1. Top Action Item

Patch Cisco Secure Firewall Management Center (FMC) now. CVE-2026-20079 (CVSS 10.0) is an authentication bypass in the FMC web interface that lets an unauthenticated, remote attacker get in, and Cisco says three threat clusters — ransomware and state-sponsored — are already exploiting it and a second, recently patched FMC flaw to steal credentials and deploy Qilin ransomware. Anyone running FMC software should apply Cisco's fixes immediately and treat the management interface as compromised until they've checked it.


2. Exploited This Week

Cisco Secure Firewall Management Center — CVE-2026-20079

Google Chrome / Microsoft Edge (Chromium) — CVE-2026-87491

JFrog Artifactory — CVE-2026-42016

ConnectWise ScreenConnect and MikroTik RouterOS

PaperCut NG/MF

Sogou Input Method (Windows) — GRAYRABBIT backdoor


3. Critical Patch Roundup

GitLab — CVE-2026-85706

Microsoft — September 2026 Patch Tuesday

Fortinet — FortiMonitor OnSight web portal (FG-IR-26-170)

Fortinet — FortiPAM Privileged Access Agent Chrome extension (FG-IR-26-168)

Fortinet — FortiSandbox / FortiSandbox Cloud / PaaS web UI (FG-IR-26-166)

Fortinet — FortiOS and FortiProxy Agentless ZTNA portal (FG-IR-26-174)

Microsoft Windows Defender — "ShieldCrash"


4. Home / SOHO Impact


5. Enterprise Impact


6. What To Patch First

  1. Cisco Secure Firewall Management Center — fixes for CVE-2026-20079 (CVSS 10.0) and the second patched FMC flaw (exploited; ransomware/credential theft)
  2. Google Chrome and Microsoft Edge — latest release for CVE-2026-87491 (exploited in the wild; universal)
  3. Microsoft September 2026 security updates — 973 vulns, 113 critical (widely deployed; maximum breadth)
  4. JFrog Artifactory (self-hosted) — latest for CVE-2026-42016 (CVSS 8.1) and the chained flaw (exploited; KEV; admin takeover and backdoors)
  5. PaperCut NG/MF — 26.0.5 / 25.0.13 / 24.1.10 (actively exploited; replaces emergency patches)
  6. ConnectWise ScreenConnect and MikroTik RouterOS — vendor updates per CISA KEV (actively exploited; see source for versions)
  7. GitLab — patched release for CVE-2026-85706 (CVSS 10.0) (critical; in-the-wild probes)
  8. Fortinet — FortiMonitor OnSight (FG-IR-26-170), FortiPAM Agent Chrome extension (FG-IR-26-168), FortiSandbox (FG-IR-26-166), FortiOS/FortiProxy ZTNA (FG-IR-26-174) (critical to high; edge and security infrastructure)
  9. Sogou Input Method (Windows) — latest version (exploited to deliver the GRAYRABBIT backdoor)

Sources