This is the security briefing for Tuesday the 15th of September 2026, drawn from the BlueTeamSec community on infosec.pub. It's a busy one, with 40 stories to cover — and most of them are actively exploited vulnerabilities added to CISA's Known Exploited list, so we'll work through those first.
CISA has added a critical SQL injection flaw in Cisco Secure Email Gateway to its Known Exploited catalogue. The vulnerability allows unauthenticated remote attackers to execute arbitrary commands with root privileges by simply sending a crafted email — no user interaction required. This one's been exploited in the wild against internet-facing gateways.
Next, an authentication bypass in Apple's macOS Screen Sharing service — actively exploited to deploy cryptominers on exposed systems. Attackers can gain root-level access remotely without valid credentials. If you're running macOS Tahoe, Sequoia, or Sonoma, patches are available now.
Another authentication bypass, this time in Microsoft SharePoint Server — caused by weak JWT token validation. It's been actively exploited within 24 hours of proof-of-concept publication, often chained with another flaw to achieve remote code execution. Microsoft's July 2026 updates address it, with priority on internet-facing instances.
VMware vCenter Server has a directory traversal vulnerability in its Syslog component that lets unauthenticated attackers execute code as root. A suspected China-nexus actor has exploited this to compromise at least 361 victims across 47 countries, deploying Babuk-derived ransomware on ESXi hosts. We've seen this vulnerability come up before in August when it was linked to the Aurora ransomware campaign.
CISA has flagged a critical server-side request forgery flaw in MLflow's webhook delivery feature. Attackers are exploiting internet-exposed MLflow servers to reach internal services and cloud metadata endpoints, potentially stealing credentials. Upgrade to version 3.15.0 or later is the fix.
Two vulnerabilities in TrueConf Server are being actively exploited by the Head Mare threat actor group. The first is a missing authentication flaw allowing remote script execution via TCP port 4307, and the second is a code injection vulnerability on the same port that permits sandbox escape and SYSTEM-level execution. Both have been used to deploy PhantomCore malware and trojanize client installers. These were covered back in August when the Head Mare group was first observed exploiting unpatched servers.
Zimbra Collaboration Suite has an unauthenticated OS command injection flaw that's been added to CISA's catalogue. It allows remote attackers to execute arbitrary commands on internet-facing mail servers when the optional Zimbra SNMP package is installed with notifications enabled. Upgrade to version 10.1.20 or disable the service as a temporary mitigation. This follows a series of Zimbra exploits we've tracked since July, including the Russian webmail espionage campaign.
Gitea self-hosted Git service has a remote code execution vulnerability allowing attackers to execute shell commands via the diffpatch API by installing malicious Git hooks. It's actively exploited against internet-facing instances, so upgrade to version 1.27.1 or later.
JFrog Artifactory has a critical authentication bypass vulnerability allowing unauthenticated remote attackers to gain full administrative control over the server, its repositories, and integrated CI/CD pipeline credentials. Mass scanning was observed within 72 hours of disclosure. Multiple fixed versions are available depending on your branch, and there's quite a bit of context here — this one appeared alongside two other Artifactory flaws in a coordinated exploitation campaign we'll come to shortly.
Sangoma Switchvox SMB Edition has an unauthenticated SQL injection vulnerability in the PA endpoint that allows remote attackers to execute code as a PostgreSQL superuser. Attackers are deploying reverse shells for persistent access on internet-facing PBX systems. Patch to version 8.4.0.2 or later.
Citrix NetScaler ADC and Gateway appliances have a memory overflow vulnerability allowing unauthenticated remote code execution as root. This one's been actively exploited following public proof-of-concept release, with attackers dropping web shells on internet-facing appliances. Patched versions are available, and organisations should rotate all credentials and cryptographic material post-patch. We covered this back in July when Anubis ransomware groups were chaining it with other flaws.
PaperCut NG and MF print management software have two critical vulnerabilities — an authentication bypass and an unsafe dynamic class loading flaw — that can be chained to achieve pre-authentication remote code execution. Recent attacks used AI-driven scanning to compromise over 440 instances, primarily targeting educational institutions. Patched versions are available, and organisations should remove admin interfaces from direct internet exposure. These flaws were disclosed on the 13th and have been under active exploitation since then.
