The IT week was the control plane. Sandworm overlap and Qilin on Cisco FMC; PaperCut’s agents; GitLab’s file-read.
7–14 September 2026. CISA listed fourteen exploited CVEs in four days. The ones that grant total control sit on FMC, N-central, ScreenConnect, PaperCut, GitLab, Magento, FortiOS, and NetScaler. Microsoft’s 974-CVE Patch Tuesday is a capacity problem, not the intelligence problem.
Executive summary
FACT: This week the highest-leverage enterprise problem was not Microsoft’s record Patch Tuesday. It was the software that already sits above the endpoint — the firewall manager, the RMM, the print server, the Git host, the artifact repo, the Magento storefront.
CISA’s Known Exploited Vulnerabilities catalog, version 2026.09.11 released 11 September 19:32 UTC, added fourteen CVEs between 8 and 11 September. Eight of those carry a BOD 26-04 forensic-triage flag. Six carried a three-day federal clock that has already expired or expires today. Catalog ransomware-use remains Unknown on every one of them. That flag is not a clean bill of health. Cisco Talos separately attributed one FMC cluster to a Qilin operator.
The week’s attributed exploitation is on Cisco Secure Firewall Management Center. Talos published three post-compromise clusters on CVE-2026-20079 (unauthenticated root, CVSS 10.0) and CVE-2026-20316 (static low-priv credentials): UAT-12197 dumped FMC user hashes; UAT-11823, high-confidence APT with Sandworm tooling overlap, dropped Cyclops Blink; UAT-11988, high-confidence Qilin affiliate, tunneled LDAP/Kerberos/SMB/WinRM off the management plane and encrypted. Federal KEV due date was 12 September. Forensic triage: Yes.
The week’s measured campaign is PaperCut. GreyNoise: 440 self-hosted NG/MF instances, 395 named organizations, 48 countries, 12 domain-admin outcomes. Education is 204 of 440. CISA KEV due date for CVE-2026-81578 / CVE-2026-82078 is today, 14 September. The emergency patch is not the hunt.
Two more due today, both forensic-triage Yes: GitLab CVE-2026-85706 (CVSS 10 unauthenticated commits-API file read) and ConnectWise ScreenConnect CVE-2026-84869 (client-side file transfer/execute in an active session). Magento StyleSmuggler (CVE-2026-75650) and N-central (CVE-2026-86218) were KEV’d on 8 September with 11 September clocks. FortiOS CVE-2025-25249 (PivotC2) and NetScaler CVE-2026-19490 were KEV’d on 9 September with 12 September clocks.
ASSESSMENT: If your patch queue this week was “the 974 Microsoft CVEs,” you sequenced it backwards. The two Windows EoPs are real SYSTEM ladders. They are local. The week’s internet-facing control planes are not.
The week in one assessment
Three threads, one pattern: attackers keep buying the box that administers the other boxes — FMC, N-central, ScreenConnect, PaperCut, GitLab, Artifactory — while Patch Tuesday inflates the backlog that hides them.
1. Most important development
Cisco FMC. It is not a firewall. It is the appliance that writes policy to the firewalls. Unauthenticated root on FMC is unauthenticated root on the management plane of the estate.
Cisco first disclosed CVE-2026-20079 on 4 March. PSIRT stated on 9 September that it became aware of exploitation in August. CISA listed it the same day. Talos’s three clusters are the increment, and they are not one campaign. Webshell-and-dump, Sandworm-overlap APT, and Qilin can all use the same two CVEs without sharing operators. That is the 2024–2026 edge-device pattern, now on the manager rather than the sensor.
Cisco’s own IoC: if zgrep "package_info.license" /var/log/messages shows package_info.pl /var/tmp/license.tmp, the vulnerability may have been exploited. The hotfixes prevent the next request. They do not unscrew Cyclops Blink or a SOCKS tunnel that still has AD hashes. Cloud-delivered Security Cloud Control was patched by Cisco. On-prem FMC is the ticket.
There is no confirmed OT or physical-process impact in Cisco’s advisory or Talos’s clusters. Firewalls FMC manages often sit on IT/OT conduits. Inventory that. Do not write it up as a PLC event.
