Last Updated On

CCTTII--22002266--00991188
CCrriittiiccaall
AAccttiivvee  EExxppllooiittaattiioonn  CCoonnffiirrmmeedd

The Box That Admits Devices Now Hands Out Root

Tomorrow morning federal operators have to prove they did more than patch Cisco ISE. CVE-2026-76460 is a CVSS 10.0 unauthenticated API bypass with root on the box that decides who joins the network, and the KEV clock ends 2026-09-19. Sitting beside it are a crafted mail root RCE on Secure Email Gateway, three intrusion sets on FMC including a Qilin affiliate and Cyclops Blink, two Windows AppContainer to SYSTEM zero days, a zero click Pixel modem bug, and an Acronis hosting plugin that turns a tenant into the host.

Settra is the noise that still encrypts. Ninety three claimed victims, MeshAgent at 45.13.122[.]7 and 193.5.65[.]114, gdrv.sys to kill EDR, then reagentc, diskpart, and cipher before .locked_wip and a Tox chat. Hunt the remote tool and the driver, not the ransom note.

The rest of the window is the same class of failure on different products. GitLab commits API file read hit KEV inside a day. MikroTik SSH and Orkes INLINE workflows stay exploitable after a lazy upgrade if persistence is left behind. Check Point is critical but not observed in the wild. Gyazo spilled tens of millions of records. PhantomRaven is stealing developer secrets from npm. ShinyHunters posted Kimberly-Clark without proof. Patch the KEV set tonight. Reimage anything that already answered an unauthenticated admin call.

10

CVSS Score

14

IOC Count

32

Source Count

84

Confidence Score

CVEs

CVE-2026-76460, CVE-2026-76461, CVE-2026-87886, CVE-2026-58704, CVE-2026-81963, CVE-2026-85880, CVE-2026-41870, CVE-2026-41871, CVE-2026-41869, CVE-2026-91843, CVE-2026-67276, CVE-2026-86060, CVE-2026-67279, CVE-2026-58138, CVE-2026-84869, CVE-2026-20079, CVE-2026-20316, CVE-2026-85706, CVE-2026-20329, CVE-2026-20330, CVE-2026-20331, CVE-2026-20332, CVE-2026-20333, CVE-2026-20334, CVE-2026-20335, CVE-2026-20336, CVE-2026-20324, CVE-2026-20341, CVE-2026-76420, CVE-2026-20323

Actors

Settra, Sandworm, Qilin, UAT-11823, UAT-11988, UAT-12197, Storm-2945, Midnight Blizzard, JPD, ShinyHunters

Sectors

Government, Critical Infrastructure, Technology, Telecom, Manufacturing, Professional Services, Retail, Hospitality, Financial Services, Healthcare, Education, MSP, Software Development, Web Hosting, Consumer Goods

Regions

Global, United States, Europe, APAC, India, Latin America, Japan, Poland

Chapter 01 - Executive Overview

The window is a management plane problem first and a ransomware problem second. The product that decides who joins the network, the product that reads every inbound message, and the product that orchestrates firewall policy all sat on unauthenticated or weakly authenticated paths at the same time.

[+] Cisco ISE and ISE-PIC CVE-2026-76460, Critical, Government Enterprise MSP: Unauthenticated API authentication bypass, CVSS 10.0, CWE-648. Cisco confirmed exploitation after a TAC case. CISA KEV on 2026-09-16 with forensic triage required and a 2026-09-19 federal date. Success can yield web management access and root command execution. Attackers can wipe on box logs. No workaround. First fixed trains are 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4. ISE 3.0 is end of maintenance and must be migrated. MSP and managed NAC operators create third party risk. Demand per node patch attestation, log hunting, and egress review.

[+] Cisco Secure Email Gateway CVE-2026-76461, Critical, Enterprise Government Email Security: Pre authentication SQL injection in AsyncOS parsing. A crafted message yields SQL and then root on the appliance. CVSS 9.8. KEV on 2026-09-14. Exploited before disclosure. Cisco contacted cloud customers after detected activity. Affected AsyncOS 15.5 before 15.5.5-014, 16.0 before 16.0.4-302, 16.5 before 16.5.0-780. No workaround.

[+] Cisco FMC CVE-2026-20079 and CVE-2026-20316, Critical, Network Security Operators: Authentication bypass plus a hard coded low privilege static credential. Talos tracks three intrusion sets on the same access: UAT-12197 (JSP web shell, cmd.jar, credential harvest), UAT-11823 (Sandworm tooling overlap, upgraded 64 bit Cyclops Blink), UAT-11988 (Qilin affiliate, disable AV, ransomware). The 2026-09-16 hardening cycle added a large sibling CVE set on the same family. Treat unpatched on premises FMC as a live incident until proven otherwise.

[+] Microsoft September 2026 Patch Tuesday, High, All Windows Estates: Record 966 flaws in the primary consult, 113 Critical. Two exploited zero days. CVE-2026-81963 Windows Update Stack link following elevation of privilege, CVSS 7.8, first in the wild for that component. CVE-2026-85880 ALPC heap buffer overflow, CVSS 7.8, second ALPC zero day since CVE-2023-21674. Both move a low privilege AppContainer process to SYSTEM. Same day KEV. Prioritize tier 0, PAW, VDI, and internet facing hosts.

