Why Should I Care? โ€” 2026-09-09 | ๐Ÿ”ด 3 HIGH ยท ๐ŸŸก 4 MEDIUM ยท ๐Ÿ”ต 25 RADAR ยท โšช 67 FILTERED

๐Ÿ“‹ Briefing โ€” 2026-09-09

32 vendor intel items scanned  |  ๐Ÿ”ด 3 HIGH  |  ๐ŸŸก 4 MEDIUM  |  ๐Ÿ”ต 25 RADAR  |  โšช 67 FILTERED

๐Ÿ”ด Critical โ€” action required:

  1. CISA Adds Four Known Exploited Vulnerabilities to Catalog โ€” Yes, if you run any of the affected versions of Adobe Commerce, Microsoft Windows, or N-able N-central, as these vulnerabilities are actively exploited.
  2. JWT used for authentication in web GUI signed with static key โ€” Yes, if you run FortiMonitorOnSight web portal with the affected versions: the static key used for JWT authentication can be exploited to bypass authentication.
  3. Improper Authentication of FortiPAM Server โ€” Yes, if you run FortiPAM Server with the affected Fortinet Privileged Access Agent Chrome Extension: this vulnerability allows attackers to intercept your browser traffic.

Everything else can wait.

๐ŸŸก Medium โ€” review when time permits:

  1. ZTNA Portal Improper Certificate Validation โ€” Yes, if you run FortiOS or FortiProxy Agentless ZTNA portal versions 7.0.0 to 7.2.4: this vulnerability allows attackers to intercept and manipulate your communications.
  2. Unauthenticated Control of NAT Rules Leading to Exposure of Sensitive Information โ€” Yes, if you run FortiSandbox, FortiSandbox Cloud, or FortiSandbox PaaS WEB UI: an unauthenticated attacker could exploit this to access sensitive information.
  3. Cron Job Injection in Remote Backup โ€” Yes, if you run FortiSandbox versions 6.2.0 to 6.2.9: this vulnerability allows attackers to inject commands and execute unauthorized actions.
  4. CareCam Pro IP Cameras โ€” Yes, if you run ANJIA AJL33PC0801 Firmware linux_linux_202008261138_svn13796_/_Bootloader_U-Boot_2010.06_compiled_2020-08-26: An attacker with physical access can take full control of your device.

๐Ÿ”ต 15 items on the radar โ€” see below โ†“


Why Should I Care? ๐Ÿ”ด HIGH โ€” Handle Now


CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA Advisories [CISA KEV]

โ“ Why Should I Care?
Yes, if you run any of the affected versions of Adobe Commerce, Microsoft Windows, or N-able N-central, as these vulnerabilities are actively exploited.

๐ŸŽฏ Affected versions: Adobe Commerce and Magento, Microsoft Windows, N-able N-central

๐ŸŽญ In plain English:
These vulnerabilities allow attackers to exploit your software to gain unauthorized access or execute malicious code. For example, an attacker could use the Adobe Commerce vulnerability to inject malicious code into your website, potentially stealing sensitive data.

๐Ÿ”ง Prerequisites:

  • Running an affected version of the software
  • Lack of proper security updates

โฑ Urgency: High urgency due to active exploitation and the potential for total control of affected systems.


JWT used for authentication in web GUI signed with static key

Fortinet PSIRT | CVSS 9.6

โ“ Why Should I Care?
Yes, if you run FortiMonitorOnSight web portal with the affected versions: the static key used for JWT authentication can be exploited to bypass authentication.

๐ŸŽฏ Affected versions: All versions prior to the patched versions

๐ŸŽญ In plain English:
The software uses a fixed key to sign login tokens, which means anyone who knows this key can create fake login tokens and log in as any user. For example, an attacker could create a fake token to log in as an admin and take control of the system.

๐Ÿ”ง Prerequisites:

  • The attacker knows the static key used for JWT signing

โฑ Urgency: High urgency due to the high CVSS score and the risk of unauthorized access to the system.

โœ… Fixed in: 2.5.0, 2.6.1

๐Ÿ’ก Context: The root cause is the inclusion of a static key in the source code, which should never be done for security-sensitive operations like authentication.


Improper Authentication of FortiPAM Server

Fortinet PSIRT | CVSS 9.1

โ“ Why Should I Care?
Yes, if you run FortiPAM Server with the affected Fortinet Privileged Access Agent Chrome Extension: this vulnerability allows attackers to intercept your browser traffic.

