Why Should I Care? β€” 2026-09-11 | πŸ”΄ 1 HIGH Β· 🟑 5 MEDIUM Β· πŸ”΅ 19 RADAR Β· βšͺ 70 FILTERED

πŸ“‹ Briefing β€” 2026-09-11

25 vendor intel items scanned  |  πŸ”΄ 1 HIGH  |  🟑 5 MEDIUM  |  πŸ”΅ 19 RADAR  |  βšͺ 70 FILTERED

πŸ”΄ Critical β€” action required:

  1. CISA Adds Two Known Exploited Vulnerabilities to Catalog (CVE-2026-67277) β€” Yes, if you run MikroTik RouterOS versions 6.48.1 to 7.8.2: These vulnerabilities can allow attackers to take full control of your router without proper authentication.

Everything else can wait.

🟑 Medium β€” review when time permits:

  1. AVEVA Pipeline Integrity Monitor β€” Yes, if you run AVEVA Pipeline Integrity Monitor <=2025_SP1_P1_build_7.1.9580.8513: An attacker could disclose sensitive information, brute-force hashes, or run arbitrary code in a browser session.
  2. ST Engineering iDirect iQ-Series Terminals (Update A) β€” Yes, if you run any Evolution iQ-Series, 3315-Series, or 9-Series terminals <=4.5.2.1: these vulnerabilities can allow unauthorized access to sensitive device information and cause denial-of-service conditions.
  3. NextGen Healthcare Mirth Connect β€” Yes, if you run NextGen Healthcare Mirth Connect <=v4.7.1: You are at risk of data exfiltration and denial-of-service attacks.
  4. Orthanc DICOM Server β€” Yes, if you run Orthanc DICOM Server <1.13.0: An attacker could crash your server and cause a denial-of-service condition.
  5. The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE β€” Yes, if you run SPIFFE/SPIRE in your Kubernetes environment: root access on a compromised node allows attackers to impersonate other workloads and harvest identities.

πŸ”΅ 15 items on the radar β€” see below ↓


Why Should I Care? πŸ”΄ HIGH β€” Handle Now


CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA Advisories [CISA KEV] | CVSS 9.8 | CVE-2026-67277

❓ Why Should I Care?
Yes, if you run MikroTik RouterOS versions 6.48.1 to 7.8.2: These vulnerabilities can allow attackers to take full control of your router without proper authentication.

🎯 Affected versions: 6.48.1 to 7.8.2
Not affected: Versions 7.8.3 and above

🎭 In plain English:
This vulnerability means that an attacker can access critical functions on your router without needing a password. For example, they could change your network settings, redirect your internet traffic, or even shut down your network.

πŸ”§ Prerequisites:

  • RouterOS version is between 6.48.1 and 7.8.2
  • Router is accessible from the internet

⏱ Urgency: High urgency because these vulnerabilities are actively exploited and can lead to full control of your router.

βœ… Fixed in: 7.8.3, 7.8.4

πŸ’‘ Context: The root cause is a lack of proper authentication checks for critical functions in the router's software.


Why Should I Care? 🟑 MEDIUM (5)


AVEVA Pipeline Integrity Monitor

CISA Advisories | CVSS 8.4 | CVE-2026-81821, CVE-2026-81822, CVE-2026-81823, CVE-2026-81824

❓ Why Should I Care?
Yes, if you run AVEVA Pipeline Integrity Monitor <=2025_SP1_P1_build_7.1.9580.8513: An attacker could disclose sensitive information, brute-force hashes, or run arbitrary code in a browser session.

🎯 Affected versions: AVEVA Pipeline Integrity Monitor <=2025_SP1_P1_build_7.1.9580.8513

🎭 In plain English:
This vulnerability means that if someone gains access to your project files, they can decrypt sensitive information, guess passwords, or inject malicious code into your browser. For example, an attacker could steal passwords and gain admin access to your system.

πŸ”§ Prerequisites:

  • Read access to PIMBoards project files

⏱ Urgency: High urgency due to the potential for sensitive information disclosure and unauthorized access.

βœ… Fixed in: AVEVA Pipeline Integrity Monitor 2025 SP1 P2

πŸ’‘ Context: The root cause includes hard-coded cryptographic keys and weak hashing algorithms.


ST Engineering iDirect iQ-Series Terminals (Update A)

CISA Advisories | CVSS 8.8 | CVE-2026-38059, CVE-2026-38057, CVE-2026-38056, CVE-2026-38058

❓ Why Should I Care?
Yes, if you run any Evolution iQ-Series, 3315-Series, or 9-Series terminals <=4.5.2.1: these vulnerabilities can allow unauthorized access to sensitive device information and cause denial-of-service conditions.

🎯 Affected versions: Evolution iQ-Series terminals <=4.5.2.1, 3315-Series terminals <=4.5.2.1, 9-Series terminals <=4.5.2.1

🎭 In plain English:
These vulnerabilities mean that an attacker can access sensitive information about your device and even cause it to reboot, disrupting service. For example, an attacker could access your device's serial number and MAC address, and then cause your device to reboot repeatedly, making it unusable.

πŸ”§ Prerequisites:

  • Network access to the device
  • Authenticated session for CSRF attacks

⏱ Urgency: High urgency due to the potential for unauthorized access to sensitive information and denial-of-service attacks.

βœ… Fixed in: 4.5.3.0

πŸ’‘ Context: The root cause includes missing authentication and authorization checks, as well as CSRF vulnerabilities.


NextGen Healthcare Mirth Connect

CISA Advisories | CVSS 8.3 | CVE-2026-82583, CVE-2026-78224, CVE-2026-82578

❓ Why Should I Care?
Yes, if you run NextGen Healthcare Mirth Connect <=v4.7.1: You are at risk of data exfiltration and denial-of-service attacks.

