Why Should I Care? โ 2026-09-09 | ๐ด 3 HIGH ยท ๐ก 4 MEDIUM ยท ๐ต 25 RADAR ยท โช 67 FILTERED
๐ Briefing โ 2026-09-09
32 vendor intel items scanned | ๐ด 3 HIGH | ๐ก 4 MEDIUM | ๐ต 25 RADAR | โช 67 FILTERED
๐ด Critical โ action required:
- CISA Adds Four Known Exploited Vulnerabilities to Catalog โ Yes, if you run any of the affected versions of Adobe Commerce, Microsoft Windows, or N-able N-central, as these vulnerabilities are actively exploited.
- JWT used for authentication in web GUI signed with static key โ Yes, if you run FortiMonitorOnSight web portal with the affected versions: the static key used for JWT authentication can be exploited to bypass authentication.
- Improper Authentication of FortiPAM Server โ Yes, if you run FortiPAM Server with the affected Fortinet Privileged Access Agent Chrome Extension: this vulnerability allows attackers to intercept your browser traffic.
Everything else can wait.
๐ก Medium โ review when time permits:
- ZTNA Portal Improper Certificate Validation โ Yes, if you run FortiOS or FortiProxy Agentless ZTNA portal versions 7.0.0 to 7.2.4: this vulnerability allows attackers to intercept and manipulate your communications.
- Unauthenticated Control of NAT Rules Leading to Exposure of Sensitive Information โ Yes, if you run FortiSandbox, FortiSandbox Cloud, or FortiSandbox PaaS WEB UI: an unauthenticated attacker could exploit this to access sensitive information.
- Cron Job Injection in Remote Backup โ Yes, if you run FortiSandbox versions 6.2.0 to 6.2.9: this vulnerability allows attackers to inject commands and execute unauthorized actions.
- CareCam Pro IP Cameras โ Yes, if you run ANJIA AJL33PC0801 Firmware linux_linux_202008261138_svn13796_/_Bootloader_U-Boot_2010.06_compiled_2020-08-26: An attacker with physical access can take full control of your device.
๐ต 15 items on the radar โ see below โ
Why Should I Care? ๐ด HIGH โ Handle Now
CISA Adds Four Known Exploited Vulnerabilities to Catalog
CISA Advisories [CISA KEV]
โ Why Should I Care?
Yes, if you run any of the affected versions of Adobe Commerce, Microsoft Windows, or N-able N-central, as these vulnerabilities are actively exploited.
๐ฏ Affected versions: Adobe Commerce and Magento, Microsoft Windows, N-able N-central
๐ญ In plain English:
These vulnerabilities allow attackers to exploit your software to gain unauthorized access or execute malicious code. For example, an attacker could use the Adobe Commerce vulnerability to inject malicious code into your website, potentially stealing sensitive data.
๐ง Prerequisites:
- Running an affected version of the software
- Lack of proper security updates
โฑ Urgency: High urgency due to active exploitation and the potential for total control of affected systems.
JWT used for authentication in web GUI signed with static key
Fortinet PSIRT | CVSS 9.6
โ Why Should I Care?
Yes, if you run FortiMonitorOnSight web portal with the affected versions: the static key used for JWT authentication can be exploited to bypass authentication.
๐ฏ Affected versions: All versions prior to the patched versions
๐ญ In plain English:
The software uses a fixed key to sign login tokens, which means anyone who knows this key can create fake login tokens and log in as any user. For example, an attacker could create a fake token to log in as an admin and take control of the system.
๐ง Prerequisites:
- The attacker knows the static key used for JWT signing
โฑ Urgency: High urgency due to the high CVSS score and the risk of unauthorized access to the system.
โ Fixed in: 2.5.0, 2.6.1
๐ก Context: The root cause is the inclusion of a static key in the source code, which should never be done for security-sensitive operations like authentication.
Improper Authentication of FortiPAM Server
Fortinet PSIRT | CVSS 9.1
โ Why Should I Care?
Yes, if you run FortiPAM Server with the affected Fortinet Privileged Access Agent Chrome Extension: this vulnerability allows attackers to intercept your browser traffic.