2. Active exploitation
CONFIRMED, CISA KEV this week (catalog 2026.09.11):
| Added | CVE | Product | Due | Forensic triage |
|---|---|---|---|---|
| 8 Sep | CVE-2026-75650 | Adobe Commerce / Magento | 11 Sep | Yes |
| 8 Sep | CVE-2026-86218 | N-able N-central | 11 Sep | Yes |
| 8 Sep | CVE-2026-81963 | Windows Update Stack | 22 Sep | No |
| 8 Sep | CVE-2026-85880 | Windows ALPC | 22 Sep | No |
| 9 Sep | CVE-2026-20079 | Cisco Secure FMC / SCC | 12 Sep | Yes |
| 9 Sep | CVE-2026-19490 | Citrix NetScaler ADC / Gateway | 12 Sep | Yes |
| 9 Sep | CVE-2025-25249 | FortiOS / FortiSwitchManager / FortiSASE | 12 Sep | Yes |
| 9 Sep | CVE-2026-87491 | Chromium V8 | 23 Sep | No |
| 10 Sep | CVE-2026-67277 | MikroTik RouterOS | 13 Sep | No |
| 10 Sep | CVE-2026-86060 | MikroTik RouterOS | 13 Sep | Yes |
| 11 Sep | CVE-2026-85706 | GitLab CE/EE | 14 Sep | Yes |
| 11 Sep | CVE-2026-84869 | ConnectWise ScreenConnect | 14 Sep | Yes |
| 11 Sep | CVE-2026-42016 | JFrog Artifactory | 25 Sep | No |
| 11 Sep | CVE-2026-42018 | JFrog Artifactory | 25 Sep | No |
CONFIRMED, due today from last month: PaperCut CVE-2026-81578 / CVE-2026-82078 (added 31 August, forensic triage No).
CONFIRMED by vendor/researcher, not yet KEV: Check Point CVE-2026-85102 / CVE-2026-85103. Check Point reports no exploitation. NCSC-NL assesses abuse as imminent. Treat internet-facing Quantum VPN as a patch-now perimeter, not as a confirmed compromise.
REPORTED Huntress three August ScreenConnect incidents with a four-stage VBScript chain; John Hammond aligned the automatic file-transfer-and-execute pattern with CVE-2026-84869. That is three incidents, not a census.
REPORTED watchTowr honeypot probes against GitLab CVE-2026-85706 at 06:00 UTC on 11 September. Reconnaissance and exploit-shaped traffic. Not a victim count.
REPORTED SOCRadar — CVE-2025-25249 exploited since at least July to drop PivotC2, a FortiGate-specific Node.js RAT; >30,000 IPs targeted, 178 infections. Russian-speaking cybercrime assessed. CISA’s KEV listing is the confirmation of exploitation, not of those counts.
3. Threat actor / campaign activity
UAT-11823 / Cyclops Blink. Talos: high-confidence APT, tooling overlap with Sandworm (GRU Unit 74455). Makeself-wrapped license.tmp, Netcat, managed-device config harvest, modular ELF with DoH, credential harvest, sniffing, /etc/init.d/ persistence. Prior US/UK attribution of Cyclops Blink to Sandworm is background. It is not, by itself, a Talos statement that this cluster is Sandworm. Do not upgrade overlap into a named GRU operation on every FMC.
UAT-11988 / Qilin. Talos: high-confidence ransomware operator using CVE-2026-20316, then Impacket / Invoke-TheHash / AV killers, then Qilin on selected endpoints. This is the week’s only vendor-attributed ransomware use on a KEV’d control-plane bug. CISA’s catalog flag on 20079 remains Unknown. Both can be true.
UAT-12197. Unattributed. JSP webshell plus cmd.jar querying OmniQuery.pl for FMC users.auth_data. Credential theft from the manager. Treat as a third occupant of the same primitive.
PaperCut operator. GreyNoise: likely Russian-speaking, IP 45.142.193.132, OpenAI Codex harness plus a DeepSeek model, commodity AD tooling. Empty lab to first real-victim RCE in under four hours; one U.S. high school, initial access to domain admin in seven minutes; once the mass run started, 11 organizations in 26 seconds. Blackpoint independently recovered agent project state — timestamped context, retry lists, up to 200 concurrent targets. ASSESSMENT: this is AI assistance across research, targeting, and retry. It is not a claim that a model discovered the zero-days. The bugs were vendor-confirmed and emergency-patched before the 31 August mass run. The AI layer is speed and concurrency.
