IT Intelligence · IT

The IT week was the control plane. Sandworm overlap and Qilin on Cisco FMC; PaperCut’s agents; GitLab’s file-read.

7–14 September 2026. CISA listed fourteen exploited CVEs in four days. The ones that grant total control sit on FMC, N-central, ScreenConnect, PaperCut, GitLab, Magento, FortiOS, and NetScaler. Microsoft’s 974-CVE Patch Tuesday is a capacity problem, not the intelligence problem.

RWP Ventures · 2026-09-14 · 13 min read · priority 8.9

Executive summary

FACT: This week the highest-leverage enterprise problem was not Microsoft’s record Patch Tuesday. It was the software that already sits above the endpoint — the firewall manager, the RMM, the print server, the Git host, the artifact repo, the Magento storefront.

CISA’s Known Exploited Vulnerabilities catalog, version 2026.09.11 released 11 September 19:32 UTC, added fourteen CVEs between 8 and 11 September. Eight of those carry a BOD 26-04 forensic-triage flag. Six carried a three-day federal clock that has already expired or expires today. Catalog ransomware-use remains Unknown on every one of them. That flag is not a clean bill of health. Cisco Talos separately attributed one FMC cluster to a Qilin operator.

The week’s attributed exploitation is on Cisco Secure Firewall Management Center. Talos published three post-compromise clusters on CVE-2026-20079 (unauthenticated root, CVSS 10.0) and CVE-2026-20316 (static low-priv credentials): UAT-12197 dumped FMC user hashes; UAT-11823, high-confidence APT with Sandworm tooling overlap, dropped Cyclops Blink; UAT-11988, high-confidence Qilin affiliate, tunneled LDAP/Kerberos/SMB/WinRM off the management plane and encrypted. Federal KEV due date was 12 September. Forensic triage: Yes.

The week’s measured campaign is PaperCut. GreyNoise: 440 self-hosted NG/MF instances, 395 named organizations, 48 countries, 12 domain-admin outcomes. Education is 204 of 440. CISA KEV due date for CVE-2026-81578 / CVE-2026-82078 is today, 14 September. The emergency patch is not the hunt.

Two more due today, both forensic-triage Yes: GitLab CVE-2026-85706 (CVSS 10 unauthenticated commits-API file read) and ConnectWise ScreenConnect CVE-2026-84869 (client-side file transfer/execute in an active session). Magento StyleSmuggler (CVE-2026-75650) and N-central (CVE-2026-86218) were KEV’d on 8 September with 11 September clocks. FortiOS CVE-2025-25249 (PivotC2) and NetScaler CVE-2026-19490 were KEV’d on 9 September with 12 September clocks.

ASSESSMENT: If your patch queue this week was “the 974 Microsoft CVEs,” you sequenced it backwards. The two Windows EoPs are real SYSTEM ladders. They are local. The week’s internet-facing control planes are not.

The week in one assessment

Three threads, one pattern: attackers keep buying the box that administers the other boxes — FMC, N-central, ScreenConnect, PaperCut, GitLab, Artifactory — while Patch Tuesday inflates the backlog that hides them.

1. Most important development

Cisco FMC. It is not a firewall. It is the appliance that writes policy to the firewalls. Unauthenticated root on FMC is unauthenticated root on the management plane of the estate.

Cisco first disclosed CVE-2026-20079 on 4 March. PSIRT stated on 9 September that it became aware of exploitation in August. CISA listed it the same day. Talos’s three clusters are the increment, and they are not one campaign. Webshell-and-dump, Sandworm-overlap APT, and Qilin can all use the same two CVEs without sharing operators. That is the 2024–2026 edge-device pattern, now on the manager rather than the sensor.

Cisco’s own IoC: if zgrep "package_info.license" /var/log/messages shows package_info.pl /var/tmp/license.tmp, the vulnerability may have been exploited. The hotfixes prevent the next request. They do not unscrew Cyclops Blink or a SOCKS tunnel that still has AD hashes. Cloud-delivered Security Cloud Control was patched by Cisco. On-prem FMC is the ticket.