๐ฏ Affected versions: All versions of the Fortinet Privileged Access Agent Chrome Extension prior to the patched version
๐ญ In plain English:
If you use the Fortinet Privileged Access Agent Chrome Extension, a hacker could set up a fake website that, when visited, would allow them to see everything you do in your browser, like a spy. For example, they could see your passwords or sensitive information.
๐ง Prerequisites:
- User must have the affected Fortinet Privileged Access Agent Chrome Extension installed
- User must visit a malicious website
โฑ Urgency: High urgency due to the potential for attackers to intercept sensitive data like passwords and personal information.
โ Fixed in: The latest version of the Fortinet Privileged Access Agent Chrome Extension
๐ก Context: The root cause is a flaw in the authentication mechanism that allows unauthorized access to the browser traffic.
Why Should I Care? ๐ก MEDIUM (4)
ZTNA Portal Improper Certificate Validation
Fortinet PSIRT | CVSS 7.3 | null
โ Why Should I Care?
Yes, if you run FortiOS or FortiProxy Agentless ZTNA portal versions 7.0.0 to 7.2.4: this vulnerability allows attackers to intercept and manipulate your communications.
๐ฏ Affected versions: 7.0.0 to 7.2.4
Not affected: null
๐ญ In plain English:
This vulnerability means that an attacker could eavesdrop on your secure communications, pretending to be the ZTNA portal or the website you're trying to access. For example, an attacker could intercept your login credentials when you try to access a secure website through the ZTNA portal.
๐ง Prerequisites:
- The attacker must be able to intercept network traffic between the ZTNA portal and the backend website
โฑ Urgency: High urgency due to the potential for sensitive data interception and manipulation.
โ Fixed in: 7.2.5, 7.3.0
๐ก Context: The root cause is a flaw in the certificate validation process, allowing attackers to use fake certificates to impersonate legitimate services.
Unauthenticated Control of NAT Rules Leading to Exposure of Sensitive Information
Fortinet PSIRT | CVSS 8.9
โ Why Should I Care?
Yes, if you run FortiSandbox, FortiSandbox Cloud, or FortiSandbox PaaS WEB UI: an unauthenticated attacker could exploit this to access sensitive information.
๐ฏ Affected versions: All versions prior to the patched versions
๐ญ In plain English:
This vulnerability means that anyone on the internet could send a special request to your system and get sensitive information that should be private. For example, an attacker could see user credentials or other confidential data.
๐ง Prerequisites:
- The attacker does not need any credentials to exploit this vulnerability.
โฑ Urgency: High urgency because an attacker can access sensitive information without needing any login credentials.
โ Fixed in: The latest versions that include the fix
๐ก Context: The root cause is an improper access control mechanism in the WEB UI of the affected products.
Cron Job Injection in Remote Backup
Fortinet PSIRT | CVSS 6.7
โ Why Should I Care?
Yes, if you run FortiSandbox versions 6.2.0 to 6.2.9: this vulnerability allows attackers to inject commands and execute unauthorized actions.
๐ฏ Affected versions: 6.2.0 to 6.2.9
Not affected: 6.0.0 to 6.1.9, 6.3.0 and above
๐ญ In plain English:
An attacker could send a special request to your FortiSandbox, tricking it into running commands they want, like deleting files or stealing data. For example, an attacker could send a request that makes your system delete critical backup files.
๐ง Prerequisites:
- Attacker must have privileged access
- Target system must be running an affected version of FortiSandbox
โฑ Urgency: High urgency due to the potential for unauthorized command execution, which can lead to data loss or system compromise.
โ Fixed in: 6.3.0, 6.2.10
๐ก Context: The root cause is the lack of proper input validation for HTTP requests, allowing command injection.
CareCam Pro IP Cameras
CISA Advisories | CVSS 6.8 | CVE-2026-85083
โ Why Should I Care?
Yes, if you run ANJIA AJL33PC0801 Firmware linux_linux_202008261138_svn13796_/_Bootloader_U-Boot_2010.06_compiled_2020-08-26: An attacker with physical access can take full control of your device.
