September 17, 2026 | Jonathan Brown

Command View


Verification cutoff

September 17, 2026, 13:15 UTC.

This edition covers material verified through the cutoff above. Product/version boundaries, CVE designations, remediation levels, and exploitation claims are tied to named vendor, government, or research sources. Confirmed exploitation, observed probes, honeypot activity, and exposure risk are kept distinct.

Priority posture

  • RED: Cisco reports active exploitation of the unauthenticated Cisco ISE authentication bypass, and active exploitation of the unauthenticated Cisco Secure Email Gateway SQL-injection-to-root-RCE vulnerability. CISA has added both CVE-2026-76460 and CVE-2026-87886 to the Known Exploited Vulnerabilities catalog; GitLab confirms CVE-2026-85706 is KEV-listed, and Acronis reports limited, targeted exploitation of its backup-plugin flaw.
  • AMBER: WSO2 CVE-2026-5430 has been exploited in honeypot observations through forged JWTs, but no production victim set is publicly confirmed. BIND 9 has 14 newly disclosed security issues affecting DNS infrastructure; no exploitation is known. Oracle’s September Critical Security Patch Update (CSPU) contains 673 new patches, including large remote-attack surface in E-Business Suite and Fusion Middleware, without a vendor claim that the new CSPU issues are being exploited.
  • WATCH: CHOSEN BRICK is a credible, targeted Iranian spyware campaign against dissidents, activists, journalists, and high-risk staff using Windows endpoints and social-message impersonation. U.S. and Canadian seizure of NightmareStresser domains disrupts one DDoS-for-hire service but does not remove residual booter capacity.
  • CONTEXT: No newly verified destructive OT event, safety-system outage, or sustained interruption of an essential service met the inclusion threshold by the cutoff. Several IT, identity, email, hosting, API, DNS, and DevOps control planes nevertheless have direct paths to critical-service disruption or sensitive-data loss.

Today’s decisions

  • RED — Cisco ISE owners: identify every ISE and ISE-PIC node, restrict management/control-plane reachability with iACLs immediately, inspect access.log on every node and external network/firewall telemetry, then upgrade ISE/ISE-PIC to 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, or 3.5 Patch 4 as applicable. Treat evidence of access as a potential root-level compromise; re-image and restore from a trusted configuration backup where warranted.
  • RED — Email-security owners: patch Cisco Secure Email Gateway to AsyncOS 15.5.5-014, 16.0.4-302, or 16.5.0-780 as applicable; restrict appliance access, separate mail and management interfaces, preserve external logs, and review mail_logs for suspicious SQL activity. If a device was contacted by Cisco or shows evidence of compromise, rebuild securely and renew credentials and cryptographic material.
  • RED — Hosting and backup owners: inventory Acronis Backup plugin for cPanel & WHM and the Acronis Backup extension for Plesk on Linux. Upgrade cPanel/WHM to 1.9.3 HF3, build 1.9.3.1021, and Plesk to the fixed 1.8.11, build 638 level; investigate the low-privilege entry path before trusting backup integrity.
  • RED — DevOps and platform owners: upgrade self-managed GitLab CE/EE to 19.1.8, 19.2.6, or 19.3.2. Hunt repository-commits API requests for local-file read attempts, especially gitlab.yml and metadata.path, and rotate exposed CI/CD, cloud, signing, and deployment secrets after assessing logs. GitLab.com and GitLab Dedicated are reported patched.
  • AMBER — API platform owners: apply WSO2’s exact update level or the vendor’s open-source fixes for CVE-2026-5430. Review authentication, token, application, subscription, credential, and secret-access logs for unsupported JWT algorithms and unexpected administrative activity.
  • AMBER — DNS and infrastructure owners: patch BIND 9 to 9.20.29 or 9.21.26 according to the supported branch. Review DNSSEC, DNS-over-HTTPS, IXFR, TSIG, and recursive exposure while changes are staged; protect authoritative and recursive services from avoidable internet reachability.
  • WATCH — Endpoint, executive-protection, and security-awareness owners: brief high-risk staff on CHOSEN BRICK impersonation through WhatsApp or Telegram and fake legitimate applications or MRI files. Hunt the named persistence, Defender-exclusion, C2, and exfiltration indicators on corporate and at-risk personal Windows devices.