There is no confirmed OT or physical-process impact in Cisco’s advisory or Talos’s clusters. Firewalls FMC manages often sit on IT/OT conduits. Inventory that. Do not write it up as a PLC event.

2. Active exploitation

CONFIRMED, CISA KEV this week (catalog 2026.09.11):

AddedCVEProductDueForensic triage
8 SepCVE-2026-75650Adobe Commerce / Magento11 SepYes
8 SepCVE-2026-86218N-able N-central11 SepYes
8 SepCVE-2026-81963Windows Update Stack22 SepNo
8 SepCVE-2026-85880Windows ALPC22 SepNo
9 SepCVE-2026-20079Cisco Secure FMC / SCC12 SepYes
9 SepCVE-2026-19490Citrix NetScaler ADC / Gateway12 SepYes
9 SepCVE-2025-25249FortiOS / FortiSwitchManager / FortiSASE12 SepYes
9 SepCVE-2026-87491Chromium V823 SepNo
10 SepCVE-2026-67277MikroTik RouterOS13 SepNo
10 SepCVE-2026-86060MikroTik RouterOS13 SepYes
11 SepCVE-2026-85706GitLab CE/EE14 SepYes
11 SepCVE-2026-84869ConnectWise ScreenConnect14 SepYes
11 SepCVE-2026-42016JFrog Artifactory25 SepNo
11 SepCVE-2026-42018JFrog Artifactory25 SepNo

CONFIRMED, due today from last month: PaperCut CVE-2026-81578 / CVE-2026-82078 (added 31 August, forensic triage No).

CONFIRMED by vendor/researcher, not yet KEV: Check Point CVE-2026-85102 / CVE-2026-85103. Check Point reports no exploitation. NCSC-NL assesses abuse as imminent. Treat internet-facing Quantum VPN as a patch-now perimeter, not as a confirmed compromise.

REPORTED Huntress three August ScreenConnect incidents with a four-stage VBScript chain; John Hammond aligned the automatic file-transfer-and-execute pattern with CVE-2026-84869. That is three incidents, not a census.

REPORTED watchTowr honeypot probes against GitLab CVE-2026-85706 at 06:00 UTC on 11 September. Reconnaissance and exploit-shaped traffic. Not a victim count.

REPORTED SOCRadar — CVE-2025-25249 exploited since at least July to drop PivotC2, a FortiGate-specific Node.js RAT; >30,000 IPs targeted, 178 infections. Russian-speaking cybercrime assessed. CISA’s KEV listing is the confirmation of exploitation, not of those counts.

3. Threat actor / campaign activity

UAT-11823 / Cyclops Blink. Talos: high-confidence APT, tooling overlap with Sandworm (GRU Unit 74455). Makeself-wrapped license.tmp, Netcat, managed-device config harvest, modular ELF with DoH, credential harvest, sniffing, /etc/init.d/ persistence. Prior US/UK attribution of Cyclops Blink to Sandworm is background. It is not, by itself, a Talos statement that this cluster is Sandworm. Do not upgrade overlap into a named GRU operation on every FMC.

UAT-11988 / Qilin. Talos: high-confidence ransomware operator using CVE-2026-20316, then Impacket / Invoke-TheHash / AV killers, then Qilin on selected endpoints. This is the week’s only vendor-attributed ransomware use on a KEV’d control-plane bug. CISA’s catalog flag on 20079 remains Unknown. Both can be true.

UAT-12197. Unattributed. JSP webshell plus cmd.jar querying OmniQuery.pl for FMC users.auth_data. Credential theft from the manager. Treat as a third occupant of the same primitive.

PaperCut operator. GreyNoise: likely Russian-speaking, IP 45.142.193.132, OpenAI Codex harness plus a DeepSeek model, commodity AD tooling. Empty lab to first real-victim RCE in under four hours; one U.S. high school, initial access to domain admin in seven minutes; once the mass run started, 11 organizations in 26 seconds. Blackpoint independently recovered agent project state — timestamped context, retry lists, up to 200 concurrent targets. ASSESSMENT: this is AI assistance across research, targeting, and retry. It is not a claim that a model discovered the zero-days. The bugs were vendor-confirmed and emergency-patched before the 31 August mass run. The AI layer is speed and concurrency.