[+] Google Pixel CVE-2026-58704, High, Mobile Fleets: Zero click baseband logic flaw. Crafted cellular signals escalate privilege with no tap and no app install. CVSS 8.0. Google describes limited targeted use. KEV on 2026-09-16, federal date 2026-09-19. Fix is security patch level 2026-09-05 or later. There is no network control that replaces the modem patch.

[+] Acronis Backup CVE-2026-87886, High, Hosting and MSP: Incorrect default permissions on cPanel WHM plugin and Plesk extension, with DirectAdmin builds also named in consults. Local low privilege to host privilege on shared infrastructure. KEV on 2026-09-16, federal date 2026-09-19. Fixed builds include cPanel plugin 1.9.3.1021 / 1.9.4.1022 and Plesk 1.8.11.638.

[+] Settra ransomware, High, Multi Sector Opportunistic: 93 claimed victims since Jun 2026. Double extortion, four plus confirmed leaks. Path is compromised VPN credentials, MeshAgent (mvtcs.exe or default), gdrv.sys BYOVD, log clear, reagentc /disable, diskpart recovery wipe, cipher /w, then [domain]_win64.exe to .locked or .locked_wip and RESTORE_FILES.txt over Tox. Best detection is before encryption.

[+] Adjacent pressure in the same window: Check Point CVE-2026-91843 CVSS 9.8 login stack overflow with no observed exploitation and LivePatch sk1000155. MikroTik MikroTrick CVE-2026-67276 plus CVE-2026-86060 exploited from 2026-09-02, persistence can survive the upgrade. Orkes Conductor CVE-2026-58138 unauthenticated INLINE RCE exploited from 2026-08-21. GitLab CVE-2026-85706 CVSS 10.0 commits API path traversal exploited within 24 hours of disclosure. ScreenConnect CVE-2026-84869 remains a post deadline worm like file push risk. Gyazo disclosed about 23.62 million user records and about 490 million image metadata records after a 2026-09-11 upload server intrusion. PhantomRaven npm stealer tied to JPD publishers. ShinyHunters posted Kimberly-Clark on a leak site without independent breach confirmation. Apache Nutch CVE-2026-41870 family is disclosed only, fixed by removing the Nutch Server component in 1.23.

[+] Leadership take: patch and triage ISE, Secure Email, FMC, Windows, Pixel, Acronis, GitLab, RouterOS, and Conductor on emergency change. Hunt MeshAgent and gdrv.sys before ransom notes appear. Do not treat a closed patch ticket as forensic closure on any KEV item that requires triage.

Chapter 02 - Threat & Exposure Analysis

Unauthenticated administrative planes and opportunistic ransomware ran in parallel. The same week that ISE and Secure Email Gateway went to KEV, operators also faced FMC multi actor abuse, a GitLab file read that landed in exploits inside a day, and a ransomware crew that kills recovery before it encrypts.

[+] Cisco ISE CVE-2026-76460: Insufficient authentication on a privileged API endpoint (CWE-648) in ISE and ISE-PIC, independent of device configuration. An unauthenticated attacker on the management or control plane sends a crafted request and bypasses the web management interface. Cisco PSIRT learned of live use during a TAC case and published cisco-sa-ISE-ABP-VNSW7Tn5 on 2026-09-16. CISA listed it the same day with forensic triage = Yes, known ransomware use = Unknown, and a 2026-09-19 federal date. Consulted trackers state root command execution is achievable when chained. Root on ISE means log wiping, certificate and admin tampering, RADIUS TACACS+ pxGrid policy edits, and a pivot through every NAD that trusts that node. Exact endpoint and request shape remain unpublished. ISE 3.0 is end of maintenance.

[+] Cisco Secure Email Gateway CVE-2026-76461: AsyncOS email parsing fails to sanitize input. A crafted message carrying SQL statements executes arbitrary SQL and escalates to root on the appliance OS with no user action. CVSS 9.8. Advisory 2026-09-15, KEV 2026-09-14, Rapid7 and related consults treat it as zero day because attacks predated disclosure. Cisco contacted Secure Email Cloud customers after detecting malicious activity. Trains: AsyncOS 15.5 before 15.5.5-014, 16.0 before 16.0.4-302, 16.5 before 16.5.0-780. No reliable workaround.

[+] Cisco FMC CVE-2026-20079 and CVE-2026-20316: CVE-2026-20079 is an authentication bypass from an improper system process created at FMC boot. If no legitimate user claims the session, an unauthenticated remote attacker hijacks it and runs scripts as root through crafted HTTP to the FMC web interface. CVE-2026-20316 is a hard coded low privilege static credential used as a chain by at least one set. Talos describes three intrusion sets. UAT-12197 drops a JSP web shell and cmd.jar into the CSM Tomcat webroot, then runs OmniQuery.pl against the internal mdb to pull auth_data. UAT-11823 overlaps previously attributed Sandworm tooling, rewrites license.tmp to trigger a reverse shell, and installs an upgraded 64 bit Cyclops Blink implant with packet sniffing and DNS over HTTPS. UAT-11988 is a Qilin affiliate path that uses the static credential for reconnaissance, disables antivirus, and deploys ransomware. The 2026-09-16 hardening cycle grouped 29 related FMC FTD ASA flaws including CVE-2026-20324 sftunnel arbitrary file write to root and CVE-2026-20341 sftunnel deserialization to root. Those siblings are not reported as exploited in consulted sources.