Threat and Resilience Ledger


[RED] — Identity and access control | Global — Cisco ISE authentication bypass is under active exploitation

Cisco’s September 16 advisory assigns CVE-2026-76460, CVSS 10.0, to an insufficient-authentication flaw in an API used by Cisco Identity Services Engine and ISE-PIC; the products are affected regardless of device configuration. An unauthenticated remote attacker can send a crafted request to bypass the web-based management interface and obtain unauthorized access; Cisco states that successful exploitation may yield root command execution and that its PSIRT is aware of active exploitation. Cisco lists fixed floors of ISE/ISE-PIC 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4; ISE 3.0 is at end of software maintenance. CISA added the CVE to KEV on September 16 with a three-calendar-day FCEB remediation deadline reported as September 19 under the current risk-based CISA framework, BOD 26-04. Restrict management/control-plane traffic with iACLs, inspect every node’s ise-kong/access.log, correlate external uploads/downloads, and re-image affected nodes if compromise is suspected because root access can conceal evidence.

Evidence: confirmed; Cisco PSIRT confirms active exploitation.
Attribution: unknown.
Confidence: high.
Uncertainty: victim population, initial attacker objective, and persistence after root access.
Sources: Cisco, “Cisco Identity Services Engine Authentication Bypass Vulnerability,” September 16, 2026; CISA, “CISA Adds Two Known Exploited Vulnerabilities to Catalog,” September 16, 2026; SecurityWeek, “Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day,” September 17, 2026.

[RED] — Messaging and security edge | Global — Cisco Secure Email Gateway SQL injection enables root-level execution

Cisco’s September 14 advisory assigns CVE-2026-76461, CVSS 9.8, to an SQL-injection flaw in AsyncOS email parsing. An unauthenticated remote attacker can send a crafted email containing malicious SQL statements; successful exploitation can execute arbitrary SQL and reach root command execution on the underlying operating system. Physical and virtual Secure Email Gateway appliances are affected regardless of configuration; Cisco Secure Email and Web Manager and Secure Web Appliance are not affected by this advisory. Cisco lists fixed versions 15.5.5-014, 16.0.4-302, and 16.5.0-780, and says Cisco Secure Email Cloud has been upgraded to 16.5.0-780. Cisco PSIRT became aware of active exploitation in September and directly contacted cloud customers where possible-compromise indicators were identified. Preserve and review mail_logs, including for suspicious SQL patterns, use external telemetry because root access can erase local evidence, and rebuild and rotate credentials/materials when compromise is suspected.

Evidence: confirmed; Cisco PSIRT confirms active exploitation.
Attribution: unknown.
Confidence: high.
Uncertainty: breadth of appliance compromise and attacker persistence outside Cisco’s contacted cloud population.
Sources: Cisco, “Cisco Secure Email Gateway SQL Injection Vulnerability,” September 14, 2026; SecurityWeek, “Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation,” September 15, 2026; Rapid7, “ETR: CVE-2026-76461 Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild,” September 2026.

[RED] — DevOps and software-supply-chain control plane | Global — GitLab path traversal exposes arbitrary server files

GitLab’s September 10 critical patch release fixes CVE-2026-85706, assigned CVSS 10.0 with the published vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N, in the repository commits API. Under certain conditions, an unauthenticated user could read arbitrary files from a GitLab server because of improper path confinement and missing authentication enforcement. The 10.0 reflects GitLab’s published high-integrity and changed-scope metrics; a narrower pure-file-read vector would score lower. Affected CE/EE ranges are all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2. GitLab says the CVE is in CISA KEV and released three detections for self-managed instances, including attempts to read gitlab.yml, use metadata.path, or otherwise request local files. WatchTowr reports reproducing the behavior and seeing matching probes in honeypots, consistent with rapid indiscriminate exploitation. Public self-managed instances are the immediate concern: arbitrary file reads can expose credentials, runner tokens, deployment keys, source, and configuration that enable follow-on compromise. Patch, hunt, preserve evidence, and rotate secrets if an instance was exposed or targeted.

