Skip to content
feed: live
>_0dayNews
Briefing · 2026-09-14 to 2026-09-20

Week in Review: Sep 14-20, 2026

Four CVSS 10.0 flaws in enterprise auth and AI platforms in one week. Three Linux kernel CVEs added to KEV. Active exploitation confirmed on six fronts.

tldr.txt
  • Four CVSS 10.0 flaws in seven days, all hitting enterprise identity or AI-platform authentication: Cisco ISE CVE-2026-76460 (Sep 17, actively exploited), WSO2 CVE-2026-5430 (Sep 17, actively exploited), Azure AI Foundry CVE-2026-85889 (Sep 19), Microsoft Fabric CVE-2026-69843 (Sep 19).
  • CISA KEV batch September 19: three exploited Linux kernel CVEs added, federal remediation deadline October 3.
  • GrimWedge zero-day chain (Chrome renderer plus Windows privilege escalation, China-attributed, no government statement) active September 15. ScreenConnect CVE-2026-84869 worm spreading as of September 14, patch available. Orkes Conductor RCE CVE-2026-58138 confirmed exploited in targeted attacks September 18.
  • SolarWinds Access Rights Manager CVE-2026-28326: hardcoded cryptographic key enabling unauthenticated RCE, disclosed September 20, exploitation status unconfirmed at publication.
  • Gyazo breach: 23 million records including OAuth tokens (Sep 19). Japan Digital Agency VPN compromise: 246,000 personnel records (Sep 15). Revolut breach: passport and financial data (Sep 14).
  • ShinyHunters seized Clop's Tor infrastructure September 20. Waterplum (North Korea) job-seeker phishing campaign reached approximately 30,000 devices through the week.

Four CVSS 10.0 flaws in seven days, all in enterprise identity or AI-platform authentication. That is the defining number of the September 14-20 week.

The patch load

Apple released iOS 27 and macOS Golden Gate on September 15, patching over 200 CVEs across the platform stack, including WebKit. No confirmed exploitation of this cycle’s fixes at publication time.

Microsoft issued an out-of-band fix on September 15 for Windows Remote Desktop Services and Hyper-V failures caused by the September Patch Tuesday update. Out-of-band release for production breakage means the prior patch caused damage. Systems waiting on the OOB fix remain in a degraded state.

Google Pixel September 2026 patches (September 17) addressed modem zero-day CVE-2026-58704 under confirmed active exploitation in limited targeted attacks. Pixel updated. Android OEM timelines for the same modem fix: variable, unconfirmed.

Cisco ISE CVE-2026-76460 (September 17): CVSS 10.0, authentication bypass requiring no credentials. Actively exploited at advisory time. Patch available.

WSO2 CVE-2026-5430 (September 17): CVSS 10.0, JWT authentication bypass in the API Gateway. Actively exploited. CISA KEV listing followed within 24 hours of the advisory.

Apache Syncope patched seven critical CVEs on September 16 across its identity provisioning platform. No confirmed exploitation at publication.

BIND 9 (September 18): 14 CVEs patched, including an unauthenticated DNS-over-HTTPS crash. DNS infrastructure. Unbound CVE-2026-81642 (September 18) also patched: critical heap overflow in DNSSEC validation reaching remote code execution, fixed in 1.26.1.

Check Point Management Server CVE-2026-91843 (September 18): RCE reaching root on the management plane. Patch confirmed available. Exploitation status: unconfirmed at publication.

Azure AI Foundry CVE-2026-85889 (September 19): CVSS 10.0, privilege escalation in Microsoft’s cloud-hosted AI development platform. Microsoft’s advisory specifies additional tenant configuration steps. Cloud-hosted does not mean no customer action required.

Microsoft Fabric CVE-2026-69843 (September 19): CVSS 10.0, authentication bypass in the analytics platform. Patched server-side by Microsoft. Advisory recommends verifying tenant configuration.

KEV additions

CISA added three Linux kernel CVEs to the Known Exploited Vulnerabilities catalog on September 19. Exploitation confirmed. Federal remediation deadline: October 3. Enterprise Linux distributions: check vendor bulletins for patch availability against your specific kernel version.

Active exploitation

GrimWedge: Chrome renderer plus Windows privilege escalation zero-day chain. Attribution to a China-linked group reported by multiple threat intelligence firms. Government attribution statement: absent at publication. Active exploitation observed September 15. Both components were unpatched zero-days at time of initial exploitation.

ScreenConnect CVE-2026-84869: worm actively spreading as of September 14. Patch is available. Running an unpatched ScreenConnect instance from this point is a deliberate choice.

LightLLM CVE-2026-90919 (September 16): unauthenticated RCE via pickle deserialization in the LightLLM config server. AI inference infrastructure. Exploitation status: unconfirmed. Treat accordingly.

Orkes Conductor CVE-2026-58138 (September 18): RCE in the workflow orchestration platform, confirmed exploited in targeted attacks against cloud deployments.

SolarWinds Access Rights Manager CVE-2026-28326 (September 20): hardcoded cryptographic key enabling unauthenticated RCE. Disclosed at end of week. Exploitation status: unconfirmed at publication.

Breaches and incidents

Revolut disclosed a breach on September 14 involving passport images and financial data. Scope and affected record count: unconfirmed.

Japan’s Digital Agency reported a VPN compromise on September 15: 246,000 personnel records accessed via a VPN gateway.

Gyazo reported a breach September 19: 23 million records including OAuth tokens. Active OAuth tokens issued by Gyazo should be treated as compromised until Gyazo confirms revocation and rotation.

North Korea’s Waterplum group ran a job-seeker phishing campaign through the week, compromising approximately 30,000 devices. Attribution: multiple threat intelligence vendors. Government statement: absent as of publication.

BragJack, published September 20: proof-of-concept demonstrating hijack of AI browser agents via malicious extensions, redirecting agentic actions without user awareness. Confirmed weaponization: none at publication. The technique is functional.

ShinyHunters took over Clop’s Tor infrastructure on September 20, obtaining onion keys and internal extortion records. Defender-facing operational impact: low. One criminal organization compromising another does not alter anyone else’s exposure.

Analysis: identity and AI-platform authentication as the target class

Four CVSS 10.0 critical flaws in one week, all in enterprise authentication or AI-platform access control: Cisco ISE (network access control), WSO2 (API gateway auth), Azure AI Foundry (cloud AI platform), Microsoft Fabric (analytics platform auth). Two confirmed actively exploited on the day of advisory publication.

Analysis: the concentration is observable. Enterprise authentication infrastructure and AI platform orchestration have become a consistent high-value target. Whether this reflects coordinated attacker prioritization or convergence of commercial vulnerability research on the same surface is unconfirmed. The pattern is confirmed.

Sources