[+] Microsoft CVE-2026-81963 and CVE-2026-85880: September 2026 Patch Tuesday closed 966 CVEs with 113 Critical. CVE-2026-81963 is improper link following in the Windows Update Stack (CWE-59). A local low privilege attacker escapes AppContainer to SYSTEM. It is the first in the wild zero day for that component. CVE-2026-85880 is a heap buffer overflow in Windows ALPC. Same impact, second ALPC zero day since CVE-2023-21674. Both listed in KEV the day they shipped. Actor unnamed.

[+] Google Pixel CVE-2026-58704: Logic error in cellular modem firmware allows a permission check bypass over an adjacent radio path. No tap, no link, no app. CVSS 8.0. Google says limited targeted exploitation. Fixed in the September 2026 Pixel update at patch level 2026-09-05 or later. All supported Pixel devices in that bulletin are in scope. CISA KEV 2026-09-16. Actor unnamed. Victimology unpublished.

[+] Acronis CVE-2026-87886: Incorrect default permissions (CWE-732) in the Backup plugin for cPanel and WHM, the Plesk extension, and DirectAdmin builds named in consults. A low privilege tenant can escalate to host privilege on shared backup infrastructure. KEV 2026-09-16, federal date 2026-09-19. Targeted exploitation reported against cPanel WHM deployments. Plesk exploitation not independently confirmed. Vendor portal text was thin in this window.

[+] Settra: Active since Jun 2026, 93 claimed victims, four plus data leaks, no RaaS panel evidence in consulted MOXFIVE notes. Initial access through compromised VPN credentials or unpatched software. Post compromise deploys open source MeshAgent, renamed mvtcs.exe in Jul and default named in Sep, calling 45.13.122[.]7 then 193.5.65[.]114. Sep incidents load Gigabyte gdrv.sys to punch EDR at kernel level. Anti forensics include wevtutil log clear, ipconfig /flushdns, reagentc /disable, diskpart against recovery partitions, and cipher /w overwrites. Payloads use [victim domain]_win64.exe from C:\Perflogs or user Documents. Extensions moved from .locked to .locked_wip. Note is RESTORE_FILES.txt. Talks move to Tox. Targeting is sector agnostic.

[+] Check Point CVE-2026-91843: Pre authentication stack overflow in the login process of Security Management Server, Multi Domain Security Management Server, Log Server, and Multi Domain Log Server. Censys style reproduction uses an extremely long username. CVSS 9.8. Check Point and CISA recorded no exploitation as of 2026-09-17. Fix is LivePatch sk1000155. Detection string: Administrator failed to log in: Username too long.

[+] MikroTik MikroTrick CVE-2026-67276 plus CVE-2026-86060, with Bishop Fox variant CVE-2026-67279: Stage one bypasses SSH authentication through incomplete RSA public key verification. Stage two feeds a crafted username such as -2 to a legacy login helper and receives full administrative rights. Exploitation against internet exposed SSH observed from 2026-09-02. Post compromise artifacts include extra full privilege accounts, scripts, and schedulers that recreate a privileged account. Suspicious objects may show owner="0" instead of owner="admin". RouterOS login history is memory resident and dies on reboot. Patching does not remove persistence. Fixed: RouterOS 6.49.21, 7.23.4, 7.24.2.

[+] Orkes Conductor CVE-2026-58138: INLINE, LAMBDA, DO_WHILE, and SWITCH tasks evaluate attacker JavaScript or Python on GraalVM with HostAccess.ALL, which disables the sandbox. Default open source server has no authentication. One unauthenticated POST registers a hostile INLINE workflow and starts it as the Conductor process, often root. Patched in 3.30.2 in Jun. In the wild from 2026-08-21. Fortinet blocked about 1300 attempts on 2026-09-08 through 2026-09-09.

[+] GitLab CVE-2026-85706: Improper path confinement plus missing authentication on /api/v4/projects/{id}/repository/commits/. Workhorse regex checks bypass via trailing slash, .json suffix, or percent encoding such as %63ommits. A POST with file.path containing ../ returns files readable by the GitLab process, including .env, gitlab.yml, SSH keys, and CI/CD variables, often echoed in Rack errors such as invalid %-encoding. CVSS 10.0. Exploited within 24 hours of the 2026-09-11 patch. KEV 2026-09-14. Affected CE/EE 18.7 before 19.1.8, 19.2 before 19.2.6, 19.3 before 19.3.2.

[+] Gyazo / Helpfeel: On 2026-09-11 a third party abused an image upload server vulnerability, ran arbitrary commands, and reached the database. Access routes were blocked by early 2026-09-12. Disclosure 2026-09-16: about 23.62 million user records including emails and password hashes, plus about 490 million image metadata records. Unique image IDs can reconstruct image URLs.

