
PSYber360 Threat Intelligence Briefing - Sept. 21, 2026
Weekly Threat Intelligence Briefing — September 21, 2026 · Coverage window: August 31 – September 21, 2026
Thirty-one vulnerabilities entered CISA’s Known Exploited Vulnerabilities catalog over the past three weeks. Sixteen of them were firewalls, VPN gateways, identity servers, remote-management platforms and build systems. The tools that control everything else were the target.
That is the pattern worth carrying out of this window, and it is not a coincidence of timing. Attackers went where the control is. For a defense contractor, a maritime operator or any organization carrying a formal assessment boundary, the uncomfortable follow-on question is whether those tools appear anywhere in the asset inventory — because they are frequently filed as infrastructure rather than scoped as security protection assets.
Three actor clusters, one firewall management console
CVE-2026-20079 carries a CVSS of 10.0 and gives an unauthenticated remote attacker root on Cisco Secure Firewall Management Center — the console that manages the firewalls. Cisco Talos reported ongoing exploitation by three distinct clusters working the same appliance class, chained in places with CVE-2026-20316, a hard-coded password flaw KEV-listed back on July 29.
UAT-12197 (crimeware) deployed a JSP web shell into the Tomcat directory and a cmd.jar command executor, then queried the FMC user database directly for stored credentials.
UAT-11823 (state-sponsored) established Netcat reverse shells, harvested managed-device configurations, and deployed a Cyclops Blink ELF implant with DNS-over-HTTPS command and control, credential harvesting, network scanning and packet sniffing. Talos assesses this cluster as overlapping with Sandworm on the basis of that implant — an assessment of tooling overlap, not a government attribution statement.
UAT-11988 (ransomware), assessed by Talos with high confidence as a Qilin affiliate, entered through the static credential flaw, abused package_info.pl with a malicious license.tmp, mapped domain controllers, stood up a Python SOCKS5 proxy and reverse-SSH tunnels forwarding LDAP, LDAPS, Kerberos, SMB, NetBIOS and WinRM, ran impacket and Invoke-TheHash, disabled AV, and deployed Qilin.
Cisco released hotfixes for affected versions and followed with a comprehensive hardening release the week of September 16. Snort coverage is published at SIDs 66075–66080, 66883 and 66960–66961.
Sector impact. Every DIB, maritime and OT estate that segments with Cisco firewalls runs a management console that is rarely scoped as a CUI asset and always holds the keys to the segments. A nation-state implant and a ransomware affiliate reached the same box through the same door in the same window, which removes the option of treating this as an APT-only problem to defer.
The RMM platform as a supply-chain path
CVE-2026-86218 is pre-authentication remote code execution on N-able N-central, also CVSS 10.0, exploited as a zero-day. Huntress confirmed active exploitation of the platform from August 2, 2026 and identified a compromised production N-central environment in its own customer base on September 4. Post-exploitation included reconnaissance against systems and domain controllers, Cloudflare tunnels for persistence, abuse of the Take Control feature to pivot into managed endpoints, arbitrary script execution across downstream estates, and creation of administrative accounts — including accounts built by appending strings such as .invalid to known N-able email addresses.
N-able shipped four emergency hotfixes in five weeks, ending at 2026.3.1.14 (Hotfix 4), which is mandatory even for organizations already running Hotfix 3.
Sector impact. Most small and mid-tier defense suppliers do not run their own SOC — they run an MSP, and the MSP runs an RMM with agent-level execution on every endpoint in scope. A pre-auth RCE on that platform is a one-hop path into the contractor estate that bypasses every perimeter control described in the SSP. If the CMMC boundary diagram stops at the contractor’s own firewall, the RMM agent is already outside it and inside everything.
The remote-access tier went next
SonicWall SMA1000 carried a pre-authentication SSRF (CVE-2026-83548, CVSS 10.0) chained to an OS command injection in the Appliance Management Console (CVE-2026-83549). Alone, the command injection requires administrator authentication; behind the SSRF, the pair produces unauthenticated remote code execution. Exploitation was confirmed to have occurred before the September 1 public disclosure. Fixes land in 12.4.3-03526 and 12.5.0-02952.
Citrix NetScaler CVE-2026-19490 is an authentication bypass affecting NetScaler ADC configured as an AAA virtual server and NetScaler Gateway in SSL VPN, ICA Proxy, CVPN or RDP Proxy modes. Exploitation attempts matching public proof-of-concept code were observed on September 3 from three IP addresses in Australia, the United States and Germany; the researcher who documented them was explicit that this evidences attempts rather than confirmed compromise. Shadowserver tracked over 22,000 exposed NetScaler ADC appliances and nearly 1,700 Gateway instances, patch status unknown. Fortinet CVE-2025-25249 was KEV-listed the same day with the same three-day deadline.