Evidence: confirmed vulnerability and KEV status; demonstrated and observed exploitation attempts.
Attribution: unknown.
Confidence: high.
Uncertainty: number of compromised self-managed instances and whether exposed files were used for follow-on access.
Sources: GitLab, “GitLab Critical Patch Release: 19.3.2, 19.2.6, 19.1.8,” September 10, 2026; WatchTowr, “Rapid Reaction: GitLab Critical Path Traversal Vulnerability CVE-2026-85706,” September 2026; CISA, “CISA Adds One Known Exploited Vulnerability to Catalog,” September 11, 2026; Canadian Centre for Cyber Security, “GitLab Security Advisory AV26-917,” September 2026.

[RED] — Hosting and backup integrity | Global — Acronis Linux plugin privilege escalation is being used in targeted attacks

Acronis identifies CVE-2026-87886, CVSS 7.8, as a local privilege-escalation flaw caused by insecure file permissions. It affects Acronis Backup plugin for cPanel & WHM on Linux before build 1.9.3.1021, fixed in 1.9.3 HF3, and the Acronis Backup extension for Plesk on Linux before build 1.8.11.638. A low-privilege attacker with local access can escalate privileges and potentially run arbitrary code, threatening hosting control, customer data, and the confidentiality and integrity of backup operations. Acronis reports exploitation in the wild in limited, targeted attacks but provides no public actor, victim, entry-path, or objective details. CISA added the CVE to KEV on September 16 with a three-calendar-day FCEB remediation deadline reported as September 19 under BOD 26-04. Patch both plugin families, identify the first local foothold, verify backup immutability and restore points from independent telemetry, and treat unexplained administrative or backup changes as a possible incident.

Evidence: confirmed vulnerability; Acronis reports limited, targeted in-the-wild exploitation.
Attribution: unknown.
Confidence: high for affected builds and remediation; moderate for campaign scope.
Uncertainty: initial access, victim count, and whether backup sets were altered or exfiltrated.
Sources: Acronis, “SEC-10986 / CVE-2026-87886,” September 2026; Acronis, “Acronis Backup plugin for cPanel & WHM 1.9.3 HF3,” September 2026; CISA, “CISA Adds Two Known Exploited Vulnerabilities to Catalog,” September 16, 2026; The Hacker News, “Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks,” September 16, 2026.

[AMBER] — API identity and management plane | Global — WSO2 JWT algorithm bypass is attracting forged-token attempts

WSO2’s advisory assigns CVE-2026-5430, CVSS 10.0 in multi-tenant deployments and 9.8 in single-tenant deployments, to a JWT authentication bypass when a token is signed with an unsupported algorithm. Affected products include API Control Plane 4.6.0/4.5.0, API Manager 4.6.0 through 4.1.0, Traffic Manager 4.6.0/4.5.0, and Universal Gateway 4.6.0/4.5.0. WSO2 describes possible administrative-account compromise and full account takeover. WatchTowr reported a first exploitation attempt in its honeypot on September 13 using forged JWTs and observed an apparent objective of reaching API backends and credentials; one attacker initially targeted the wrong product, but the payload worked against WSO2. Apply the exact WSO2 update level or open-source fixes, then audit token validation, administrative access, API subscriptions, consumer keys, and secrets. This remains AMBER because the public evidence confirms malicious attempts in a honeypot, not a confirmed production-victim set.

Evidence: confirmed vulnerability; demonstrated/observed honeypot exploitation attempt.
Attribution: unknown.
Confidence: high for technical impact and fixed update levels; moderate for campaign breadth.
Uncertainty: production victim count, attacker identity, and whether backend credentials were obtained.
Sources: WSO2, “Security Advisory WSO2-2026-5328/CVE-2026-5430,” May 3, 2026; SecurityWeek, “Enterprises Warned of Attacks Exploiting WSO2 Vulnerability,” September 16, 2026.

[AMBER] — Core network services | Global — BIND 9 publishes 14-fix security release for DNS resilience

The Internet Systems Consortium published 14 BIND 9 security advisories on September 16. The set includes seven high-severity remote denial-of-service conditions, including CVE-2026-80274, CVE-2026-76163, CVE-2026-19666, CVE-2026-81563, CVE-2026-77692, CVE-2026-19667, and CVE-2026-81736, plus medium-severity issues involving cache poisoning, CPU exhaustion, packet loss, and zone-data handling. One example, CVE-2026-77692, can allow an unauthenticated remote attacker to crash named with a single DNS-over-HTTPS SIG(0) request. ISC’s fixed release floors are BIND 9.20.29 and 9.21.26. No exploitation is known in the reviewed sources. DNS operators should patch authoritative and recursive fleets, verify branch support, and review DNSSEC, DoH, IXFR, and TSIG exposure because service instability or poisoned responses can amplify downstream outages even without a confirmed intrusion.