[+] CaptiveCrunch Storm-2945: Microsoft describes a Midnight Blizzard subcluster manipulating DNS and HTTP on hospitality networks, dropping travelers into device code phishing on a legitimate Microsoft sign in page or into fake updates that steal credentials, session tokens, security configuration, and remote access history. Single vendor in this window.

[+] PhantomRaven: CrowdStrike describes an LLM flavored JavaScript stealer in typosquatted npm packages transform-jsbi-to-bigint and sort-imports-es6-autofix, publishers jpdhellonpm1, jpd15, jpd12, jpd13, npmhell, jpdhackerone11. Collects mail addresses, fingerprints, and CI/CD variables. Actor JPD claims bug bounty work and has been active since 2022-11.

[+] ShinyHunters / Kimberly-Clark: Leak site post on 2026-09-13 with a 2026-09-16 deadline and language about digital problems. No independent confirmation of intrusion or theft appeared by window close. Historical ShinyHunters tradecraft (vishing, Okta hijack, Salesforce and Snowflake theft) is context, not proof of this incident.

[+] Apache Nutch CVE-2026-41870, CVE-2026-41871, CVE-2026-41869: Unauthenticated JEXL RCE, missing auth plus unsafe reflection job execution, and missing auth plus improper shutdown denial of service on Nutch Server in 1.10 through 1.22. Fixed in 1.23 by removing the component. No KEV, no known exploitation, no public proof of concept in consulted sources.

[+] ScreenConnect CVE-2026-84869 remains a post deadline context item. Unpatched clients that accept TransferFiles style push and execute through live sessions should be treated as suspect.

Chapter 03 - Operational Response

Work the KEV clock first, then hunt persistence that survives a patch.

[+] Cisco ISE CVE-2026-76460 P0: Inventory every ISE and ISE-PIC node including MSP, managed NAC, SASE, and campus vendor nodes. Record exact release plus patch against 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4. Migrate ISE 3.0. Restrict management with iACLs during the window. Pull ise-kong/access.log and ./ise/logs/apigateway/access.log on every node, not only the primary. Hunt odd usernames including dummyuser as a non exhaustive example. Compare firewall, NetFlow, and proxy telemetry for ISE originated egress. Root can wipe local logs, so off box telemetry is the record. If compromise is plausible, reimage, restore from a clean config backup, and revalidate admins, certificates, authorization policies, pxGrid trusts, and RADIUS TACACS+ secrets. Demand vendor attestation per node by 2026-09-19.

[+] Cisco Secure Email Gateway CVE-2026-76461 P0: Inventory AsyncOS appliances. Upgrade to 15.5.5-014, 16.0.4-302, 16.5.0-780 or later. Review mail_logs for SQL error leakage and system_logs for unexpected command execution. Check for new admin accounts and config drift. Cloud customers should confirm whether Cisco already flagged their tenant.

[+] Cisco FMC CVE-2026-20079 P0: Confirm patch state against the already passed federal date. Hunt license.tmp staging, cmd.jar and JSP in Tomcat webroot, OmniQuery.pl against mdb, unexpected sftunnel use, and Cyclops Blink style outbound DNS over HTTPS. Treat Qilin affiliate behavior as ransomware prep. Rebuild rather than tidy any FMC that shows web shell artifacts.

[+] Windows CVE-2026-81963 and CVE-2026-85880 P0: Deploy September 2026 Patch Tuesday everywhere. Lead with domain controllers, PAW, jump hosts, VDI, and internet facing servers. Watch wuauclt.exe and Update related svchost.exe spawning shells as SYSTEM. Watch lsass.exe ALPC oddities from low integrity parents. Event 4672 plus an AppContainer parent is the correlation to keep.

[+] Pixel CVE-2026-58704 P1: Enforce patch level 2026-09-05 or later through MDM. Block unmanaged or unpatched Pixels from corporate resources. High risk users can reduce radio time, but that is not a fix.

[+] Acronis CVE-2026-87886 P1: Upgrade cPanel WHM plugin to 1.9.3.1021 or 1.9.4.1022, Plesk extension to 1.8.11.638 or later, DirectAdmin plugin to 1.2.3.238 or later. Audit tenant isolation and auth logs for sudo or su from hosting users into Acronis paths.

[+] Settra P1: Hunt MeshAgent and mvtcs.exe, outbound 45.13.122[.]7 and 193.5.65[.]114, certificate CN matches on those addresses, Sysmon 6 loads of gdrv.sys, reagentc /disable, diskpart recovery edits, cipher /w, wevtutil cl, Event 1102. Quarantine hits, revoke VPN credentials, unload the driver, restore from offline immutable backups. Do not pay. Tox negotiation is criminal contact.

[+] Check Point CVE-2026-91843 P1: Apply LivePatch sk1000155. Alert on Username too long in admin login logs and on usernames longer than 512 bytes.