Artifactory. Wiz: multiple actors chained CVE-2026-42018 (anonymous token even with anonymous access disabled) and CVE-2026-42016 (token-scope not checked) against self-hosted instances between 15 August and 8 September. Persistence via Groovy plugins, shell via plugin endpoints, Rust backdoors. CVE-2026-82329 (unauth admin under default config) was already KEV’d 2 September. Cloud Artifactory is JFrog’s problem. Self-hosted is yours.

UNKNOWN a single actor behind the KEV pile. Do not invent one. The shared fact is internet-facing enterprise middleware, not a merger of crews.

4. Vulnerabilities to prioritize

Sequence by reachability and forensic-triage, not by CVE count.

  1. On-prem Cisco FMC — listed hotfixes for CVE-2026-20079 / CVE-2026-20316. Hunt package_info.pl /var/tmp/license.tmp first. Cisco’s hardening bundle is due the week of 14 September; do not wait for it if the hotfix is already sitting in the advisory. Management interface off the internet.
  2. PaperCut NG/MF — QA’d maintenance 26.0.5 / 25.0.13 / 24.1.10, which replace Emergency Patch Releases 1–3. If the Application Server answered from the internet after 27 August: hunt pc-app.execmd.exe, hive dumps under C:\Windows\Temp\pc-*.hiv, SimpleHelp “Remote Access Service,” Ligolo under C:\ProgramData, Administrator17. Firewall the Application Server. Cloud PaperCut is not this product.
  3. Self-managed GitLab — 19.1.8 / 19.2.6 / 19.3.2. Hunt HTTP POST to /api/v4/projects/{id}/repository/commits/ with a file.path parameter. This is a secrets-read, not claimed unauthenticated RCE. Rotate tokens, CI variables, deploy keys, and runner credentials if the instance was internet-facing after 10 September. GitLab.com and Dedicated are out of scope.
  4. ScreenConnect — 26.6.5, then reinstall host clients and update access agents. Cloud “no action” is server-side only. Hunt wscript.exe children of ScreenConnect.WindowsClient.exe and 1.vbs4.vbs. This is not CVE-2024-1709.
  5. N-central — 2026.3.1.14 (Hotfix 4) for CVE-2026-86218. Last week this was a disputed in-the-wild. This week it is KEV with forensic triage and an 11 September federal clock. Audit admin accounts created since 1 August. Pull internet-facing N-central off WAN.
  6. Magento / Adobe Commerce — VULN-39341 (APSB26-146) and encryption-key plus credential rotation at every upstream (Stripe, Braintree, Adyen, PayPal, deploy keys, GraphQL tokens). Patch without rotation is not remediation. Sansec: two operators, Rust implant renaming itself ([kworker/u:8:0]fc-cachechronyd), C2 onto NTP-shaped UDP.
  7. FortiOS CVE-2025-25249 — patched in January; KEV’d this week because PivotC2 is live. CAPWAP cw_acd / UDP 5246. Fixed floors include FortiOS 7.6.4 / 7.4.9 / 7.2.12 / 7.0.18. Assume config and credential harvest on any box that was internet-reachable on 5246.
  8. NetScaler CVE-2026-19490 — 14.1-73.32+ / 13.1-63.21+ (and listed FIPS). No workaround. Previdian: exploit-shaped traffic from 3 September. Gateway or AAA virtual-server configs.
  9. Check Point 85102 / 85103 — LivePatch Take 24 on R81.20 / R82 / R82.10, or the listed Jumbo takes. Take 18 is not Take 24. R82.20 is not affected. EoS R80–R81.10 has no LivePatch.
  10. Self-hosted Artifactory — branch-correct fixed builds for 42018 / 42016 / 82329. Hunt new admin accounts, Groovy plugins, unexpected reverse shells. Due 25 September is not permission to wait.
  11. Windows September cumulatives — CVE-2026-81963 (Update Stack link-following) and CVE-2026-85880 (ALPC heap overflow). Both Important / 7.8 / Exploitation Detected / KEV due 22 September / forensic triage No. They turn a phished user into SYSTEM. They are not remote worms.
  12. Chrome / Edge Chromium — CVE-2026-87491 (V8 OOB write, KEV 9 September) on top of last week’s CVE-2026-85046. Forced current stable, not next month’s ring.

