Why Should I Care? β 2026-09-11 | π΄ 1 HIGH Β· π‘ 5 MEDIUM Β· π΅ 19 RADAR Β· βͺ 70 FILTERED
π Briefing β 2026-09-11
25 vendor intel items scanned | π΄ 1 HIGH | π‘ 5 MEDIUM | π΅ 19 RADAR | βͺ 70 FILTERED
π΄ Critical β action required:
- CISA Adds Two Known Exploited Vulnerabilities to Catalog (CVE-2026-67277) β Yes, if you run MikroTik RouterOS versions 6.48.1 to 7.8.2: These vulnerabilities can allow attackers to take full control of your router without proper authentication.
Everything else can wait.
π‘ Medium β review when time permits:
- AVEVA Pipeline Integrity Monitor β Yes, if you run AVEVA Pipeline Integrity Monitor <=2025_SP1_P1_build_7.1.9580.8513: An attacker could disclose sensitive information, brute-force hashes, or run arbitrary code in a browser session.
- ST Engineering iDirect iQ-Series Terminals (Update A) β Yes, if you run any Evolution iQ-Series, 3315-Series, or 9-Series terminals <=4.5.2.1: these vulnerabilities can allow unauthorized access to sensitive device information and cause denial-of-service conditions.
- NextGen Healthcare Mirth Connect β Yes, if you run NextGen Healthcare Mirth Connect <=v4.7.1: You are at risk of data exfiltration and denial-of-service attacks.
- Orthanc DICOM Server β Yes, if you run Orthanc DICOM Server <1.13.0: An attacker could crash your server and cause a denial-of-service condition.
- The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE β Yes, if you run SPIFFE/SPIRE in your Kubernetes environment: root access on a compromised node allows attackers to impersonate other workloads and harvest identities.
π΅ 15 items on the radar β see below β
Why Should I Care? π΄ HIGH β Handle Now
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA Advisories [CISA KEV] | CVSS 9.8 | CVE-2026-67277
β Why Should I Care?
Yes, if you run MikroTik RouterOS versions 6.48.1 to 7.8.2: These vulnerabilities can allow attackers to take full control of your router without proper authentication.
π― Affected versions: 6.48.1 to 7.8.2
Not affected: Versions 7.8.3 and above
π In plain English:
This vulnerability means that an attacker can access critical functions on your router without needing a password. For example, they could change your network settings, redirect your internet traffic, or even shut down your network.
π§ Prerequisites:
- RouterOS version is between 6.48.1 and 7.8.2
- Router is accessible from the internet
β± Urgency: High urgency because these vulnerabilities are actively exploited and can lead to full control of your router.
β Fixed in: 7.8.3, 7.8.4
π‘ Context: The root cause is a lack of proper authentication checks for critical functions in the router's software.
Why Should I Care? π‘ MEDIUM (5)
AVEVA Pipeline Integrity Monitor
CISA Advisories | CVSS 8.4 | CVE-2026-81821, CVE-2026-81822, CVE-2026-81823, CVE-2026-81824
β Why Should I Care?
Yes, if you run AVEVA Pipeline Integrity Monitor <=2025_SP1_P1_build_7.1.9580.8513: An attacker could disclose sensitive information, brute-force hashes, or run arbitrary code in a browser session.
π― Affected versions: AVEVA Pipeline Integrity Monitor <=2025_SP1_P1_build_7.1.9580.8513
π In plain English:
This vulnerability means that if someone gains access to your project files, they can decrypt sensitive information, guess passwords, or inject malicious code into your browser. For example, an attacker could steal passwords and gain admin access to your system.
π§ Prerequisites:
- Read access to PIMBoards project files
β± Urgency: High urgency due to the potential for sensitive information disclosure and unauthorized access.
β Fixed in: AVEVA Pipeline Integrity Monitor 2025 SP1 P2
π‘ Context: The root cause includes hard-coded cryptographic keys and weak hashing algorithms.