Sector impact. SMA1000, NetScaler Gateway and FortiOS are the remote-access tier — the assets that define where the assessment boundary starts, and where maritime shoreside networks meet vessel operations. All three were KEV-listed inside a single ten-day span. Patch status on an internet-facing VPN concentrator is an inventory question before it is a patching question.
At sea: nearly twenty vessels under federal cyber-threat tracking
The VL Prosperity, a 1,093-foot Liberian-flagged crude carrier, departed Egypt’s Sidi Kerir terminal on August 1 bound for Galveston. Iran’s Mehr News Agency publicized an incident aboard the vessel on August 20 and claimed attackers reached the engine room, disrupted cooling flow, increased engine speed, tampered with fuel systems, compromised propulsion, navigation and cargo systems, and cut communications for roughly 30 hours.
A joint boarding team of USCG Cyber Command specialists, FBI Cyber Action Team operators and law enforcement conducted a four-day examination beginning August 21. Rear Admiral Amy Grable, commanding USCG Cyber Command, reported that signs of malicious cyber activity were found, and that investigators found no evidence the vessel had become unsafe to operate. A second foreign-flagged vessel was boarded in the Gulf of Mexico on August 24.
Bloomberg reported on September 16–17, citing three US officials not authorized to speak publicly, that agencies are tracking cyber threats against nearly 20 shipping vessels worldwide, jointly across the Coast Guard, FBI and DHS. CISA stated that attackers did not appear to have taken control of the targeted ships, and the Coast Guard reported no operational disruptions, vessel instability, physical danger to crews or environmental impact. Its Cyber Protection Team has run an estimated 40–50 such boardings in the past year.
Three evidentiary states sit in that account and they stay separate: the engine-room manipulation is an Iranian state-media claim; “signs of malicious cyber activity” is a USCG finding; the twenty-vessel figure is unnamed-official reporting. No party has attributed either incident, and Grable noted attribution can take weeks or months.
Sector impact. This is the scenario the USCG Marine Transportation System rule was written for, arriving with 298 days left before its July 16, 2027 Cyber Assessment, Cyber Plan and CySO deadline. A Cyber Assessment that inventories only shoreside IT does not reach the engine-room and navigation OT that federal boarding teams are examining right now.
Across the other sectors
Aviation. The extortion group FulcrumSec claimed the Manchester Airports Group breach on August 31, asserting roughly 86 GB of booking and travel data taken, theft only, with a stated intent to leak. MAG disclosed the incident on August 27, confirming access to a database hosted by a third party. MAG has not confirmed the 8.7 million figure or the volume claim.
OT and ICS. The US water and wastewater internet-facing PLC campaign remains unattributed — no FBI attribution statement and no expansion beyond seven states surfaced this window. Similarity to a known Iranian-affiliated campaign remains similarity, not evidence, and competing pro-Russian hacktivist claims are unresolved.
Healthcare. McKesson confirmed on August 31 that attackers broke into cloud-hosted accounts and exfiltrated data relating to oncology, multispecialty and medical-surgical units. ShinyHunters claims millions of rows from Snowflake and Salesforce environments obtained through phishing and social engineering; McKesson has not confirmed the volume, the affected-individual count or the reported ransom demand. Separately, SickKids confirmed on September 4 that employee and job-applicant data was accessed through a vulnerability in a third-party application on its Careers website — the vendor, application and CVE all still unnamed.
The largest Patch Tuesday on record
Microsoft’s September 8 release addressed a record 966 flaws, including 105 rated Critical, per BleepingComputer’s count. (Totals for this release vary between 964 and 974 across outlets depending on counting method.) Two were exploited zero-days: CVE-2026-81963, a Windows Update Stack link-following flaw escalating a local attacker to SYSTEM, and CVE-2026-85880, a heap-based buffer overflow in Advanced Local Procedure Call. Both were KEV-listed September 8 with fourteen-day deadlines expiring September 22.
What to do this week
Treat every Cisco Secure FMC and SCC Firewall Management instance as compromised until proven otherwise, not merely as unpatched. Apply the hotfixes and the hardening release, then hunt: JSP files in the Tomcat directory, cmd.jar, modified license.tmp, Netcat reverse shells, and unexpected OmniQuery.pl or package_info.pl execution. Deploy the published Snort coverage. Rotate every credential the FMC user database held.
Ask your MSP, in writing, which N-central build they run and when Hotfix 4 was applied. If the answer is later than September 6 or unavailable, treat the window from August 2 forward as exposed. Audit N-central accounts for unexpected creations, review UI logs for unfamiliar viewer IPs, and pull the support-service logs from managed endpoints.
Reconcile the remote-access tier in one pass — SonicWall SMA1000, NetScaler, FortiOS, FortiSwitchManager, FortiSASE, Cisco ISE and Secure Email Gateway. All carried three-day federal deadlines that have now passed.