SonicWall SMA1000 series appliances have a pre-authentication server-side request forgery vulnerability with a perfect CVSS score of 10. It allows remote unauthenticated attackers to access sensitive internal functionality and completely compromise the device, and can be chained with another flaw to achieve remote code execution. Apply SonicWall's hotfix immediately, or disconnect affected devices from the internet. There's been a fair bit of SonicWall activity this year — we covered credential stuffing campaigns and earlier RCE exploits back in July and August.
BerriAI's LiteLLM AI Gateway has an authentication bypass vulnerability in its Model Context Protocol endpoint that lets unauthenticated attackers access MCP tooling by sending crafted Authorization headers. It's actively exploited in the wild against public-facing applications. Upgrade to version 1.84.0 or later.
N-able N-central remote monitoring and management platform has a pre-authentication remote code execution flaw that allows unauthenticated attackers to achieve complete server takeover with no user interaction. This one's particularly nasty given the downstream risk to managed service providers and their clients. Upgrade on-premises deployments to version 2026.3.1.14 or later.
Adobe Commerce, Adobe Commerce B2B, and Magento Open Source are affected by a server-side template injection vulnerability nicknamed StyleSmuggler — another perfect CVSS score. Unauthenticated attackers can execute arbitrary code remotely on internet-facing e-commerce platforms, and it's actively exploited to deploy webshells and Rust-based backdoors. Adobe's security patch is available now.
Another Citrix NetScaler flaw, this time an authentication bypass that allows unauthenticated remote attackers to forge sessions and gain unauthorised access. Public proof-of-concept code is available, and it's actively exploited against internet-facing appliances configured as gateways or authentication servers. Patch beyond versions 14.1-73.32 and 13.1-63.21, and kill all active sessions post-patching. This follows the earlier memory overflow flaw we mentioned — NetScaler has had a rough few months.
MikroTik RouterOS has an authentication bypass vulnerability in the bandwidth test service that allows unauthenticated attackers to disclose kernel memory and crash devices without any user interaction. It's currently being exploited against internet-facing routers. Patch to the latest stable version, or disable the btest service and restrict management port access.
And another MikroTik RouterOS vulnerability — this one's an argument injection flaw in the SSH login path that allows unauthenticated attackers to manipulate the trusted policy mask and achieve full device compromise. Also actively exploited in the wild. Same patching advice applies, or disable SSH where it's not needed.
GitLab Community and Enterprise Edition have a path traversal vulnerability in the repository commits API that allows unauthenticated attackers to read arbitrary files from the server, including secrets and credentials. It's actively exploited and has been added to CISA's Known Exploited catalogue. Upgrade to patched versions and rotate all potentially exposed secrets.
Two more JFrog Artifactory flaws to wrap up the CISA section. The first is an improper authentication vulnerability that allows unauthenticated attackers to obtain internal anonymous-user tokens even when anonymous access is disabled, and the second is an authorisation flaw that lets authenticated low-privilege users escalate to full administrator access. Both are actively exploited in the wild, often chained together or with the earlier CVE-2026-82329 we mentioned. Patched versions are available, and organisations should review access logs for signs of unauthorised administrative activity.
Moving on to the rest of today's coverage. CYBERWARCON 2026 has opened its call for proposals, seeking submissions on state-sponsored cyber operations, critical infrastructure threats, and AI-enhanced attacks. Focus areas include conflict zones like Ukraine and the Middle East, threats to democratic elections, and evolving tactics of APT groups.
Elastic Security Labs published detection engineering guidance for Linux Local Privilege Escalation vulnerabilities, noting a surge in 2026 exploits targeting recurring bug classes like copy-on-write and zero-copy failures. The article advocates for behavioural detection based on common execution flows rather than per-CVE signatures — worth a look if you're building detection logic for Linux environments.
On the defence side, NIST and NSA are finalising post-quantum cryptography standards to replace quantum-vulnerable algorithms like RSA and ECDSA. Federal agencies and critical infrastructure face strict migration timelines, with quantum-vulnerable algorithms deprecated after 2030 and disallowed after 2035. This addresses store-now-decrypt-later threats where adversaries capture encrypted traffic for future decryption using quantum computers. There's an audit index available tracking which algorithms, standards bodies, and auditors are involved.
