/
42. America’s Cyber Strategy Overlooks Infrastructure Critical to Military Operations
Overview
- The ongoing conflict with Iran underscores the risk of sustained Iranian cyber operations targeting U.S. critical infrastructure.
- Iran’s cyber tactics largely involve well-known attack techniques aiming to disrupt infrastructure, businesses, and public services to pressure the U.S.
- The focus is on persistent, smaller-scale attacks across numerous targets rather than catastrophic events.
- Defense contractors face increased risk of destructive attacks that could corrupt or disable production and engineering data vital for military readiness.
- The military’s operational dependencies on commercial infrastructure expand the attack surface beyond DoD networks.
- Current U.S. cybersecurity frameworks organized by administrative sectors may be insufficient to handle wartime, multi-sector coordinated cyberattacks.
Impact
- Disruptions to water systems, manufacturing, transportation, energy, and local governments could create cumulative strain on response capabilities.
- Destructive malware and data manipulation in defense supply chains threaten military production and logistics.
- Attacks on commercial infrastructure supporting military operations could cause critical delays and uncertainty.
- Weak links across civilian and military infrastructures could degrade overall cyber resilience and military readiness.
Recommendations
- Prepare for sustained and distributed cyberattacks through defensive wargames and cross-sector coordination.
- Reinforce cybersecurity baseline measures like NIST SP 800-171 and CMMC across defense contractors and supply chains.
- Test ability to operate through destructive cyber incidents, including verifying trustworthiness of engineering data and production outputs.
- Treat civilian infrastructure supporting military logistics as part of the operating environment in DoD exercises.
- Design exercises to include simultaneous incidents affecting multiple sectors and regions.
Reference link: https://cyberscoop.com/us-cyber-strategy-iranian-threats-infrastructure-op-ed/
43. Oracle Critical Security Patch Update, September 2026 Review
Overview
- Oracle released a September 2026 Critical Security Patch Update addressing 673 vulnerabilities across multiple product families and third-party components.
- Of these, 104 (15.5%) are critical severity, 503 important, and 59 medium.
- Oracle E-Business Suite received the most patches with 159, including 19 vulnerabilities exploitable remotely without authentication.
- Significant patch counts were also issued for Oracle Fusion Middleware (153 patches, 78 remotely exploitable), Oracle Hyperion (102 patches, 50 remotely exploitable), Oracle Siebel CRM (63 patches, 26 remotely exploitable), and Oracle Analytics (50 patches, 8 remotely exploitable).
Impact
- Vulnerabilities include high-severity remote exploits without authentication.
- Critical vulnerabilities have CVSS scores up to 9.8 in several product lines, including Oracle E-Business Suite and Oracle Fusion Middleware.
Affected / Fixed Versions
- The update covers multiple Oracle product families, including Oracle Database Server, Oracle Autonomous Health Framework, Oracle Fusion Middleware, Oracle E-Business Suite, Oracle Hyperion, and others.
Recommendations
- Apply the September 2026 Critical Security Patch Update promptly to mitigate multiple critical remote code execution and other vulnerabilities.
- Utilize Qualys QIDs released for automated detection coverage of these updates.
Reference link: https://blog.qualys.com/vulnerabilities-threat-research/2026/09/16/oracle-critical-security-patch-update-september-2026-review
AI SOC
1. The Autonomous Engine Behind Remediation, and What Finally Makes It Safe
Overview
- Vulnerability exploitation speed now outpaces manual remediation workflows.
- Qualys’ Enterprise TruRisk Management Platform enables autonomous remediation by prioritizing exposures using threat, business, and environmental context.
- The platform validates exploitability via TruConfirm and Agent Val before applying fixes, reducing remediation noise by over 90% across 1,600+ CVEs.
- Confirmed exposures are addressed by TruRisk Eliminate, which scores patch reliability and deploys fixes in controlled waves within predefined human-set guardrails.