No invented CVEs. MikroTik RouterOS (CVE-2026-67277 / CVE-2026-86060, CERT.PL “MikroTrick” since 2 September) is an IT-to-OT edge path; the OT read is in [this week’s weekly OT](/posts/2026-09-11-weekly-ot-m580-reyrolle-mikrotik/).

5. Identity / cloud / enterprise

The identity story this week is not a new AiTM kit. It is what a print server and a firewall manager do to Active Directory.

PaperCut NG/MF on Windows runs as SYSTEM and is usually domain-joined. GreyNoise’s 12 domain-admin outcomes and the seven-minute high-school case are the identity incident. Hunt LSASS, hive dumps, and newly created privileged accounts — not just the PaperCut version string.

FMC credential theft (users.auth_data) plus Qilin’s LDAP/Kerberos/SMB/WinRM forwarding is the other identity incident. A SOCKS tunnel off the management plane is an alternate path into the IdP. Conditional Access that ignores a tunnel sourced from a “trusted” management VLAN will keep losing.

Last week’s standing war — BigBear 2.0, Knight Office, stolen M365 sessions — did not end. It was quieter in primary reporting than the KEV pile. KnowBe4 described Direct Send abuse for internal-looking M365 mail; that is REPORTED tradecraft, not this week’s lead. Revolut’s 14 September disclosure is social engineering via a fraudulent government data request on a legitimate-looking domain, not a core-banking compromise. Do not mash it into Entra.

Non-human identities on GitLab and Artifactory — CI tokens, deploy keys, package-registry credentials, Groovy plugin exec — are the cloud-adjacent blast radius of the two DevOps KEVs. Rotate them if the box was reachable.

6. Ransomware / criminal activity

CONFIRMED by Talos: Qilin affiliate activity (UAT-11988) on FMC via CVE-2026-20316. That is criminal encryption staged from the firewall manager. It is not a new ransomware family.

REPORTED SOCRadar’s PivotC2 cluster as financially motivated, with US intrusions moving to AD dumps, RDP pass-the-hash, and Exchange PST exfil to object storage. Treat the 178-infection figure as SOCRadar’s census, not CISA’s.

PaperCut’s first-wave post-exploit picture from the vendor included SimpleHelp and AnyDesk. Second-wave, per PaperCut and GreyNoise, was more sophisticated. Ransomware-use on the PaperCut KEVs remains Unknown in the catalog. Domain admin on a school district print server is still a ransomware precondition.

StyleSmuggler’s Rust implant and PHP web shell are commerce persistence, not a named ransomware crew. Manchester Airports Group and Rhysida/Berlin were last week’s extortion notes; they did not grow a new technical increment in this window.

Do not convert an IT compromise at a manufacturer or a hospital into confirmed OT impact. No primary source this week documented encryption of a controller or a safety system.

7. Defensive priorities

  1. Internet-facing FMC, N-central, ScreenConnect clients, PaperCut Application Server, self-managed GitLab, Magento, FortiOS CAPWAP, NetScaler Gateway/AAA, Check Point VPN. If it administers other boxes and it answers from WAN, it is this week’s ticket.
  2. Forensic triage is the instruction on Magento, N-central, FMC, NetScaler, Fortinet, ScreenConnect, GitLab, and MikroTik 86060. Patching without the hunt is how you leave license.tmp, 1.vbs, a Groovy plugin, or a Magento chronyd implant in place.
  3. PaperCut: maintenance release and AD hunt. Education-sector print is over-represented in GreyNoise’s 440.
  4. Magento: hotfix and key/credential rotation at the source.
  5. ScreenConnect: 26.6.5 does not refresh the host client by itself. Cloud banners that say “no action” are about the server.
  6. Windows September cumulatives for the two KEV EoPs, then DNS / Netlogon / Exchange / SharePoint by reachability. Do not let 974 CVEs postpone the control plane.
  7. Forced Chromium current stable.