ST Engineering iDirect iQ-Series Terminals (Update A)
CISA Advisories | CVSS 8.8 | CVE-2026-38059, CVE-2026-38057, CVE-2026-38056, CVE-2026-38058
β Why Should I Care?
Yes, if you run any Evolution iQ-Series, 3315-Series, or 9-Series terminals <=4.5.2.1: these vulnerabilities can allow unauthorized access to sensitive device information and cause denial-of-service conditions.
π― Affected versions: Evolution iQ-Series terminals <=4.5.2.1, 3315-Series terminals <=4.5.2.1, 9-Series terminals <=4.5.2.1
π In plain English:
These vulnerabilities mean that an attacker can access sensitive information about your device and even cause it to reboot, disrupting service. For example, an attacker could access your device's serial number and MAC address, and then cause your device to reboot repeatedly, making it unusable.
π§ Prerequisites:
- Network access to the device
- Authenticated session for CSRF attacks
β± Urgency: High urgency due to the potential for unauthorized access to sensitive information and denial-of-service attacks.
β Fixed in: 4.5.3.0
π‘ Context: The root cause includes missing authentication and authorization checks, as well as CSRF vulnerabilities.
NextGen Healthcare Mirth Connect
CISA Advisories | CVSS 8.3 | CVE-2026-82583, CVE-2026-78224, CVE-2026-82578
β Why Should I Care?
Yes, if you run NextGen Healthcare Mirth Connect <=v4.7.1: You are at risk of data exfiltration and denial-of-service attacks.
π― Affected versions: Mirth Connect <=v4.7.1
π In plain English:
These vulnerabilities allow attackers to steal sensitive data and disrupt services. For example, an attacker could steal patient data or crash the system, preventing critical communications.
π§ Prerequisites:
- Authenticated user access
- XML processing enabled
β± Urgency: High urgency due to the potential for data theft and service disruption.
β Fixed in: v4.7.2
π‘ Context: The root cause includes improper handling of SQL commands and XML external entities.
Orthanc DICOM Server
CISA Advisories | CVSS 8.1 | CVE-2026-87020
β Why Should I Care?
Yes, if you run Orthanc DICOM Server <1.13.0: An attacker could crash your server and cause a denial-of-service condition.
π― Affected versions: Orthanc DICOM Server <1.13.0
π In plain English:
If you use an older version of Orthanc DICOM Server, an attacker could send a specially crafted image that crashes your server, making it unavailable. This means your medical imaging services could be interrupted.
π§ Prerequisites:
- Authenticated remote attacker
- Server running Orthanc DICOM Server <1.13.0
β± Urgency: High urgency due to the potential for a denial-of-service attack that could disrupt medical imaging services.
β Fixed in: 1.13.0
π‘ Context: The root cause is an integer overflow during the decoding of PNG or JPEG images, leading to a heap out-of-bounds write.
The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE
Palo Alto Unit 42
β Why Should I Care?
Yes, if you run SPIFFE/SPIRE in your Kubernetes environment: root access on a compromised node allows attackers to impersonate other workloads and harvest identities.
π― Affected versions: All versions using SPIFFE/SPIRE for identity management in Kubernetes environments
π In plain English:
If an attacker gets root access to a Kubernetes node, they can trick the SPIFFE/SPIRE system into giving them the identities of other workloads running on the same node. This means they can pretend to be those workloads and access resources as if they were legitimate.
π§ Prerequisites:
- Root access on a Kubernetes node
- SPIFFE/SPIRE for identity management
β± Urgency: High urgency because root access on a node can lead to full identity spoofing and unauthorized access to other workloads.
π‘ Context: The root cause is the trust placed in the node's integrity, which is compromised when an attacker gains root access.
Why Should I Care? π΅ On the Radar (19)
- CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline (The Hacker News) β CISA has flagged critical vulnerabilities in Cisco, Citrix, and Fortinet products that could allow attackers to gain unauthorized access and execute commands. Federal agencies must patch by September 12, 2026, but all users should prioritize these updates.