Artifactory. Wiz: multiple actors chained CVE-2026-42018 (anonymous token even with anonymous access disabled) and CVE-2026-42016 (token-scope not checked) against self-hosted instances between 15 August and 8 September. Persistence via Groovy plugins, shell via plugin endpoints, Rust backdoors. CVE-2026-82329 (unauth admin under default config) was already KEV’d 2 September. Cloud Artifactory is JFrog’s problem. Self-hosted is yours.
UNKNOWN a single actor behind the KEV pile. Do not invent one. The shared fact is internet-facing enterprise middleware, not a merger of crews.
4. Vulnerabilities to prioritize
Sequence by reachability and forensic-triage, not by CVE count.
- On-prem Cisco FMC — listed hotfixes for CVE-2026-20079 / CVE-2026-20316. Hunt
package_info.pl /var/tmp/license.tmpfirst. Cisco’s hardening bundle is due the week of 14 September; do not wait for it if the hotfix is already sitting in the advisory. Management interface off the internet. - PaperCut NG/MF — QA’d maintenance 26.0.5 / 25.0.13 / 24.1.10, which replace Emergency Patch Releases 1–3. If the Application Server answered from the internet after 27 August: hunt
pc-app.exe→cmd.exe, hive dumps underC:\Windows\Temp\pc-*.hiv, SimpleHelp “Remote Access Service,” Ligolo underC:\ProgramData,Administrator17. Firewall the Application Server. Cloud PaperCut is not this product. - Self-managed GitLab — 19.1.8 / 19.2.6 / 19.3.2. Hunt HTTP POST to
/api/v4/projects/{id}/repository/commits/with afile.pathparameter. This is a secrets-read, not claimed unauthenticated RCE. Rotate tokens, CI variables, deploy keys, and runner credentials if the instance was internet-facing after 10 September. GitLab.com and Dedicated are out of scope. - ScreenConnect — 26.6.5, then reinstall host clients and update access agents. Cloud “no action” is server-side only. Hunt
wscript.exechildren ofScreenConnect.WindowsClient.exeand1.vbs–4.vbs. This is not CVE-2024-1709. - N-central — 2026.3.1.14 (Hotfix 4) for CVE-2026-86218. Last week this was a disputed in-the-wild. This week it is KEV with forensic triage and an 11 September federal clock. Audit admin accounts created since 1 August. Pull internet-facing N-central off WAN.
- Magento / Adobe Commerce — VULN-39341 (APSB26-146) and encryption-key plus credential rotation at every upstream (Stripe, Braintree, Adyen, PayPal, deploy keys, GraphQL tokens). Patch without rotation is not remediation. Sansec: two operators, Rust implant renaming itself (
[kworker/u:8:0]→fc-cache→chronyd), C2 onto NTP-shaped UDP. - FortiOS CVE-2025-25249 — patched in January; KEV’d this week because PivotC2 is live. CAPWAP
cw_acd/ UDP 5246. Fixed floors include FortiOS 7.6.4 / 7.4.9 / 7.2.12 / 7.0.18. Assume config and credential harvest on any box that was internet-reachable on 5246. - NetScaler CVE-2026-19490 — 14.1-73.32+ / 13.1-63.21+ (and listed FIPS). No workaround. Previdian: exploit-shaped traffic from 3 September. Gateway or AAA virtual-server configs.
- Check Point 85102 / 85103 — LivePatch Take 24 on R81.20 / R82 / R82.10, or the listed Jumbo takes. Take 18 is not Take 24. R82.20 is not affected. EoS R80–R81.10 has no LivePatch.
- Self-hosted Artifactory — branch-correct fixed builds for 42018 / 42016 / 82329. Hunt new admin accounts, Groovy plugins, unexpected reverse shells. Due 25 September is not permission to wait.
- Windows September cumulatives — CVE-2026-81963 (Update Stack link-following) and CVE-2026-85880 (ALPC heap overflow). Both Important / 7.8 / Exploitation Detected / KEV due 22 September / forensic triage No. They turn a phished user into SYSTEM. They are not remote worms.
- Chrome / Edge Chromium — CVE-2026-87491 (V8 OOB write, KEV 9 September) on top of last week’s CVE-2026-85046. Forced current stable, not next month’s ring.