Evidence: confirmed vendor security release; no known exploitation reported.
Attribution: not applicable.
Confidence: high.
Uncertainty: asset exposure and the time required for exploit development against individual DNS configurations.
Sources: Internet Systems Consortium, “All BIND Advisories,” September 16, 2026; ISC, “BIND 9 Release Notes,” September 16, 2026; SecurityWeek, “ISC Patches 14 Vulnerabilities in BIND 9 Security Update,” September 16, 2026.

[AMBER] — Enterprise middleware and business systems | Global — Oracle’s September CSPU expands urgent inventory-driven remediation

Oracle’s September 2026 Critical Security Patch Update (CSPU) provides 673 new security patches across its product portfolio. Oracle E-Business Suite accounts for 159 patches, including 19 remotely exploitable without authentication, while Fusion Middleware accounts for 153, including 78 remotely exploitable without authentication. The risk is highly inventory-dependent: the update spans database, middleware, identity, enterprise applications, communications, banking, utility-management, and other enterprise components, and unsupported versions may remain exposed. Oracle recommends prompt application to supported versions, but the CSPU does not state that these newly patched issues are under active exploitation. Prioritize internet-reachable identity and middleware planes, map exact product/version combinations to Oracle’s risk matrices, stage emergency changes for externally reachable systems, and validate compensating controls where patching cannot be completed immediately.

Evidence: confirmed vendor patch release; no confirmed exploitation claim for the new CSPU issues.
Attribution: not applicable.
Confidence: high for patch counts and vendor remediation guidance; moderate for local exposure until inventory is complete.
Uncertainty: organization-specific product population, unsupported-version exposure, and exploitability of individual deployments.
Sources: Oracle, “Critical Security Patch Update Advisory - September 2026,” September 15, 2026; SecurityWeek, “Oracle Patches 800+ Vulnerabilities in September 2026 Security Update,” September 16, 2026.

[WATCH] — Endpoint and identity targeting | Europe / North America / Middle East — CHOSEN BRICK spyware targets high-risk users through trusted-contact impersonation

A joint NCSC, FBI, and AIVD advisory published September 15 describes CHOSEN BRICK, a Windows malware operation used worldwide since at least 2025 against dissidents, activists, and journalists, with likely repression objectives. Operators use WhatsApp or Telegram impersonation and fake legitimate applications such as Pictory, RunwayML, Norton, Telegram, Adobe Flash Player, or KeePass; malicious MRI files are also reported. The malware persists through HKCU\Software\Microsoft\Windows\CurrentVersion\Run, may add Microsoft Defender exclusions, uses a per-victim Telegram bot for command and control, and can collect system/process data, screenshots, microphone audio, browser and messaging data, email, and files before exfiltration through Telegram and cloud/proxy services. No automated lateral movement was observed in the advisory, but the ability to download further payloads and wipe systems creates an escalation path on corporate or personal devices used by high-risk staff. Hunt both corporate and at-risk personal Windows endpoints, enforce phishing-resistant MFA and application allowlisting, and investigate the listed persistence and infrastructure indicators.

Evidence: confirmed joint-government technical advisory and observed malware behavior.
Attribution: public assessment: Iranian state-linked actors.
Confidence: high for malware behavior and targeting; moderate for full victim population.
Uncertainty: operator identity, campaign scale, and whether access to targeted staff has been used to reach organizational networks.
Sources: NCSC, “Iranian Cyber Targeting of Dissidents, Activists and Journalists,” September 15, 2026; NCSC, “UK and Allies Expose Spyware Used by Iranian State Actors,” September 15, 2026; FBI Internet Crime Complaint Center, “CHOSEN BRICK,” September 15, 2026; Reuters, “UK, US and Netherlands issue advisory on Iran spyware,” September 15, 2026.

