โ† September 2026
News 2026-09-12

๐Ÿ›ก๏ธ Cybersecurity Vulnerability Watch

Patch Cisco Secure Firewall Management Center (FMC) now. CVE-2026-20079 (CVSS 10.0) is an authentication bypass in the FMC web interface that lets an unauthenticated, remote attacker get in, andโ€ฆ

๐Ÿ›ก๏ธ Cybersecurity Vulnerability Watch
Open report

๐Ÿ›ก๏ธ Cybersecurity Vulnerability Watch

Week of: 2026-09-06 to 2026-09-12 Reporting window: Most recently completed Sundayโ€“Saturday (excludes the in-progress week).


1. Top Action Item

Patch Cisco Secure Firewall Management Center (FMC) now. CVE-2026-20079 (CVSS 10.0) is an authentication bypass in the FMC web interface that lets an unauthenticated, remote attacker get in, and Cisco says three threat clusters โ€” ransomware and state-sponsored โ€” are already exploiting it and a second, recently patched FMC flaw to steal credentials and deploy Qilin ransomware. Anyone running FMC software should apply Cisco's fixes immediately and treat the management interface as compromised until they've checked it.


2. Exploited This Week

Cisco Secure Firewall Management Center โ€” CVE-2026-20079

  • Source: The Hacker News
  • Link: The Hacker News
  • Severity: CVSS 10.0
  • What's happening: Three distinct threat clusters linked to ransomware and state-sponsored activity are exploiting two recently patched FMC vulnerabilities, led by CVE-2026-20079, an authentication bypass in the FMC web interface that allows unauthenticated, remote attackers in; observed activity includes credential theft and Qilin ransomware deployment.
  • Fix: Apply Cisco's patches for both FMC flaws (recently released; see source for versions). Treat any unpatched or internet-exposed FMC as compromised and hunt for credential theft and Qilin activity.

Google Chrome / Microsoft Edge (Chromium) โ€” CVE-2026-87491

  • Source: Microsoft MSRC
  • Link: Microsoft MSRC
  • Severity: see source (out-of-bounds write in V8)
  • What's happening: Google is aware that an exploit for this Chromium V8 out-of-bounds write exists in the wild; Microsoft Edge ingests Chromium and carries the same vulnerability, and the same Chromium update resolves other related fixes.
  • Fix: Update Google Chrome and Microsoft Edge to the latest release (see Google Chrome Releases for versions).

JFrog Artifactory โ€” CVE-2026-42016

  • Source: The Hacker News
  • Link: The Hacker News
  • Severity: CVSS 8.1 (incorrect authorization)
  • What's happening: CISA added this and other flaws to its Known Exploited Vulnerabilities catalog following reports of active exploitation; separately, Wiz reported attackers chaining two Artifactory flaws to take administrator control of self-hosted servers and plant backdoors between August 15 and September 8.
  • Fix: Update self-hosted Artifactory. JFrog fixed both flaws before the observed attacks, so only servers that had not been updated were exposed (see source for versions).

ConnectWise ScreenConnect and MikroTik RouterOS

  • Source: The Hacker News
  • Link: The Hacker News
  • Severity: see source
  • What's happening: These products are covered by the same CISA KEV batch of five flaws added after reports of exploitation in the wild (the advisory details CVE-2026-42016; other CVEs and affected versions are in the source).
  • Fix: Check the CISA KEV entry and vendor advisories for the affected versions and apply the vendor updates.

PaperCut NG/MF

  • Source: The Hacker News
  • Link: The Hacker News
  • Severity: see source
  • What's happening: Two PaperCut flaws have come under active exploitation, prompting the vendor to replace all previously published emergency patches with regular maintenance releases.
  • Fix: Install PaperCut NG/MF 26.0.5, 25.0.13, or 24.1.10.