- September Windows Server updates break Remote Desktop Services (BleepingComputer) β The September 2026 Windows Server updates are causing Remote Desktop Services to fail, preventing users from connecting and sometimes requiring a hard reset to restore functionality. This impacts Windows Server 2019, 2022, and 2025.
- New Android malware encrypts files, steals data, and harasses victims (BleepingComputer) β A new Android malware, Mantax Otax, can encrypt files, steal sensitive data, and harass users. It targets older Android versions and spreads through malicious APKs outside Google Play. This can affect both personal and corporate devices, leading to data loss and security breaches.
- Surfshark VPN says hackers breached internal testing, proxy servers (BleepingComputer) β Surfshark had a security breach due to a misconfigured test server. While customer data was not affected, this incident shows the risks of exposing internal systems to the internet. It's a reminder to ensure all environments, especially test ones, are securely configured and monitored.
- PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances (The Hacker News) β A cyber attacker used AI to exploit vulnerabilities in PaperCut NG/MF, compromising over 440 instances. This attack targeted the education sector in multiple countries and used a combination of AI and offensive security tools to gain access.
- Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE (The Hacker News) β Check Point has found and patched two critical flaws in its firewall and management products that could allow attackers to run code remotely without authentication. This affects Security Gateways and Security Management Server.
- New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws (BleepingComputer) β Cyber-espionage groups are using a new exploit kit called 'BlueMoon' that takes advantage of zero-day vulnerabilities in Windows and Chrome. This means attackers can execute remote code and escalate privileges on your systems, potentially leading to data theft or system compromise.
- IDScan confirms breach tied to 153 million stolen driverβs licenses (BleepingComputer) β IDScan, a company that verifies identities through driver's licenses, was breached, potentially exposing over 153 million driver's license scans. This could affect businesses that use IDScan for identity verification, such as car rental companies, retailers, and financial institutions.
- AI-powered attack exploited PaperCut flaws to hack 395 organizations (BleepingComputer) β A sophisticated attack used AI to exploit vulnerabilities in PaperCut NG/MF servers, compromising 395 organizations. This attack highlights the need for immediate action to secure your infrastructure.
- CISA: WatchGuard RCE flaw now exploited in ransomware attacks (BleepingComputer) β Ransomware attackers are exploiting a critical flaw in WatchGuard Firebox firewalls, which could allow them to execute malicious code remotely. This affects firewalls running Fireware OS 11.x and later versions. If your organization uses these firewalls, you need to patch them immediately to avoid potential ransomware attacks.
- Trezor warns users of email provider breach, phishing attacks (BleepingComputer) β Trezor, a cryptocurrency hardware wallet provider, warns of phishing attacks due to a breach of their email provider. Users received fake security alert emails, which are part of a phishing scheme. This affects users who might have received such emails and could lead to potential account compromise.
- Microsoft Excel KB5002914 update breaks copy and paste for some users (BleepingComputer) β A recent security update for Microsoft Excel (KB5002914) is causing issues with copy-and-paste and formula dragging for some users. Removing or rolling back the update restores normal functionality.
- Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers (BleepingComputer) β Two critical vulnerabilities in Cisco FMC have been exploited by ransomware groups and state-sponsored hackers to deploy malware, steal credentials, and gain persistent access to networks. This affects network security and can lead to data breaches and ransomware attacks.
- Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key (The Hacker News) β A recent scan found that nearly 1 in 10 internet-facing LiteLLM servers accepted a default admin key, 'sk-1234', which can expose cloud credentials and API keys. This means unauthorized users could potentially access sensitive information and services.
- ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories (The Hacker News) β Weekly security news summary.
βͺ 70 low-priority items filtered.
π¦ Aggregated and triaged by Donna AI | Sources: 8 vendor feeds | CISA KEV