[WATCH] — Availability and DDoS ecosystem | Global / North America — NightmareStresser domains seized under Operation PowerOFF

The U.S. Department of Justice announced September 15 that the FBI, with the Royal Canadian Mounted Police, obtained court-authorized seizure of domains associated with NightmareStresser, a DDoS-for-hire service linked to hundreds of thousands of actual or attempted attacks worldwide since 2022. Victims included educational institutions, government agencies, and gaming targets; the service could degrade internet performance and disrupt connections. The action reportedly seized more than 100 domains and follows prior Operation PowerOFF prosecutions. This is a confirmed law-enforcement disruption, not evidence that the broader DDoS-for-hire market has disappeared. Critical-service operators should maintain upstream filtering, rate limiting, provider escalation paths, and tested continuity procedures while watching for residual services, copycats, or retaliatory traffic.

Evidence: confirmed law-enforcement seizure and charging activity.
Attribution: not applicable to the broader residual DDoS ecosystem.
Confidence: high for the seizure; low for any forecast reduction in attack volume.
Uncertainty: residual infrastructure, replacement services, and whether seized customers or operators redirect activity.
Sources: U.S. Department of Justice, “FBI Seizes DDoS-for-Hire Domains as Part of Continuing District of Alaska Crackdown on Booter and Counterfeit Services,” September 15, 2026; The Hacker News, “U.S. Seizes NightmareStresser Domains,” September 15, 2026.

Defensive Posture Changes


  • Control-plane isolation: treat identity, email-security, API, DevOps, hosting, and DNS management interfaces as incident-sensitive assets. Remove unnecessary internet reachability and verify that management traffic traverses controlled paths.
  • Patch-to-investigate: for Cisco ISE, Cisco Secure Email Gateway, GitLab, and Acronis, patching does not close the response. Preserve external logs, examine credential and token use, and rotate secrets or cryptographic material where exposure is plausible.
  • Detection priorities: hunt ISE access-log anomalies, Cisco mail_logs SQL patterns, GitLab repository-commits path traversal attempts, Acronis local privilege changes, WSO2 unsupported-algorithm JWTs, and CHOSEN BRICK persistence or Defender-exclusion changes.
  • Resilience checks: validate independent backup and restore points, DNS failover and DNSSEC behavior, API gateway isolation, email-routing continuity, and DDoS-provider escalation contacts.

Regional and Sector Pulse


North America / Global

The most urgent operational exposure is global rather than geographically bounded: Cisco identity and email gateways, self-managed GitLab, Acronis hosting plugins, WSO2 API platforms, and BIND DNS are widely deployed enterprise or service-provider components. The DOJ’s NightmareStresser seizure is a U.S.-led action against global infrastructure. No reviewed source reports a new North American critical-service outage tied to these items.

Europe

The NCSC/AIVD/FBI CHOSEN BRICK advisory identifies the UK, United States, and Netherlands among affected or targeted geographies and emphasizes dissidents, activists, journalists, and high-risk users. This is a targeted endpoint and identity threat; the advisory does not establish automated lateral movement or a broad European infrastructure compromise.

Middle East

CHOSEN BRICK is publicly assessed as Iranian state-linked activity and carries a repression-oriented targeting profile. Organizations with staff, contractors, or partners in the region should treat personal-device compromise as an identity and access risk even when corporate endpoints show no malware.

Sector emphasis

Highest immediate concern is for identity and access, managed service providers, hosting and backup providers, email-security operators, software development and CI/CD, API platforms, DNS operators, and enterprise middleware. No source reviewed establishes direct OT or safety-system compromise; any such claim requires separate incident evidence.