[+] MikroTik P1: Capture config, accounts, scripts, schedulers, proxies, and tunnels before reboot or reset. Upgrade to 6.49.21, 7.23.4, or 7.24.2. Hunt owner="0" and usernames matching ^-[0-9]+$. Rotate secrets on any exposed box. Patching alone leaves persistence.

[+] Orkes P1: Upgrade to 3.30.2 or later. Authenticate and firewall the workflow API. Review INLINE and LAMBDA submissions since 2026-08-21.

[+] GitLab CVE-2026-85706 P0 for self managed: Upgrade to 19.1.8, 19.2.6, or 19.3.2. Hunt unauthenticated POST to /api/v4/projects//repository/commits with file.path and ../. Rotate SSH keys, deploy tokens, database secrets, and CI/CD variables. Audit users, projects, and webhooks created after 2026-09-11.

[+] Gyazo users P2: Force password resets, revoke sessions, expect phishing that weaponizes reconstructed image URLs.

[+] PhantomRaven P2: Remove transform-jsbi-to-bigint and sort-imports-es6-autofix. Block the JPD publisher handles. Rotate developer and CI secrets. Prefer a private registry and signed packages.

[+] CaptiveCrunch P2 for hospitality: Constrain device code flow in Conditional Access. Brief front of house networks on captive portal tampering.

[+] ShinyHunters claim P2: Monitor the leak site. Do not treat the post as confirmed compromise. Verify backups and watch Okta impossible travel only as general hygiene.

[+] Apache Nutch P2: Upgrade to 1.23 so the vulnerable Nutch Server component is gone.

[+] ScreenConnect P1 if still unpatched: Isolate, assume file push abuse, rotate access.

Time IST

Event

2022-11

JPD publisher activity that later maps to PhantomRaven

2026-06

Settra campaign start in consulted victimology

2026-08-21

Orkes Conductor exploitation identified

2026-09-02

MikroTrick exploitation observed on exposed RouterOS SSH

2026-09-05

CERT Polska discloses six RouterOS flaws

2026-09-08 to 2026-09-09

Fortinet blocks about 1300 Orkes attempts

2026-09-09

Talos public on CVE-2026-20079 exploitation

2026-09-11

GitLab patches CVE-2026-85706. Gyazo upload intrusion. Acronis fixed plugin builds. ScreenConnect KEV context

2026-09-12

Gyazo access routes blocked. GitLab public detail expands

2026-09-13

ShinyHunters posts Kimberly-Clark

2026-09-14

Cisco discloses CVE-2026-76461. CISA KEV for CVE-2026-76461 and CVE-2026-85706. GitLab exploitation reported inside 24 hours of disclosure

2026-09-15

Pixel bulletin fixes CVE-2026-58704. CrowdStrike PhantomRaven analysis

2026-09-16

Cisco ISE advisory and KEV for CVE-2026-76460, CVE-2026-87886, CVE-2026-58704. Microsoft Patch Tuesday with two exploited zero days. Gyazo disclosure. Check Point sk1000155. FMC hardening cycle siblings published

2026-09-17

Trade press ISE analyses. Huntress Settra detail. SEG KEV date passes. Check Point exploitation recorded as none

2026-09-18

CSA Singapore, JPCERT/CC, AhnLab Secure Email alerts. Pixel targeted use restated. Settra coverage expands. Window close 19:10 IST

2026-09-19

Federal date for CVE-2026-76460, CVE-2026-87886, CVE-2026-58704

2026-09-28

Single consult states CISA weekly vulnerability bulletin ends. Treat as unconfirmed

Chapter 04 - Detection Intelligence

[+] CVE-2026-76460: CWE-648 privileged API misuse in the Kong gateway layer of ISE and ISE-PIC 3.1.0 through 3.5.0. Authentication is not enforced before a privileged endpoint runs. One crafted unauthenticated HTTP request bypasses web management. ISE is a hardened Linux appliance, so post bypass admin actions are device wide. First fixed: 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4.

[+] CVE-2026-76461: Pre authentication SQL injection in AsyncOS parsing. Injected SQL in headers, body, or attachments rides the normal mail path to root OS command execution.

[+] CVE-2026-20079: Boot time system process creates a session that can be claimed by an unauthenticated HTTP client if a legitimate user never binds it. Combined with CVE-2026-20316 static credential, operators get script execution as root and a path into Tomcat webroot.

[+] CVE-2026-81963: Link following in Windows Update Stack lets a low integrity or AppContainer process plant a path that Update processing follows into SYSTEM.

[+] CVE-2026-85880: ALPC heap overflow from a low privilege client to a SYSTEM service, token escape out of the sandbox.

[+] CVE-2026-58704: CWE-284 style permission check failure in Pixel modem firmware. Adjacent radio input escalates inside the modem context and can reach host data. Host EDR cannot see the first hop.

[+] CVE-2026-87886: World accessible or mis-permissioned files under Acronis plugin paths on cPanel, Plesk, and DirectAdmin allow local privilege escalation to host root.

[+] CVE-2026-91843: Stack buffer overflow in a pre authentication login handler triggered by an oversized username.

[+] MikroTrick: Incomplete RSA public key verification opens SSH without the private key. A crafted username is then parsed as an instruction by a legacy helper, which applies an attacker chosen identity and policy mask.