๐ฏ Affected versions: ANJIA AJL33PC0801 Firmware linux_linux_202008261138_svn13796_/_Bootloader_U-Boot_2010.06_compiled_2020-08-26
๐ญ In plain English:
The camera uses a hard-coded password that anyone can use to access and control the device. An attacker could change the firmware and configuration, potentially taking full control of the camera.
๐ง Prerequisites:
- Physical access to the device
โฑ Urgency: High urgency because an attacker with physical access can exploit this vulnerability to take full control of the device.
๐ก Context: The root cause is the use of a hard-coded credential for bootloader authentication.
Why Should I Care? ๐ต On the Radar (25)
- DoppelCart fraud network uses 119,000 fake shops to steal credit cards (BleepingComputer) โ A large-scale fraud operation named DoppelCart is using over 119,000 fake online stores to steal credit card information. This could impact any e-commerce platform or payment processor that doesn't have robust security measures in place.
- ShinyHunters hackers claim breach of Florida "DAVID" DMV database (BleepingComputer) โ A hacking group claims to have stolen over 200,000 driver records from Florida's DMV database. This could impact anyone using or managing DMV-related systems in Florida, potentially exposing sensitive personal data.
- Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days (BleepingComputer) โ Microsoft has released a massive update to fix 966 security flaws, including two zero-days. If you use Microsoft products, these updates are crucial to protect your systems from potential attacks.
- Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit (BleepingComputer) โ Hackers are targeting F5 BIG-IP APM devices with a Linux rootkit that can inject malicious code into memory, potentially giving them access to your network without leaving traces on disk. For example, if your company relies on F5 devices for secure access, this could mean unauthorized access to sensitive data.
- WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls (The Hacker News) โ A security flaw in WeChat allows attackers to take over accounts simply by making a call, even if the call isn't answered. This affects iPhone and Android users. Tencent has mitigated the issue, but the underlying flaw's status is unclear.
- Adobe fixes critical Magento zero-day exploited to backdoor servers (BleepingComputer) โ A serious security flaw in Magento and Adobe Commerce was exploited by hackers to install backdoors on servers. Adobe has released a fix.
- Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell (The Hacker News) โ Adobe has patched a critical vulnerability in Adobe Commerce and Magento Open Source that allows attackers to execute arbitrary code. This flaw has been exploited to deploy a Rust backdoor and a PHP web shell, impacting the security of affected systems.
- FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials (The Hacker News) โ A critical flaw in FreeIPA allows attackers to create administrator credentials without logging in, potentially giving them full control over your Linux domain. This impacts any system using FreeIPA or Red Hat's Identity Management product.
- 220 million traveler records exposed in Vietnam-linked APIS leak (BleepingComputer) โ A massive data leak exposed 220 million traveler records due to a security lapse in an APIS system linked to Vietnam. This could affect anyone who travels or manages travel data.
- The EU CRA's Real Question: What Shipped, and When Did You Know? (BleepingComputer) โ The EU Cyber Resilience Act requires software vendors to report actively exploited flaws within 24 hours, starting September 11. This means companies must have a clear record of what products were shipped and when vulnerabilities were discovered to comply.
- Hackers build AI frameworks for widescale credential theft (BleepingComputer) โ Hackers are using advanced AI to automate credential theft, making attacks more efficient and harder to detect. For example, if your company uses weak passwords or has poor multi-factor authentication practices, you're at higher risk.
- Microsoft adds age-awareness APIs that can tell if users are children, teens, or adults (BleepingComputer)
- Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution (The Hacker News) โ New threat actor targeting Brazilian financial institutions.
- China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies (CISA Advisories) โ News item reporting industrial-scale distillation campaigns.
- What It Took to Reach 1 Billion Build Manifests (The Hacker News) โ Chainguard's container build manifest output growth.
โช 67 low-priority items filtered.
๐ฆ Aggregated and triaged by Donna AI | Sources: 8 vendor feeds | CISA KEV