8. What changed from last week

Last week’s [weekly IT](/posts/2026-09-07-weekly-it-rmm-identity-browser/) was N-central (four hotfixes in five weeks, CVE-2026-86218 still disputed in production), Chrome CVE-2026-85046 as the sixth in-the-wild of 2026, BigBear 2.0 / Knight Office session theft, and Magento StyleSmuggler with no vendor patch.

This week those open items closed in the wrong direction:

9. What we are watching next

Whether CISA lists Check Point 85102/85103 after the first public exploit attempt — NCSC-NL has already put a clock on it. Whether Cisco’s week-of-14-September FMC hardening release adds CVEs that change the hunt, not just the patch file. Whether GreyNoise or PaperCut publish a second-wave victim increment past 440. Whether GitLab 85706 produces a documented secrets-to-supply-chain case, which the CVSS Integrity High / Availability None vector allows without being RCE. Whether Artifactory 82329/42016/42018 get a ransomware-use flag. Whether N-central 86218 hunt notes from MSPs show admin-account creation at scale. Chromium’s next in-the-wild after 85046 and 87491.

10. RWP assessment

Confidence: High on the KEV listing set (catalog 2026.09.11), on Talos’s three FMC clusters as described, on PaperCut’s GreyNoise census as a measured campaign, and on GitLab/ScreenConnect as forensic-triage due-today items. Moderate on unifying those into a single “control-plane campaign” — the pattern is target class, not actor. Low on Check Point exploitation (vendor: none; national CERT: imminent). None claimed on OT process impact.

The week does not require a new SIEM use-case. It requires the boxes that administer other boxes to be patched, hunted, and pulled off WAN, and the IdP to assume that a print server or a firewall manager can already mint a domain admin.

This assessment covers 7–14 September 2026 and was published 14 September 2026.

Sources

  1. CISA — KEV catalog JSON catalogVersion 2026.09.11
  2. CISA — Adds four KEVs 8 September 2026
  3. CISA — Adds four KEVs 9 September 2026
  4. CISA — Adds two KEVs 10 September 2026
  5. CISA — Known Exploited Vulnerabilities Catalog
  6. CISA — BOD 26-04
  7. Cisco Talos — Active exploitation of Cisco Secure FMC vulnerabilities
  8. Cisco — Secure FMC Authentication Bypass CVE-2026-20079
  9. Cisco — Secure FMC Static Credential CVE-2026-20316
  10. GreyNoise — Agents Gone Wild
  11. PaperCut — Security Bulletin 27 Aug 2026
  12. GitLab — Critical Patch Release 19.3.2, 19.2.6, 19.1.8
  13. watchTowr — Rapid Reaction CVE-2026-85706
  14. ConnectWise — ScreenConnect 26.6.5 Security Patch
  15. Huntress — Rogue ScreenConnect installations, worm-like activity
  16. Adobe — APSB26-146 CVE-2026-75650
  17. Sansec — StyleSmuggler CVE-2026-75650
  18. Microsoft — September 2026 Security Updates
  19. Microsoft — CVE-2026-81963 Windows Update Stack
  20. Microsoft — CVE-2026-85880 Windows ALPC
  21. Fortinet — FG-IR-25-084 CVE-2025-25249
  22. SOCRadar — CVE-2025-25249 Exploitation Delivers PivotC2
  23. Citrix — CTX696939 NetScaler CVE-2026-19490
  24. Rapid7 — CVE-2026-19490
  25. Wiz — Artifactory under attack
  26. Check Point — sk1000117 CVE-2026-85102
  27. Check Point — sk1000118 CVE-2026-85103
  28. NCSC-NL — Kritieke kwetsbaarheden in Check Point VPN-producten
  29. N-able — N-central 2026.3 Hotfix 4 / CVE-2026-86218
  30. Google — Chrome 153 Stable Channel Update CVE-2026-87491
  31. RWP — Daily Top Cisco FMC
  32. RWP — Daily Top PaperCut
  33. RWP — Daily Top GitLab
  34. RWP — Daily Top ScreenConnect
  35. RWP — Weekly IT 7 September 2026