
Weekly Threat Intelligence Briefing — September 07, 2026
Weekly Threat Intelligence Briefing · Monday, September 7, 2026
The Sector Doesn't Matter This Week — Print Servers, VPN Gateways, and AI Proxies All Made KEV
Weekly Threat Intelligence Briefing | Monday, September 7, 2026
Three unrelated product categories, three actively exploited chains, one week. Whatever sector you're in — defense, maritime, aviation, healthcare — one of this week's KEV additions sits somewhere in your vendor stack.
PaperCut NG/MF — pre-auth RCE via a chained flaw pair. An authentication bypass in the web management interface plus unsafe dynamic class loading in the database utilities gives an unauthenticated attacker remote code execution on the PaperCut Application Server. KEV-listed August 31. Over 800 instances remain exposed to the internet, and incident responders are already reporting credential theft, Meterpreter deployment, and direct database exfiltration — not proof-of-concept activity. PaperCut flaws have delivered LockBit before.
Sector impact: Print management sits outside almost every SSP asset inventory — DIB and enterprise clients alike. Healthcare and education deploy PaperCut at scale too; the exposure isn't sector-specific, the blind spot is.
SonicWall SMA1000 — the third zero-day chain since December. A maximum-severity pre-auth SSRF chained with a post-auth command injection in the appliance management console produced unauthenticated remote code execution. SonicWall confirmed active exploitation September 1; CISA gave federal agencies a three-day window. This follows a root-privilege chain in December and a custom-malware campaign in July — three distinct incidents against the same platform in nine months.
Sector impact: SMA1000 is perimeter infrastructure for mid-to-large enterprises, MSSPs, and government agencies — maritime terminal operators and DIB primes both run SonicWall SSL VPN. Patching this chain closes today's door; it doesn't tell you whether an earlier one was already used.
📌Watch: three of the seven vulnerabilities CISA added September 2 hit AI infrastructure directly — an auth bypass in the LiteLLM AI gateway, a request-smuggling flaw in the framework underneath LiteLLM, vLLM, and MCP servers, and a default-config bypass in JFrog Artifactory. First KEV batch where AI components account for nearly half the additions.
Sector impact: Any organization running an internal AI gateway or LLM proxy — including OT vendors whose remote-support tooling now routes through one. If it's not in your SSP boundary yet, this is the week it should be.
Quick hits by sector: Maritime — no direct hit this window, but the MTS Cyber Plan clock keeps running (~10 months to July 16, 2027). Aviation — Manchester Airports Group's 8.7M-record breach is still open, no attribution yet. Healthcare — five separate ransomware-adjacent breach disclosures this week alone, no single shared vector. OT/ICS — quiet on new exploitation, but the AI-gateway KEV additions above are the OT-vendor-remote-access story most people will miss.
What this means: if PaperCut or SonicWall SMA1000 sit anywhere in your environment, patch and hunt — assume prior exposure, don't just close the current CVE. If your teams run an AI gateway, it belongs in your SSP asset boundary today. This week's deadlines (Sept 5 and Sept 16) apply whether or not you're a federal agency.
Security brings compliance. Compliance does not bring security.
Which of these three — print server, VPN gateway, or AI proxy — is furthest outside your inventory right now?