No invented CVEs. MikroTik RouterOS (CVE-2026-67277 / CVE-2026-86060, CERT.PL “MikroTrick” since 2 September) is an IT-to-OT edge path; the OT read is in [this week’s weekly OT](/posts/2026-09-11-weekly-ot-m580-reyrolle-mikrotik/).
5. Identity / cloud / enterprise
The identity story this week is not a new AiTM kit. It is what a print server and a firewall manager do to Active Directory.
PaperCut NG/MF on Windows runs as SYSTEM and is usually domain-joined. GreyNoise’s 12 domain-admin outcomes and the seven-minute high-school case are the identity incident. Hunt LSASS, hive dumps, and newly created privileged accounts — not just the PaperCut version string.
FMC credential theft (users.auth_data) plus Qilin’s LDAP/Kerberos/SMB/WinRM forwarding is the other identity incident. A SOCKS tunnel off the management plane is an alternate path into the IdP. Conditional Access that ignores a tunnel sourced from a “trusted” management VLAN will keep losing.
Last week’s standing war — BigBear 2.0, Knight Office, stolen M365 sessions — did not end. It was quieter in primary reporting than the KEV pile. KnowBe4 described Direct Send abuse for internal-looking M365 mail; that is REPORTED tradecraft, not this week’s lead. Revolut’s 14 September disclosure is social engineering via a fraudulent government data request on a legitimate-looking domain, not a core-banking compromise. Do not mash it into Entra.
Non-human identities on GitLab and Artifactory — CI tokens, deploy keys, package-registry credentials, Groovy plugin exec — are the cloud-adjacent blast radius of the two DevOps KEVs. Rotate them if the box was reachable.
6. Ransomware / criminal activity
CONFIRMED by Talos: Qilin affiliate activity (UAT-11988) on FMC via CVE-2026-20316. That is criminal encryption staged from the firewall manager. It is not a new ransomware family.
REPORTED SOCRadar’s PivotC2 cluster as financially motivated, with US intrusions moving to AD dumps, RDP pass-the-hash, and Exchange PST exfil to object storage. Treat the 178-infection figure as SOCRadar’s census, not CISA’s.
PaperCut’s first-wave post-exploit picture from the vendor included SimpleHelp and AnyDesk. Second-wave, per PaperCut and GreyNoise, was more sophisticated. Ransomware-use on the PaperCut KEVs remains Unknown in the catalog. Domain admin on a school district print server is still a ransomware precondition.
StyleSmuggler’s Rust implant and PHP web shell are commerce persistence, not a named ransomware crew. Manchester Airports Group and Rhysida/Berlin were last week’s extortion notes; they did not grow a new technical increment in this window.
Do not convert an IT compromise at a manufacturer or a hospital into confirmed OT impact. No primary source this week documented encryption of a controller or a safety system.
7. Defensive priorities
- Internet-facing FMC, N-central, ScreenConnect clients, PaperCut Application Server, self-managed GitLab, Magento, FortiOS CAPWAP, NetScaler Gateway/AAA, Check Point VPN. If it administers other boxes and it answers from WAN, it is this week’s ticket.
- Forensic triage is the instruction on Magento, N-central, FMC, NetScaler, Fortinet, ScreenConnect, GitLab, and MikroTik 86060. Patching without the hunt is how you leave
license.tmp,1.vbs, a Groovy plugin, or a Magentochronydimplant in place. - PaperCut: maintenance release and AD hunt. Education-sector print is over-represented in GreyNoise’s 440.
- Magento: hotfix and key/credential rotation at the source.
- ScreenConnect: 26.6.5 does not refresh the host client by itself. Cloud banners that say “no action” are about the server.
- Windows September cumulatives for the two KEV EoPs, then DNS / Netlogon / Exchange / SharePoint by reachability. Do not let 974 CVEs postpone the control plane.
- Forced Chromium current stable.
8. What changed from last week
Last week’s [weekly IT](/posts/2026-09-07-weekly-it-rmm-identity-browser/) was N-central (four hotfixes in five weeks, CVE-2026-86218 still disputed in production), Chrome CVE-2026-85046 as the sixth in-the-wild of 2026, BigBear 2.0 / Knight Office session theft, and Magento StyleSmuggler with no vendor patch.
This week those open items closed in the wrong direction:
- CISA put 86218 on KEV on 8 September (due 11 September, forensic triage Yes). Last week’s “treat as exploited until telemetry says otherwise” is now the catalog.