Sogou Input Method (Windows) โ€” GRAYRABBIT backdoor

  • Source: The Hacker News
  • Link: The Hacker News
  • Severity: see source
  • What's happening: China-linked group UNC3569 exploited a flaw in Sogou Input Method โ€” widely used for typing Chinese on Windows โ€” starting with a crafted link and ending with the attacker able to do anything the logged-in user could do, including installing the GRAYRABBIT backdoor (research by Gen Digital; Sogou is owned by Tencent).
  • Fix: Update Sogou Input Method to the latest version; see source for vendor guidance.

3. Critical Patch Roundup

GitLab โ€” CVE-2026-85706

  • Source: The Hacker News
  • Link: The Hacker News
  • Severity: CVSS 10.0
  • What's happening: A path traversal issue in the repository commits API could let an unauthenticated user read arbitrary files from the GitLab server; in-the-wild probes were observed within hours of public disclosure (probing, not confirmed exploitation).
  • Fix: Apply GitLab's patches released with this disclosure (see source for versions).

Microsoft โ€” September 2026 Patch Tuesday

  • Source: Cisco Talos
  • Link: Cisco Talos
  • Severity: 113 vulnerabilities rated "critical" out of 973 total
  • What's happening: Microsoft's monthly security update covers a very large set of flaws across its product range, including a high number of critical-rated issues.
  • Fix: Apply Microsoft's September 2026 security updates; use the Talos roundup to prioritize the prominent vulnerabilities.

Fortinet โ€” FortiMonitor OnSight web portal (FG-IR-26-170)

  • Source: Fortinet FortiGuard
  • Link: Fortinet FortiGuard
  • Severity: CVSS 9.6
  • What's happening: Sensitive information (a static JWT signing key) in source code may let a remote, unauthenticated attacker bypass authentication via a forged or reused JWT.
  • Fix: Apply Fortinet's update for the affected version (see advisory).

Fortinet โ€” FortiPAM Privileged Access Agent Chrome extension (FG-IR-26-168)

  • Source: Fortinet FortiGuard
  • Link: Fortinet FortiGuard
  • Severity: CVSS 9.1
  • What's happening: An improper authentication flaw may let a remote, unauthenticated attacker proxy a user's browser traffic through attacker-controlled servers if the user visits a malicious website.
  • Fix: Update the Chrome extension per the advisory.

Fortinet โ€” FortiSandbox / FortiSandbox Cloud / PaaS web UI (FG-IR-26-166)

  • Source: Fortinet FortiGuard
  • Link: Fortinet FortiGuard
  • Severity: CVSS 8.9
  • What's happening: An improper access control flaw (unauthenticated control of NAT rules) may let an unauthenticated attacker access sensitive information via crafted HTTP requests.
  • Fix: Apply Fortinet's update per the advisory.

Fortinet โ€” FortiOS and FortiProxy Agentless ZTNA portal (FG-IR-26-174)

  • Source: Fortinet FortiGuard
  • Link: Fortinet FortiGuard
  • Severity: CVSS 7.3
  • What's happening: Improper certificate validation may let a remote, unauthenticated attacker perform a man-in-the-middle attack between the ZTNA portal and the backend destination website.
  • Fix: Apply Fortinet's update per the advisory.

Microsoft Windows Defender โ€” "ShieldCrash"

  • Source: Dark Reading
  • Link: Dark Reading
  • Severity: see source
  • What's happening: A disgruntled researcher published another zero-day exploit targeting Windows Defender. The article does not report in-the-wild exploitation of this specific flaw.
  • Fix: see source; monitor Microsoft guidance and keep Defender and Windows fully updated.