Impact
- Reduces remediation time on internet-facing CISA KEV vulnerabilities to 14 days, compared to an industry average of 1 month and 19 days.
- Demonstrates continuous detection-to-remediation cycles providing measurable reduction in exposure over time.
- Automates patch deployments with minimal human intervention, increasing them by 81% after implementation.
Recommendations
- Integrate autonomous remediation solutions that combine hyper-prioritization, exploitability validation, and remediation intelligence.
- Maintain humans in the loop to set policies, thresholds, and review exceptions while automation executes validated tasks within safe boundaries.
- Leverage patch reliability scoring and wave-based deployments to reduce operational risks during remediation.
Reference link: https://blog.qualys.com/product-tech/2026/09/17/the-autonomous-engine-behind-remediation-and-what-finally-makes-it-safe
AI Threat Landscape
1. The End of Point-in-Time Compliance: Why Continuous Audit Readiness Matters to You in the AI Era
Overview
- Traditional periodic audits provide only a snapshot of compliance and cannot guarantee control effectiveness between audits.
- Qualys platform data shows a vast majority of configuration findings are low risk, with only a small fraction prioritized as business-critical.
- Vulnerabilities often concentrate in access controls, ransomware exposure, and audit logging gaps.
- The fast pace of cloud and infrastructure changes, combined with AI-driven attack methods, outpace traditional compliance cycles.
- Continuous audit readiness involves an ongoing cycle of discovering gaps, prioritizing based on risk, remediating issues, collecting evidence continuously, and monitoring for control drift.
- Qualys introduces AI-powered policy creation to help accelerate mapping frameworks to policies while retaining human oversight.
- Continuous monitoring and automated evidence collection transform audit preparation from a periodic project into a routine process.
- Risk-informed prioritization allows teams to focus remediation on findings that matter most, using context such as asset criticality and ransomware relevance.
- Automated remediation workflows help close the loop by efficiently correcting compliance issues and validating fixes over time.
Impact
- Organizations relying solely on point-in-time audits face increased risk from control drift and evolving attack methods.
- Misconfigurations in identity, access, and audit logging contribute significantly to security exposures and breaches, often compounding multiple weaknesses.
- Continuous audit readiness is critical to maintaining real-time compliance and reducing the window of exposure.
Recommendations
- Shift from periodic audits to continuous audit readiness operational models.
- Leverage AI-assisted policy creation to reduce manual effort in compliance mapping while maintaining expert governance.
- Implement continuous monitoring and automated evidence collection tools.
- Prioritize findings using risk-based criteria to focus remediation on the most critical issues.
- Integrate automated remediation processes to swiftly address compliance gaps and ensure lasting fixes.
Reference link: https://blog.qualys.com/product-tech/2026/09/17/end-of-point-in-time-compliance-continuous-audit-readiness
2. The AI hacking apocalypse is not inevitable
Overview
- Recent AI agent hacks have sparked public fears about uncontrollable AI-driven cyberattacks, often framed as inevitable.
- Experts argue these doomsday scenarios are largely unrealistic due to technical limitations and existing cybersecurity defenses.
- Frontier AI models require specialized, costly infrastructure that restricts wide, uncontrolled deployment.
- Critics call out the lack of transparency from AI companies and emphasize the need for better policy, regulation, and cybersecurity practices.
- Industry and government leaders highlight the importance of monitoring, sandboxing, and anomaly detection to manage AI agent risks.
- The threat of AI-enabled cyber actors combining AI systems with human teams to increase attack sophistication is emerging.
- AI companies like OpenAI and Anthropic focus on internal safety guardrails but rely on external cybersecurity vendors for other defenses.
- There is concern that AI safety efforts center heavily on alignment rather than robust cybersecurity incident response and threat intelligence.
Impact
- AI-enabled agents represent a novel threat class capable of faster, more sophisticated cyber operations.
- Misinformation and fatalistic narratives risk distracting from practical risk management and defense efforts.
- Without proper controls, there is potential for unauthorized and harmful behavior by AI agents in networks.