[+] CVE-2026-58138: GraalVM HostAccess.ALL on INLINE class tasks turns user expressions into Java Runtime or ProcessBuilder calls.

[+] CVE-2026-85706: file.path is not confined to the repository root and Workhorse auth regex is bypassed by slash, .json, or percent encoding. Rails opens the traversal target and leaks content through error pages.

[+] Settra chain: VPN credential reuse, MeshAgent C2, gdrv.sys kernel callbacks, then a recovery destruction sequence before [domain]_win64.exe encrypts and drops RESTORE_FILES.txt.

[+] Nutch 1.10 to 1.22: JEXL injection and unsafe reflection on an unauthenticated REST job API. 1.23 deletes the component.

[+] Gyazo: command execution on the image upload server to database access. Image IDs are enough to rebuild public URLs.

[+] Network high confidence: 45.13.122[.]7 MeshAgent C2 Jul Settra. 193.5.65[.]114 MeshAgent C2 Sep Settra, certificate CN match.

[+] Network low confidence do not operationalize alone: 208.123.119[.]215, 89.34.96[.]x reported as Cyclops Blink C2 by a single consult.

[+] Host files: mvtcs.exe renamed MeshAgent. [domain]_win64.exe Settra payload pattern. license.tmp FMC staging. cmd.jar FMC Tomcat executor. RESTORE_FILES.txt Settra note. JSP web shell in CSM Tomcat webroot, filename unpublished.

[+] Driver: gdrv.sys Gigabyte BYOVD, historical CVE-2018-19320 pairing, SHA256 insufficient.

[+] Extensions: .locked Jul Settra. .locked_wip Sep Settra.

[+] Names: WIN-LIVFRVQFMKO workstation. dummyuser ISE hunt example, non exhaustive.

[+] Paths: ise-kong/access.log. ./ise/logs/apigateway/access.log from support bundles. C:\Perflogs Jul launch. %USERPROFILE%\Documents Sep launch. /usr/local/cpanel/base/3rdparty/acronis/ and Plesk Acronis paths for permission audit.

[+] Log signatures: Check Point Administrator failed to log in: Username too long. GitLab Rack invalid %-encoding with ../. RouterOS usernames matching ^-[0-9]+$. ISE API success with empty or odd user from outside approved admin networks.

[+] Packages: transform-jsbi-to-bigint, sort-imports-es6-autofix. Publishers jpdhellonpm1, jpd15, jpd12, jpd13, npmhell, jpdhackerone11.

[+] Workflow objects: Orkes taskType INLINE with java.lang.Runtime, ProcessBuilder, /bin/sh, or cmd.exe. RouterOS objects with owner="0" and schedulers that recreate privileged users.

Coverage is strong where hosts emit process, driver, and API logs. It is weak on the Pixel modem and on appliances that can wipe their own disks after root.

[+] Coverage snapshot:

Item

SIGMA or equivalent

EDR behavior

Network

Log hunt

Coverage

Cisco ISE

Yes

Process tree, file, egress

ISE originated flows

ise-kong/access.log

High

Secure Email Gateway

Yes

Limited on appliance

Limited

mail_logs, system_logs

Moderate

Windows zero days

Yes

AppContainer to SYSTEM

Weak

Events 4672, 4688

High

Pixel modem

No host view

No

Specialized radio

No

Low, patch only

Acronis

Weak

Auth and sudo

No

auth.log, plugin paths

Low to moderate

Settra

Yes

Driver, process, file

MeshAgent C2

Events 1102, 4688

High

FMC clusters

Behavioral

Tomcat webroot, license.tmp

DoH, reverse shell

FMC audit

Moderate

GitLab

Yes

Weak

Unauth POST

Rack errors

High

Check Point

Yes

Weak

Weak

Username too long

Moderate

MikroTik

On box CLI

Weak

SSH anomalies

owner="0", crafted user

Moderate

Orkes

YARA on workflows

Interpreter spawn

Workflow API

API bodies

Moderate

Nutch

REST anomalies

Java child process

Job API

Access logs

Moderate

PhantomRaven

Package install

Outbound from npm

Unknown C2

npm audit

Moderate

[+] Detection gaps: Pixel baseband has no useful endpoint sensor. Acronis vendor text in this window was too thin for a precise signature. Secure Email and ISE can lose local evidence after root. Attribution gaps mean there is no actor specific C2 list for the vulnerability clusters.