- Adobe shipped APSB26-146 / CVE-2026-75650 and CISA KEV’d it the next day. The hole has a lever. Stores that were internet-facing 4–7 September are a secrets-and-implant incident, not a patch-and-close.
- Citrix NetScaler CVE-2026-19490, which last week was a Previdian-reported candidate, is KEV with forensic triage.
- The RMM story widened: ScreenConnect client file-run (KEV due today) plus PaperCut as a domain-join print server, not just N-central.
- The edge story widened: FMC (Sandworm overlap + Qilin), FortiOS PivotC2, NetScaler, Check Point imminent, MikroTik MikroTrick.
- DevOps joined the control-plane list: GitLab file-read and Artifactory token chain.
- Identity kits were not the loudest thread. AD takeover via print and firewall-manager tunnels was.
- Patch Tuesday happened. Two local EoPs are in KEV. The count is not the story.
9. What we are watching next
Whether CISA lists Check Point 85102/85103 after the first public exploit attempt — NCSC-NL has already put a clock on it. Whether Cisco’s week-of-14-September FMC hardening release adds CVEs that change the hunt, not just the patch file. Whether GreyNoise or PaperCut publish a second-wave victim increment past 440. Whether GitLab 85706 produces a documented secrets-to-supply-chain case, which the CVSS Integrity High / Availability None vector allows without being RCE. Whether Artifactory 82329/42016/42018 get a ransomware-use flag. Whether N-central 86218 hunt notes from MSPs show admin-account creation at scale. Chromium’s next in-the-wild after 85046 and 87491.
10. RWP assessment
Confidence: High on the KEV listing set (catalog 2026.09.11), on Talos’s three FMC clusters as described, on PaperCut’s GreyNoise census as a measured campaign, and on GitLab/ScreenConnect as forensic-triage due-today items. Moderate on unifying those into a single “control-plane campaign” — the pattern is target class, not actor. Low on Check Point exploitation (vendor: none; national CERT: imminent). None claimed on OT process impact.
The week does not require a new SIEM use-case. It requires the boxes that administer other boxes to be patched, hunted, and pulled off WAN, and the IdP to assume that a print server or a firewall manager can already mint a domain admin.
This assessment covers 7–14 September 2026 and was published 14 September 2026.
Sources
- CISA — KEV catalog JSON catalogVersion 2026.09.11
- CISA — Adds four KEVs 8 September 2026
- CISA — Adds four KEVs 9 September 2026
- CISA — Adds two KEVs 10 September 2026
- CISA — Known Exploited Vulnerabilities Catalog
- CISA — BOD 26-04
- Cisco Talos — Active exploitation of Cisco Secure FMC vulnerabilities
- Cisco — Secure FMC Authentication Bypass CVE-2026-20079
- Cisco — Secure FMC Static Credential CVE-2026-20316
- GreyNoise — Agents Gone Wild
- PaperCut — Security Bulletin 27 Aug 2026
- GitLab — Critical Patch Release 19.3.2, 19.2.6, 19.1.8
- watchTowr — Rapid Reaction CVE-2026-85706
- ConnectWise — ScreenConnect 26.6.5 Security Patch
- Huntress — Rogue ScreenConnect installations, worm-like activity
- Adobe — APSB26-146 CVE-2026-75650
- Sansec — StyleSmuggler CVE-2026-75650
- Microsoft — September 2026 Security Updates
- Microsoft — CVE-2026-81963 Windows Update Stack
- Microsoft — CVE-2026-85880 Windows ALPC
- Fortinet — FG-IR-25-084 CVE-2025-25249
- SOCRadar — CVE-2025-25249 Exploitation Delivers PivotC2
- Citrix — CTX696939 NetScaler CVE-2026-19490
- Rapid7 — CVE-2026-19490
- Wiz — Artifactory under attack
- Check Point — sk1000117 CVE-2026-85102
- Check Point — sk1000118 CVE-2026-85103
- NCSC-NL — Kritieke kwetsbaarheden in Check Point VPN-producten
- N-able — N-central 2026.3 Hotfix 4 / CVE-2026-86218
- Google — Chrome 153 Stable Channel Update CVE-2026-87491
- RWP — Daily Top Cisco FMC
- RWP — Daily Top PaperCut
- RWP — Daily Top GitLab
- RWP — Daily Top ScreenConnect
- RWP — Weekly IT 7 September 2026