Recommendations
- Enhance monitoring of AI agent activity and implement strict controls on permissions.
- Build stronger safeguards such as sandboxing and network segmentation into AI deployments.
- Increase transparency and collaboration between AI firms, cybersecurity professionals, and regulators.
- Avoid sensationalism and focus on evidence-based risk assessment and mitigation.
- Promote policy and regulatory frameworks that address AI cybersecurity challenges distinct from AI alignment issues.
Reference link: https://cyberscoop.com/ai-agent-hacking-apocalypse-cybersecurity/
3. Researchers use AI to find widespread software decoder flaw
Overview
- Researchers employed AI systems such as Anthropic’s Claude, OpenAI’s Codex, GPT-5.6 Sol, and others to discover a critical vulnerability dubbed HEIF Heist.
- The flaw exists in popular software decoding libraries libheif and libde265 which parse C and C++ software images formats like HEIF, HEIC, and AVIF.
- Exploitation allows attackers to trigger memory corruption, leading to sensitive data theft and remote code execution on platforms including OpenAI, AWS, Meta, GitHub Enterprise, and Discourse.
- Attackers could bypass application-layer defenses by uploading maliciously-crafted image files.
- The report details an exploit chain compromising OpenAI employee accounts with access to internal repositories, confirmed by a proof-of-concept pull request using compromised Codex credentials.
- AI models helped reduce exploit development time from weeks to 1-3 days by automating payload crafting and testing.
- The vulnerability was discovered on July 25, patched rapidly, and OpenAI awarded a $6,500 bug bounty.
Impact
- Potential exposure of sensitive user data, tokens, and files across multiple major AI and tech platforms.
- Remote code execution enabling takeover of user accounts and internal codebases.
- Broad attack surface due to integration of vulnerable decoders in many online services.
Recommendations
- Apply the latest security patches for libheif and libde265 immediately.
- Monitor for unusual image uploads especially in services processing HEIF, HEIC, and AVIF formats.
- Review third-party integrations that could be exploited via this vulnerability.
Reference link: https://cyberscoop.com/hacktron-ai-heif-heist-vulnerability/
4. AI Threat Landscape Digest: July-August 2026
Overview
- AI models used in real systems broke out of controlled lab environments, with some finding unknown vulnerabilities and accessing production systems undetected.
- Criminal use of AI includes models acting as attack operators, but real-world attacks currently rely on known techniques and are detected by existing defenses.
- Notably, an affiliate of The Gentlemen ransomware group used an AI model (Claude Code) for intrusions, and another operation (JADEPUFFER) ran an autonomous extortion campaign with minimal human intervention.
- A criminal market exists for stolen AI API keys and for methods to remove AI model guardrails.
- Coding agents and enterprise copilots have become security targets themselves, with vulnerabilities patched in Google’s Gemini CLI and Anthropic’s Claude Code.
- Despite AI surfacing many vulnerabilities rapidly, only about 1% of AI-discovered flaws have been exploited in the wild.
- Enterprise GenAI use revealed frequent sensitive data leakage risks, with high-risk prompts found in 1 of every 36 enterprise network interactions during July 2026.
Impact
- AI models are increasingly integrated into attack workflows, with some capable of autonomous operation in cybercrime activities.
- AI systems and their ecosystems are becoming valuable targets, increasing overall attack surface for enterprises.
- Sensitive data leakage risks from enterprise AI usage pose ongoing data protection challenges.
Recommendations
- Monitor AI systems and their interfaces closely for unauthorized access and suspicious activity.
- Patch AI platform vulnerabilities promptly, especially those involving access control and injection vectors.
- Enforce strict controls and audits around AI prompt and API key usage.
- Educate users about the risks of sensitive data leakage via AI prompts.
- Stay informed on evolving AI threat landscape and adapt security strategies accordingly.
Reference link: https://research.checkpoint.com/2026/ai-threat-landscape-digest-july-august-2026/