Vulnerability and Supplier Watchlist


  • Cisco ISE / ISE-PIC — CVE-2026-76460: CVSS 10.0; unauthenticated remote authentication bypass with possible root execution; active exploitation. Fixed floors: 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4. ISE 3.0 is end of software maintenance.
  • Cisco Secure Email Gateway — CVE-2026-76461: CVSS 9.8; unauthenticated crafted-email SQL injection leading to root OS command execution; active exploitation. Fixed: AsyncOS 15.5.5-014, 16.0.4-302, or 16.5.0-780.
  • GitLab CE/EE — CVE-2026-85706: GitLab-published CVSS 10.0, vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N; unauthenticated arbitrary file read via repository commits API. Affected: 18.7 to before 19.1.8, 19.2 to before 19.2.6, and 19.3 to before 19.3.2. Fixed: 19.1.8, 19.2.6, 19.3.2. CISA KEV-listed.
  • Acronis Backup plugin / extension — CVE-2026-87886: CVSS 7.8; local privilege escalation from insecure file permissions; limited targeted in-the-wild exploitation. Fixed cPanel/WHM: 1.9.3 HF3, build 1.9.3.1021. Fixed Plesk Linux extension: 1.8.11, build 638. CISA KEV-listed.
  • WSO2 API products — CVE-2026-5430: CVSS 10.0 multi-tenant / 9.8 single-tenant; JWT authentication bypass and possible account takeover. Apply the WSO2 product-specific update levels or public fixes; a generic version-only statement is insufficient.
  • ISC BIND 9: 14 security issues published September 16, including seven high-severity remote DoS conditions. Fixed releases: 9.20.29 and 9.21.26. No known exploitation in reviewed sources.
  • Oracle September 2026 CSPU: 673 new patches; prioritize exact inventory matches for E-Business Suite, Fusion Middleware, database, identity, communications, banking, and utility-management deployments. Oracle’s update is not treated as a confirmed-exploitation event.

Outlook and Uncertainty


Next 24 hours

Expect rapid scanning and exploit adaptation against Cisco ISE, Cisco Secure Email Gateway, GitLab, and Acronis. Monitor for vendor revisions, emergency guidance, detection content, confirmed victim notifications, and public exploit details. Watch WSO2 for production-victim confirmation, BIND for exploit development, and CHOSEN BRICK for additional infrastructure or targeting indicators. Verify that CISA item-specific alert pages remain available through forwarding-safe news URLs and do not substitute a generic KEV landing page.

What is not known

The public record does not establish the Cisco ISE or Secure Email Gateway victim populations, the full GitLab compromise set, or whether Acronis attackers changed or exfiltrated backup data. It does not identify the WSO2 actor or production victims, the BIND exploitability of each local configuration, or the Oracle CSPU exposure of any particular organization. CHOSEN BRICK’s full operator identity, scale, and enterprise-network reach remain unresolved. NightmareStresser seizure effects on the wider DDoS market are unknown.

Trigger for escalation

Escalate immediately on any Cisco ISE or Secure Email Gateway indicator, unexplained root-level change, or contacted-customer notice; GitLab file-read attempt, secret use, or unauthorized repository/runner activity; Acronis local privilege escalation or backup alteration; WSO2 forged-token or administrative anomaly; BIND crash, DNSSEC failure, or unexplained authoritative/recursive behavior; CHOSEN BRICK persistence on a staff device; or DDoS traffic that threatens essential-service availability. Promote WSO2 or BIND from AMBER to RED on confirmed production exploitation or material service impact.

Source Register — September 17, 2026


URLs are grouped by story and shown in full. This register uses item-specific CISA news-alert URLs rather than the generic Known Exploited Vulnerabilities landing page because CISA pages do not reliably forward from bordercybergroup.com.

Cisco ISE / CVE-2026-76460

Cisco advisory — Cisco Identity Services Engine Authentication Bypass Vulnerability:

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5

CISA news alert — CISA Adds Two Known Exploited Vulnerabilities to Catalog:

https://www.cisa.gov/news-events/alerts/2026/09/16/cisa-adds-two-known-exploited-vulnerabilities-catalog

SecurityWeek — Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day:

https://www.securityweek.com/active-exploitation-triggers-emergency-patch-for-cisco-ise-zero-day/

Cisco Secure Email Gateway / CVE-2026-76461

Cisco advisory — Cisco Secure Email Gateway SQL Injection Vulnerability:

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX

SecurityWeek — Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation:

https://www.securityweek.com/root-rce-zero-day-in-cisco-secure-email-gateway-under-active-exploitation/

Rapid7 — ETR: CVE-2026-76461 Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild:

https://www.rapid7.com/blog/post/etr-cve-2026-76461-critical-cisco-secure-email-gateway-vulnerability-exploited-in-the-wild/

GitLab / CVE-2026-85706

GitLab — GitLab Critical Patch Release: 19.3.2, 19.2.6, 19.1.8:

https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/

CISA news alert — CISA Adds One Known Exploited Vulnerability to Catalog:

https://www.cisa.gov/news-events/alerts/2026/09/11/cisa-adds-one-known-exploited-vulnerability-catalog