AWS has introduced cross-account EBS volume cloning via AWS RAM, and the announcement includes defensive guidance on securing the feature through IAM permissions, KMS key policies, and monitoring controls to prevent unauthorised data exposure. One for AWS environments concerned about data exfiltration risks.
runZero released SSHamble, an open-source auditing and research framework designed to identify insecure SSH implementations and configurations. The tool helps security teams discover SSH services that fail to follow security best practices or contain known vulnerabilities. We've seen SSH mentioned in several stories over the past few weeks, including agent containment failures and the Virtualizor compromise in August.
Cybertrust in Japan announced a procedural compliance failure with Apple Root Program requirements affecting its SSL/TLS intermediate CA certificate, requiring revocation of the intermediate CA and all certificates issued under it. The transition to a new intermediate CA has been delayed, with an alternative solution provided through Secom Trust Systems. Relevant if you're managing certificates issued by Cybertrust.
The Suricata development team introduced the subslice keyword as a new transform feature that allows rule writers to isolate specific data segments within buffers for inspection. The feature integrates with Suricata's prefilter phase for optimised performance and can be chained with other transforms for complex data normalisation. Useful if you're writing custom Suricata rules.
The EU Cyber Resilience Act's mandatory vulnerability reporting requirements became effective on September 11th, requiring manufacturers of products with digital elements to report actively exploited vulnerabilities within 24 hours to ENISA. The regulation applies globally to any manufacturer selling into the EU market, with tiered reporting deadlines ranging from 24 hours to one month depending on the type and stage of disclosure.
Two incident disclosures next. Sakura Internet detected unauthorised access to its rental server infrastructure on August 9th after attackers compromised internal management systems and installed malware. The incident affected 583 customer accounts with potential exfiltration of personal data and communication records.
Sysdig documented a skilled human threat actor exploiting a pre-authentication RCE vulnerability in marimo notebook platform. The attacker manually developed custom Python tooling over nine hours, then executed a rapid credential-pivot chain in eight seconds to reach a bastion host — demonstrating human expertise rather than AI-driven automation. The vulnerability exists in the unauthenticated terminal WebSocket endpoint.
On to vulnerabilities. Security researcher Maxim Suhanov disclosed an out-of-bounds read vulnerability in NetScaler ADC and Gateway appliances. Attackers can exploit this by sending crafted TCP SYN packets to leak memory contents, including potentially decrypted sensitive data from packet buffers. A vendor patch was released back in June, and mitigation involves disabling TCP timestamps or enabling SYN cookies.
The same researcher disclosed multiple vulnerabilities in Full-Disk Encryption implementations including Microsoft BitLocker, BestCrypt Volume Encryption, and Linux GRUB. The flaws exploit weaknesses in boot and recovery processes, improper memory management, and cryptographic implementation issues that allow attackers with physical or firmware-level access to bypass encryption, leak keys, or extract plaintext data. Eight CVEs were assigned. We've seen BitLocker extortion activity covered back in July, so this adds useful technical context.
Bishop Fox published detailed analysis of the Citrix NetScaler authentication bypass vulnerability we mentioned earlier. The flaw exploits a deserialisation error in the RelayState parameter processing of SAML handling, allowing unauthenticated remote attackers to bypass authentication and potentially gain root-level execution when combined with management credentials. Worth reading for the technical depth on how the vulnerability works.
A WhatsApp vulnerability patched in July allowed attackers to spoof link previews and trigger arbitrary URI schemes on iOS and macOS devices. Attackers could craft messages where the preview appearance differed from the underlying deep link, which would execute without user confirmation when clicked. The flaw was reported in March and patched by late July.
Two exploitation stories to finish. Wiz Research documented active exploitation of the JFrog Artifactory vulnerability chain we mentioned earlier — authentication bypass and privilege escalation flaws being used to deploy Rust-based backdoors, create rogue admin accounts, execute malicious Groovy plugins, and exfiltrate sensitive data. Despite patches being available, 67 to 69 percent of organisations remain vulnerable.
And finally, Rapid7 documented a three-vulnerability exploit chain targeting SonicWall SMA 1000 series appliances — the same device we covered under CISA's catalogue. The chain combines server-side request forgery, CouchDB access, and command injection vulnerabilities to achieve unauthenticated remote code execution with root privileges. A Metasploit module now automates the full attack lifecycle against unpatched devices. Huntress covered this back in August when Akira ransomware was rebooting systems into Safe Mode to bypass EDR.
That's everything for today from BlueTeamSec. The articles are the work of their original authors — the analysis here was automated. We'll be back tomorrow.