Confirm the September 8 Windows rollup is deployed fleet-wide before end of day September 22. Both zero-days are local escalations to SYSTEM — the step between a phished user and a domain.
Put the management plane inside the assessment boundary. Firewall managers, RMM servers, identity services, backup consoles and artifact repositories control CUI-bearing assets even when they store no CUI. JFrog Artifactory alone took three KEV listings in ten days.
Maritime: scope the MTS Cyber Assessment to include engine-room, navigation and cargo OT, not shoreside IT alone.
Known Exploited Vulnerabilities added this window
Due dates below are read verbatim from the CISA KEV machine-readable catalog (catalogVersion 2026.09.18). Under BOD 26-04 deadlines are scored per entry against exposure, known exploitation, automation potential and technical impact — twenty of these carried three-day windows and eleven carried fourteen-day windows. No date here is calculated.
CVEVendor / ProductAddedDue
CVE-2026-81578 | PaperCut NG/MF | 2026-08-31 | 2026-09-14 |
CVE-2026-82078 | PaperCut NG/MF | 2026-08-31 | 2026-09-14 |
CVE-2026-48710 | Kludex Starlette | 2026-09-02 | 2026-09-16 |
CVE-2026-49869 | Kestra OSS | 2026-09-02 | 2026-09-05 |
CVE-2026-59822 | BerriAI LiteLLM | 2026-09-02 | 2026-09-16 |
CVE-2026-82329 | JFrog Artifactory | 2026-09-02 | 2026-09-05 |
CVE-2026-83548 | SonicWall SMA1000 Appliances | 2026-09-02 | 2026-09-05 |
CVE-2026-83549 | SonicWall SMA1000 Appliances | 2026-09-02 | 2026-09-05 |
CVE-2026-9586 | Sangoma Switchvox | 2026-09-02 | 2026-09-05 |
CVE-2026-85046 | Google Chromium V8 | 2026-09-04 | 2026-09-18 |
CVE-2026-75650 | Adobe Commerce and Magento | 2026-09-08 | 2026-09-11 |
CVE-2026-81963 | Microsoft Windows (Update Stack) | 2026-09-08 | 2026-09-22 |
CVE-2026-85880 | Microsoft Windows (ALPC) | 2026-09-08 | 2026-09-22 |
CVE-2026-86218 | N-able N-central | 2026-09-08 | 2026-09-11 |
CVE-2025-25249 | Fortinet (FortiOS, FortiSwitchManager, FortiSASE) | 2026-09-09 | 2026-09-12 |
CVE-2026-19490 | Citrix NetScaler ADC / Gateway | 2026-09-09 | 2026-09-12 |
CVE-2026-20079 | Cisco Secure Firewall Management Center / SCC | 2026-09-09 | 2026-09-12 |
CVE-2026-87491 | Google Chromium V8 | 2026-09-09 | 2026-09-23 |
CVE-2026-67277 | MikroTik RouterOS | 2026-09-10 | 2026-09-13 |
CVE-2026-86060 | MikroTik RouterOS | 2026-09-10 | 2026-09-13 |
CVE-2026-42016 | JFrog Artifactory | 2026-09-11 | 2026-09-25 |
CVE-2026-42018 | JFrog Artifactory | 2026-09-11 | 2026-09-25 |
CVE-2026-84869 | ConnectWise ScreenConnect | 2026-09-11 | 2026-09-14 |
CVE-2026-85706 | GitLab CE / EE | 2026-09-11 | 2026-09-14 |
CVE-2026-76461 | Cisco Secure Email Gateway | 2026-09-14 | 2026-09-17 |
CVE-2026-58704 | Google Pixel | 2026-09-16 | 2026-09-19 |
CVE-2026-76460 | Cisco Identity Services Engine | 2026-09-16 | 2026-09-19 |
CVE-2026-87886 | Acronis Backup (cPanel/WHM, Plesk) | 2026-09-16 | 2026-09-19 |
CVE-2025-39682 | Linux Kernel (TLS receive path) | 2026-09-18 | 2026-09-21 |
CVE-2025-39964 | Linux Kernel (AF_ALG race) | 2026-09-18 | 2026-09-21 |
CVE-2026-53266 | Linux Kernel (ebtables SNAT) | 2026-09-18 | 2026-09-21 |
The bottom line
Security brings compliance. Compliance does not bring security. A boundary that excludes the tools controlling the boundary is a diagram, not a defense.
PSY Logistics Technology Partners advises defense contractors, MTSA-regulated operators and regulated enterprises on CMMC readiness, assessment scoping and vCISO program leadership. If this briefing raised a question about your own boundary, that is the conversation worth having.
Craig Wood | CISM | CCA Lead Assessor | ISO/IEC 27001 Senior Lead Auditor | CEO, PSY Logistics Technology Partners | CMMC | Maritime Cybersecurity | vCISO | DIB