๐ŸŽฏ Affected versions: All versions of the Fortinet Privileged Access Agent Chrome Extension prior to the patched version

๐ŸŽญ In plain English:
If you use the Fortinet Privileged Access Agent Chrome Extension, a hacker could set up a fake website that, when visited, would allow them to see everything you do in your browser, like a spy. For example, they could see your passwords or sensitive information.

๐Ÿ”ง Prerequisites:

  • User must have the affected Fortinet Privileged Access Agent Chrome Extension installed
  • User must visit a malicious website

โฑ Urgency: High urgency due to the potential for attackers to intercept sensitive data like passwords and personal information.

โœ… Fixed in: The latest version of the Fortinet Privileged Access Agent Chrome Extension

๐Ÿ’ก Context: The root cause is a flaw in the authentication mechanism that allows unauthorized access to the browser traffic.


Why Should I Care? ๐ŸŸก MEDIUM (4)


ZTNA Portal Improper Certificate Validation

Fortinet PSIRT | CVSS 7.3 | null

โ“ Why Should I Care?
Yes, if you run FortiOS or FortiProxy Agentless ZTNA portal versions 7.0.0 to 7.2.4: this vulnerability allows attackers to intercept and manipulate your communications.

๐ŸŽฏ Affected versions: 7.0.0 to 7.2.4
Not affected: null

๐ŸŽญ In plain English:
This vulnerability means that an attacker could eavesdrop on your secure communications, pretending to be the ZTNA portal or the website you're trying to access. For example, an attacker could intercept your login credentials when you try to access a secure website through the ZTNA portal.

๐Ÿ”ง Prerequisites:

  • The attacker must be able to intercept network traffic between the ZTNA portal and the backend website

โฑ Urgency: High urgency due to the potential for sensitive data interception and manipulation.

โœ… Fixed in: 7.2.5, 7.3.0

๐Ÿ’ก Context: The root cause is a flaw in the certificate validation process, allowing attackers to use fake certificates to impersonate legitimate services.


Unauthenticated Control of NAT Rules Leading to Exposure of Sensitive Information

Fortinet PSIRT | CVSS 8.9

โ“ Why Should I Care?
Yes, if you run FortiSandbox, FortiSandbox Cloud, or FortiSandbox PaaS WEB UI: an unauthenticated attacker could exploit this to access sensitive information.

๐ŸŽฏ Affected versions: All versions prior to the patched versions

๐ŸŽญ In plain English:
This vulnerability means that anyone on the internet could send a special request to your system and get sensitive information that should be private. For example, an attacker could see user credentials or other confidential data.

๐Ÿ”ง Prerequisites:

  • The attacker does not need any credentials to exploit this vulnerability.

โฑ Urgency: High urgency because an attacker can access sensitive information without needing any login credentials.

โœ… Fixed in: The latest versions that include the fix

๐Ÿ’ก Context: The root cause is an improper access control mechanism in the WEB UI of the affected products.


Cron Job Injection in Remote Backup

Fortinet PSIRT | CVSS 6.7

โ“ Why Should I Care?
Yes, if you run FortiSandbox versions 6.2.0 to 6.2.9: this vulnerability allows attackers to inject commands and execute unauthorized actions.

๐ŸŽฏ Affected versions: 6.2.0 to 6.2.9
Not affected: 6.0.0 to 6.1.9, 6.3.0 and above

๐ŸŽญ In plain English:
An attacker could send a special request to your FortiSandbox, tricking it into running commands they want, like deleting files or stealing data. For example, an attacker could send a request that makes your system delete critical backup files.

๐Ÿ”ง Prerequisites:

  • Attacker must have privileged access
  • Target system must be running an affected version of FortiSandbox

โฑ Urgency: High urgency due to the potential for unauthorized command execution, which can lead to data loss or system compromise.

โœ… Fixed in: 6.3.0, 6.2.10

๐Ÿ’ก Context: The root cause is the lack of proper input validation for HTTP requests, allowing command injection.


CareCam Pro IP Cameras

CISA Advisories | CVSS 6.8 | CVE-2026-85083

โ“ Why Should I Care?
Yes, if you run ANJIA AJL33PC0801 Firmware linux_linux_202008261138_svn13796_/_Bootloader_U-Boot_2010.06_compiled_2020-08-26: An attacker with physical access can take full control of your device.