title: Cisco ISE Unauthenticated API Access Anomaly
id: cti-2026-0918-cisco-ise-api-bypass
status: experimental
description: Suspicious unauthenticated access to Cisco ISE management API paths that may indicate CVE-2026-76460
logsource:
  product: network
  service: firewall
  category: network_connection
detection:
  selection_ise_mgmt:
    destination.port: [443, 8443, 9060, 9061]


title: Cisco Secure Email Gateway SQL Injection Attempt
id: cti-2026-0918-cisco-secemail-sqli
status: experimental
logsource:
  product: email
  service: cisco_secemail
  category: email_received
detection:
  selection_sqli_patterns:
    subject|body|attachment.content|header.*:
      - "(?i)(union.*select|select.*from|insert.*into|update.*set|delete.*from|drop.*table|exec|execute|xp_cmdshell|sp_executesql)"
      - "(?i)('|--|;|/\\*|\\*/|@@version|@@servername|waitfor.*delay|benchmark.*\\(|sleep\\


title: Vulnerable Gigabyte Driver gdrv.sys Load
id: cti-2026-0918-settra-byvd-gdrv
status: experimental
logsource:
  product: windows
  service: sysmon
  category: driver_load
detection:
  selection_driver:
    ImageLoaded|endswith: "gdrv.sys"
  selection_context:
    Image|contains: ["cmd.exe", "powershell.exe", "rundll32.exe", "regsvr32.exe", "msiexec.exe"]






title: GitLab Commits API Path Traversal
id: cti-2026-0918-gitlab-path-traversal
status: experimental
logsource:
  product: gitlab
  service: web_server
detection:
  selection:
    http.request.method: "POST"
    http.request.uri.path|contains: "/api/v4/projects/"
    http.request.uri.path|contains: "/repository/commits"
    http.request.body|contains: "file.path="
    http.request.body|contains: "../"
    http.response.status_code: [400, 500]




rule Orkes_Conductor_Hostile_Inline_Task_CVE_2026_58138 {
  meta:
    desc = "INLINE task carrying host execution primitives"
  strings:
    $task = "\"taskType\"




rule PhantomRaven_Stealer_Code {
  strings:
    $comment_pattern = /\/\/\s+[A-Z][a-z]+\s+global\s+variable/i
    $exfil_pattern = /fetch\(['"]hxxps?:\/\/[^\)]+['"],\s*{method:\s*['"]POST['"]

[+] ISE SIEM idea: successful API or admin events without a prior RADIUS or login from the same source in five minutes, plus any ISE node not on the fixed patch matrix.

[+] SEG CLI hunt: grep SQL syntax and command words in /var/log/mail_logs/current and /var/log/system_logs/current.

[+] RouterOS hunt: /user print detail, /system script print, /system scheduler print, /system logging print, and alert on usernames matching ^-[0-9]+$.

[+] MeshAgent hunt: process name mvtcs.exe or MeshAgent, outbound 45.13.122[.]7 or 193.5.65[.]114.

Technique to detection pairing. All inferred mappings carry a behavioral basis. No vendor published a full official ATT&CK annex in this window.

Technique

Basis

Detection object

T1190

ISE API, SEG mail SQLi, FMC HTTP, GitLab commits API, Check Point login, Orkes API, MikroTik SSH

ISE, SEG, GitLab, Check Point rules above

T1210

ISE and FMC root after bypass

ISE egress and FMC webroot hunt

T1068

Windows zero days, Pixel modem, Acronis permissions, gdrv.sys

EoP token rule, MDM patch, auth logs, driver load rule

T1211

gdrv.sys used to kill agents

Driver load rule

T1505.003

FMC JSP, possible ISE or Nutch web shell

Tomcat webroot, Java child processes

T1059.003

Settra cmd, diskpart, cipher, wevtutil

Anti recovery rule

T1059.004

Root shells on Linux appliances

Appliance process and egress

T1105

MeshAgent, Cyclops Blink

IOC addresses and license.tmp

T1070.001 T1070.004 T1490

Settra log clear and recovery wipe

Anti recovery rule, Event 1102

T1486

Settra and Qilin affiliate

.locked, .locked_wip, RESTORE_FILES.txt

T1136 T1053

RouterOS extra accounts and schedulers

owner="0" CLI hunt

T1552 T1552.001

FMC auth_data, GitLab file read

OmniQuery.pl, Rack errors

T1528

CaptiveCrunch device code tokens

Conditional Access anomalies

T1195.002 T1036.005

PhantomRaven packages

npm publisher and package rules

T1040 T1071.004

Cyclops Blink sniff and DoH

FMC outbound DoH

T1546.012

Nutch reflection jobs

REST job API anomalies

T1562.001

Qilin affiliate disables AV

Security tool stop events

[+] D3FEND: D3-PLA inventory of ISE, SEG, FMC, Pixel, Windows, Acronis, GitLab, RouterOS, Conductor. D3-NM restrict management planes and watch ISE egress plus MeshAgent C2. D3-HLA block gdrv.sys. D3-SBR reimage compromised ISE or FMC. D3-PM Sysmon driver and process creation. D3-LLA centralize ise-kong/access.log, Windows Security, GitLab access, RouterOS config.

Chapter 05 - Governance, Risk & Compliance

KEV dates turn several of these from patch backlog into audit findings.

[+] Cisco ISE CVE-2026-76460: BOD 26-04 requires forensic triage by 2026-09-19 for FCEB, not a patch ticket alone. MSP operated ISE is third party risk. A compromised vendor node is a compromised admission fabric. Demand written per node attestation. NIS2, CIRCIA, and UK NIS notification clocks can start if identity or essential service impact is found. Insurers may exclude unpatched KEV after the date. Keep the triage file.