4. Home / SOHO Impact

  • Update Chrome and Microsoft Edge to the latest version today โ€” an exploit for CVE-2026-87491 is confirmed to be in the wild, and it affects both browsers.
  • Install this month's Windows updates. Microsoft's September release fixes 973 vulnerabilities, 113 of them rated critical; keep Windows Defender updated as well, since a new public zero-day exploit for Defender (ShieldCrash) was published this week.
  • Check your MikroTik RouterOS router for firmware updates. It's on CISA's list of actively exploited flaws this week โ€” if you can't update it, consider isolating or replacing it.
  • If you use Sogou Input Method on Windows, update it. Attackers used a flaw in it to install the GRAYRABBIT backdoor.
  • Android users: stick to official app stores. A campaign in Indonesia is delivering the Gigabud Trojan through cloned banking apps that abuse the Android Work Profile feature.

5. Enterprise Impact

  • Cisco FMC is the top enterprise priority. Patch CVE-2026-20079 (CVSS 10.0) and the second patched FMC flaw immediately; restrict internet exposure of the FMC web interface where possible, and hunt for credential theft and Qilin ransomware staging on any host that may have been reachable.
  • Treat the CISA KEV batch as emergency work. Self-hosted JFrog Artifactory (CVE-2026-42016, CVSS 8.1 โ€” with observed chaining to admin takeover and backdoors), ConnectWise ScreenConnect, and MikroTik RouterOS are all reported as actively exploited. Build pipelines pulling from unpatched Artifactory instances are a supply-chain risk, not just a server risk.
  • GitLab admins should patch and review. CVE-2026-85706 (CVSS 10.0) allows unauthenticated arbitrary file reads via the repository commits API, and probes began within hours of disclosure โ€” check logs for scanning of the commits API and for exposed GitLab instances.
  • Work the Microsoft September update deliberately. 973 vulnerabilities with 113 rated critical is too many to treat uniformly; use the Talos roundup to prioritize the prominent and remotely reachable issues.
  • Fortinet shops have four high-impact fixes: FortiMonitor OnSight (CVSS 9.6 JWT auth bypass), the FortiPAM Privileged Access Agent Chrome extension (CVSS 9.1), FortiSandbox web UI (CVSS 8.9), and the FortiOS/FortiProxy Agentless ZTNA portal (CVSS 7.3).
  • PaperCut NG/MF operators should move to the new maintenance releases (26.0.5 / 25.0.13 / 24.1.10), which replace the emergency patches for the two actively exploited flaws.
  • Identity is the recurring weak point. This week's reporting covers Microsoft 365 access reached via BYOD and the Graph API with handoff to extortion groups like ShinyHunters, plus post-exploitation identity spoofing in SPIFFE/SPIRE from a compromised Kubernetes node โ€” review token/session exposure and workload identity trust boundaries.

6. What To Patch First

  1. Cisco Secure Firewall Management Center โ€” fixes for CVE-2026-20079 (CVSS 10.0) and the second patched FMC flaw (exploited; ransomware/credential theft)
  2. Google Chrome and Microsoft Edge โ€” latest release for CVE-2026-87491 (exploited in the wild; universal)
  3. Microsoft September 2026 security updates โ€” 973 vulns, 113 critical (widely deployed; maximum breadth)
  4. JFrog Artifactory (self-hosted) โ€” latest for CVE-2026-42016 (CVSS 8.1) and the chained flaw (exploited; KEV; admin takeover and backdoors)
  5. PaperCut NG/MF โ€” 26.0.5 / 25.0.13 / 24.1.10 (actively exploited; replaces emergency patches)
  6. ConnectWise ScreenConnect and MikroTik RouterOS โ€” vendor updates per CISA KEV (actively exploited; see source for versions)
  7. GitLab โ€” patched release for CVE-2026-85706 (CVSS 10.0) (critical; in-the-wild probes)
  8. Fortinet โ€” FortiMonitor OnSight (FG-IR-26-170), FortiPAM Agent Chrome extension (FG-IR-26-168), FortiSandbox (FG-IR-26-166), FortiOS/FortiProxy ZTNA (FG-IR-26-174) (critical to high; edge and security infrastructure)
  9. Sogou Input Method (Windows) โ€” latest version (exploited to deliver the GRAYRABBIT backdoor)

Sources

More from News