🎯 Affected versions: Mirth Connect <=v4.7.1

🎭 In plain English:
These vulnerabilities allow attackers to steal sensitive data and disrupt services. For example, an attacker could steal patient data or crash the system, preventing critical communications.

πŸ”§ Prerequisites:

  • Authenticated user access
  • XML processing enabled

⏱ Urgency: High urgency due to the potential for data theft and service disruption.

βœ… Fixed in: v4.7.2

πŸ’‘ Context: The root cause includes improper handling of SQL commands and XML external entities.


Orthanc DICOM Server

CISA Advisories | CVSS 8.1 | CVE-2026-87020

❓ Why Should I Care?
Yes, if you run Orthanc DICOM Server <1.13.0: An attacker could crash your server and cause a denial-of-service condition.

🎯 Affected versions: Orthanc DICOM Server <1.13.0

🎭 In plain English:
If you use an older version of Orthanc DICOM Server, an attacker could send a specially crafted image that crashes your server, making it unavailable. This means your medical imaging services could be interrupted.

πŸ”§ Prerequisites:

  • Authenticated remote attacker
  • Server running Orthanc DICOM Server <1.13.0

⏱ Urgency: High urgency due to the potential for a denial-of-service attack that could disrupt medical imaging services.

βœ… Fixed in: 1.13.0

πŸ’‘ Context: The root cause is an integer overflow during the decoding of PNG or JPEG images, leading to a heap out-of-bounds write.


The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE

Palo Alto Unit 42

❓ Why Should I Care?
Yes, if you run SPIFFE/SPIRE in your Kubernetes environment: root access on a compromised node allows attackers to impersonate other workloads and harvest identities.

🎯 Affected versions: All versions using SPIFFE/SPIRE for identity management in Kubernetes environments

🎭 In plain English:
If an attacker gets root access to a Kubernetes node, they can trick the SPIFFE/SPIRE system into giving them the identities of other workloads running on the same node. This means they can pretend to be those workloads and access resources as if they were legitimate.

πŸ”§ Prerequisites:

  • Root access on a Kubernetes node
  • SPIFFE/SPIRE for identity management

⏱ Urgency: High urgency because root access on a node can lead to full identity spoofing and unauthorized access to other workloads.

πŸ’‘ Context: The root cause is the trust placed in the node's integrity, which is compromised when an attacker gains root access.


Why Should I Care? πŸ”΅ On the Radar (19)


βšͺ 70 low-priority items filtered.


πŸ¦… Aggregated and triaged by Donna AI  |  Sources: 8 vendor feeds  |  CISA KEV

Read more

Why Should I Care? β€” 2026-09-24 | πŸ”΄ 0 HIGH Β· 🟑 0 MEDIUM Β· πŸ”΅ 27 RADAR Β· βšͺ 69 FILTERED

πŸ“‹ Briefing β€” 2026-09-24 27 vendor intel items scanned Β |Β  πŸ”΄ 0 HIGH Β |Β  🟑 0 MEDIUM Β |Β  πŸ”΅ 27 RADAR Β |Β  βšͺ 69 FILTERED βœ… No critical items today. Everything else can wait. πŸ”΅ 15 items on the radar β€” see below ↓ Why Should I Care? πŸ”΄ HIGH β€” Handle Now No HIGH priority items in the last 24h. Why Should I Care? 🟑 MEDIUM

By Josip Sokolovic

Why Should I Care? β€” 2026-09-23 | πŸ”΄ 5 HIGH Β· 🟑 3 MEDIUM Β· πŸ”΅ 27 RADAR Β· βšͺ 69 FILTERED

πŸ“‹ Briefing β€” 2026-09-23 35 vendor intel items scanned Β |Β  πŸ”΄ 5 HIGH Β |Β  🟑 3 MEDIUM Β |Β  πŸ”΅ 27 RADAR Β |Β  βšͺ 69 FILTERED πŸ”΄ Critical β€” action required: 1. CISA Adds Four Known Exploited Vulnerabilities to Catalog (CVE-2026-85102, CVE-2026-93616, CVE-2026-93952, CVE-2026-94127) β€” Yes, if you run any affected versions of Check Point, Arista VeloCloud Orchestrator, or F5 BIG-IP APM: these vulnerabilities

By Josip Sokolovic

Why Should I Care? β€” 2026-09-22 | πŸ”΄ 1 HIGH Β· 🟑 0 MEDIUM Β· πŸ”΅ 17 RADAR Β· βšͺ 66 FILTERED

πŸ“‹ Briefing β€” 2026-09-22 18 vendor intel items scanned Β |Β  πŸ”΄ 1 HIGH Β |Β  🟑 0 MEDIUM Β |Β  πŸ”΅ 17 RADAR Β |Β  βšͺ 66 FILTERED πŸ”΄ Critical β€” action required: 1. CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-7273) β€” Yes, if you run Zyxel GS1900 Series Switches: This vulnerability can allow attackers to take full control of your switch. Everything else

By Josip Sokolovic

Why Should I Care? β€” 2026-09-21 | πŸ”΄ 23 HIGH Β· 🟑 32 MEDIUM Β· πŸ”΅ 209 RADAR Β· βšͺ 73 FILTERED

πŸ“‹ Briefing β€” 2026-09-21 264 vendor intel items scanned Β |Β  πŸ”΄ 23 HIGH Β |Β  🟑 32 MEDIUM Β |Β  πŸ”΅ 209 RADAR Β |Β  βšͺ 73 FILTERED πŸ”΄ Critical β€” action required: 1. CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-76461) β€” Yes, if you run Cisco Secure Email Gateway versions 12.0.0 - 12.0.4: SQL injection vulnerability, actively exploited in

By Josip Sokolovic