๐ŸŽฏ Affected versions: ANJIA AJL33PC0801 Firmware linux_linux_202008261138_svn13796_/_Bootloader_U-Boot_2010.06_compiled_2020-08-26

๐ŸŽญ In plain English:
The camera uses a hard-coded password that anyone can use to access and control the device. An attacker could change the firmware and configuration, potentially taking full control of the camera.

๐Ÿ”ง Prerequisites:

  • Physical access to the device

โฑ Urgency: High urgency because an attacker with physical access can exploit this vulnerability to take full control of the device.

๐Ÿ’ก Context: The root cause is the use of a hard-coded credential for bootloader authentication.


Why Should I Care? ๐Ÿ”ต On the Radar (25)


โšช 67 low-priority items filtered.


๐Ÿฆ… Aggregated and triaged by Donna AI  |  Sources: 8 vendor feeds  |  CISA KEV

Read more

Why Should I Care? โ€” 2026-09-24 | ๐Ÿ”ด 0 HIGH ยท ๐ŸŸก 0 MEDIUM ยท ๐Ÿ”ต 27 RADAR ยท โšช 69 FILTERED

๐Ÿ“‹ Briefing โ€” 2026-09-24 27 vendor intel items scanned ย |ย  ๐Ÿ”ด 0 HIGH ย |ย  ๐ŸŸก 0 MEDIUM ย |ย  ๐Ÿ”ต 27 RADAR ย |ย  โšช 69 FILTERED โœ… No critical items today. Everything else can wait. ๐Ÿ”ต 15 items on the radar โ€” see below โ†“ Why Should I Care? ๐Ÿ”ด HIGH โ€” Handle Now No HIGH priority items in the last 24h. Why Should I Care? ๐ŸŸก MEDIUM

By Josip Sokolovic

Why Should I Care? โ€” 2026-09-23 | ๐Ÿ”ด 5 HIGH ยท ๐ŸŸก 3 MEDIUM ยท ๐Ÿ”ต 27 RADAR ยท โšช 69 FILTERED

๐Ÿ“‹ Briefing โ€” 2026-09-23 35 vendor intel items scanned ย |ย  ๐Ÿ”ด 5 HIGH ย |ย  ๐ŸŸก 3 MEDIUM ย |ย  ๐Ÿ”ต 27 RADAR ย |ย  โšช 69 FILTERED ๐Ÿ”ด Critical โ€” action required: 1. CISA Adds Four Known Exploited Vulnerabilities to Catalog (CVE-2026-85102, CVE-2026-93616, CVE-2026-93952, CVE-2026-94127) โ€” Yes, if you run any affected versions of Check Point, Arista VeloCloud Orchestrator, or F5 BIG-IP APM: these vulnerabilities

By Josip Sokolovic

Why Should I Care? โ€” 2026-09-22 | ๐Ÿ”ด 1 HIGH ยท ๐ŸŸก 0 MEDIUM ยท ๐Ÿ”ต 17 RADAR ยท โšช 66 FILTERED

๐Ÿ“‹ Briefing โ€” 2026-09-22 18 vendor intel items scanned ย |ย  ๐Ÿ”ด 1 HIGH ย |ย  ๐ŸŸก 0 MEDIUM ย |ย  ๐Ÿ”ต 17 RADAR ย |ย  โšช 66 FILTERED ๐Ÿ”ด Critical โ€” action required: 1. CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-7273) โ€” Yes, if you run Zyxel GS1900 Series Switches: This vulnerability can allow attackers to take full control of your switch. Everything else

By Josip Sokolovic

Why Should I Care? โ€” 2026-09-21 | ๐Ÿ”ด 23 HIGH ยท ๐ŸŸก 32 MEDIUM ยท ๐Ÿ”ต 209 RADAR ยท โšช 73 FILTERED

๐Ÿ“‹ Briefing โ€” 2026-09-21 264 vendor intel items scanned ย |ย  ๐Ÿ”ด 23 HIGH ย |ย  ๐ŸŸก 32 MEDIUM ย |ย  ๐Ÿ”ต 209 RADAR ย |ย  โšช 73 FILTERED ๐Ÿ”ด Critical โ€” action required: 1. CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-76461) โ€” Yes, if you run Cisco Secure Email Gateway versions 12.0.0 - 12.0.4: SQL injection vulnerability, actively exploited in

By Josip Sokolovic