WatchTowr — Rapid Reaction: GitLab Critical Path Traversal Vulnerability CVE-2026-85706:

https://watchtowr.com/intelligence/rapid-reaction-gitlab-critical-path-traversal-vulnerability-cve-2026-85706/

Canadian Centre for Cyber Security — GitLab Security Advisory AV26-917:

https://www.cyber.gc.ca/en/alerts-advisories/gitlab-security-advisory-av26-917

Acronis Backup plugin / CVE-2026-87886

Acronis advisory — SEC-10986 / CVE-2026-87886:

https://security-advisory.acronis.com/advisories/SEC-10986

Acronis update — Acronis Backup plugin for cPanel & WHM 1.9.3 HF3:

https://security-advisory.acronis.com/updates/UPD-2609-3d72-20a7

CISA news alert — CISA Adds Two Known Exploited Vulnerabilities to Catalog:

https://www.cisa.gov/news-events/alerts/2026/09/16/cisa-adds-two-known-exploited-vulnerabilities-catalog

The Hacker News — Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks:

https://thehackernews.com/2026/09/acronis-cpanel-backup-plugin.html

WSO2 API products / CVE-2026-5430

WSO2 — Security Advisory WSO2-2026-5328/CVE-2026-5430:

https://security.docs.wso2.com/en/latest/security-announcements/security-advisories/2026/WSO2-2026-5328/

SecurityWeek — Enterprises Warned of Attacks Exploiting WSO2 Vulnerability:

https://www.securityweek.com/enterprises-warned-of-attacks-exploiting-wso2-vulnerability/

ISC BIND 9

Internet Systems Consortium — All BIND Advisories:

https://kb.isc.org/docs/all-bind-advisories

ISC — BIND 9 Release Notes:

https://bind9.readthedocs.io/en/stable/notes.html

SecurityWeek — ISC Patches 14 Vulnerabilities in BIND 9 Security Update:

https://www.securityweek.com/isc-patches-14-vulnerabilities-in-bind-9-security-update/

CHOSEN BRICK / Iranian spyware

NCSC — Iranian Cyber Targeting of Dissidents, Activists and Journalists:

https://www.ncsc.gov.uk/news/iranian-cyber-targeting-of-dissidents-activists-and-journalists

NCSC — UK and Allies Expose Spyware Used by Iranian State Actors:

https://www.ncsc.gov.uk/news/uk-allies-expose-spyware-iranian-state-actors-target-dissidents-activists-journalists

FBI Internet Crime Complaint Center — CHOSEN BRICK:

https://www.ic3.gov/CSA/2026/260915.pdf

Reuters — UK, US and Netherlands issue advisory on Iran spyware:

https://www.reuters.com/world/uk-us-netherlands-issue-advisory-iran-spyware-2026-09-15/

Oracle September 2026 Critical Security Patch Update (CSPU)

Oracle — Critical Security Patch Update Advisory - September 2026:

https://www.oracle.com/security-alerts/cspusep2026.html

SecurityWeek — Oracle Patches 800+ Vulnerabilities in September 2026 Security Update:

https://www.securityweek.com/oracle-patches-800-vulnerabilities-in-september-2026-security-update/

CISA remediation deadline framework

CISA — BOD 26-04: Prioritizing Security Updates Based on Risk:

https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk

NightmareStresser / Operation PowerOFF

U.S. Department of Justice — FBI Seizes DDoS-for-Hire Domains as Part of Continuing District of Alaska Crackdown on Booter and Counterfeit Services:

https://www.justice.gov/usao-ak/pr/fbi-seizes-ddos-hire-domains-part-continuing-district-alaska-crackdown-booter-and

The Hacker News — U.S. Seizes NightmareStresser Domains:

https://thehackernews.com/2026/09/us-seizes-nightmarestresser-domains.html


Jonathan Brown writes independent, decision-focused analysis on cybersecurity, infrastructure resilience, and operational risk, with an emphasis on primary-source verification and explicit uncertainty.

Support this work by sharing the briefing with operators who can act on it. Corrections supported by primary evidence are welcomed; material errors should be amended transparently. Feel free to subscribe, comment, or buy us a coffee! Thanks.

© 2026 Border Cyber Group. All rights reserved.