[+] Cisco Secure Email Gateway CVE-2026-76461: Same KEV logic, date already passed on 2026-09-17. Mail gateway compromise exposes inbound and outbound content, attachments, and privilege. GDPR Art. 33/34, CCPA, and HIPAA clocks start on discovery. MSPs that host mail inherit contractual notice duties.

[+] Cisco FMC CVE-2026-20079: Federal date already passed. Multi actor use including a ransomware affiliate makes this a board level control failure on the firewall brain, not a routine advisory.

[+] Windows zero days: 966 CVEs and two exploited elevations create enterprise wide evidence needs for PCI DSS 6.5.6, SOX, and HIPAA Security Rule patch tracking. Tier 0 and PAW miss here is a reportable control gap.

[+] Pixel CVE-2026-58704: Conditional access must enforce patch level 2026-09-05 or later. Zero click bypasses awareness training. NIST 800-124 and ISO 27001 Annex A.6.2.1 are the mobile control references. Targeted use implies executive protection briefing.

[+] Acronis CVE-2026-87886: Shared hosting tenant isolation failure is a GDPR, SOC 2, and ISO 27001 event if cross tenant access occurred. Federal date 2026-09-19.

[+] GitLab CVE-2026-85706: Source and CI/CD secret exposure can be material under SEC disclosure, SOC 2 confidentiality, and GDPR if personal data sat in those files. Rotate secrets even when logs look clean.

[+] Settra: Double extortion plus confirmed leaks starts 72 hour notice clocks. Anti forensics can delay timelines. Document impairment. OFAC and insurer rules weigh against payment. Law enforcement contact is the defensible path.

[+] Gyazo: 23.62 million user records and 490 million metadata records create downstream notice questions for EU and UK processors. Action not confirmed per jurisdiction in consulted sources.

[+] MikroTik and Orkes: Internet reachable admin planes without authentication or with broken SSH checks are a measurable hygiene class. Inventory is the control.

[+] ShinyHunters claim: No confirmed regulatory threshold met because the breach itself is unverified. Do not notify solely on a leak site post.

[+] Vodafone España €400000 GDPR fine reported 2026-09-17 after a service provider ransomware event is the reminder on third party oversight. Single consult item, used as context only.

[+] CISA weekly bulletin retirement on 2026-09-28 is a single consult claim. Plan as if KEV and live exploitation evidence remain the prioritization spine.

Chapter 06 - Adversary Emulation

Lab and owned assets only. Do not fire withheld ISE payloads or public exploit code at production.

[+] ISE API bypass: On a lab 3.4 Patch 6 node, generate unauthenticated management API calls from a non admin network. Validate the ISE API anomaly rule, ise-kong/access.log source oddity, and NetFlow egress. Blue team applies iACLs, hunts, reimages, and restores config. Do not attempt root post exploitation on a live cluster.

[+] ISE as pivot: On an isolated lab with a downstream NAD, show how a hostile authorization profile or pxGrid trust would look. Validate RADIUS and pxGrid change alerts.

[+] Secure Email SQLi: On lab AsyncOS 16.0.3 send a mail with SQL tokens in header or body. Expect log leakage or parser faults. Confirm the SEG rule and system_logs process spawn.

[+] Windows EoP: On pre patch Windows 11 24H2, use a low integrity AppContainer parent and watch for Event 4672 plus SYSTEM token. Public proof of concept was not in consulted sources. Stop at detection validation.

[+] Settra MeshAgent: Launch renamed mvtcs.exe against a mock MeshCentral. Confirm process creation and C2 address match.

[+] Settra BYOVD: Load gdrv.sys via a lab service. Confirm Sysmon 6 and kernel callback visibility. Unload and delete after.

[+] Settra anti recovery: reagentc /disable, diskpart recovery, cipher /w, wevtutil cl. Confirm the anti recovery rule and Event 1102.

[+] Settra encrypt simulation: harmless canary files to .locked_wip plus RESTORE_FILES.txt. Confirm file monitors.

[+] Check Point long username: scripted logins over 512 bytes against a patched build. Alert must fire. No code execution expected.

[+] MikroTrick: On lab RouterOS below 7.24.2 with lab SSH only, show extra accounts and owner="0" schedulers after the chain. Confirm hunting commands.

[+] Orkes INLINE: Unauthenticated POST of an INLINE task that runs a benign marker, not a destructive command, on Conductor below 3.30.2. YARA must match the stored workflow.

[+] GitLab traversal: POST file.path=../../../../etc/passwd style against a disposable self managed instance below 19.1.8. Confirm the GitLab rule and Rack error leak. Rotate lab secrets after.

[+] CaptiveCrunch purple: Simulated device code phishing and fake update lure. Measure helpdesk report rate and Conditional Access blocks.

[+] PhantomRaven purple: Install known bad package names in an isolated runner. Confirm SCA and npm audit alerts.

[+] Safety: no production ISE bypass attempts, no rogue base station against staff Pixels, no real ransomware encryptors, no contact with Tox negotiation channels.

Intelligence Confidence84%

Score 84/100.

Factor

Direction

Effect

Cisco ISE vendor plus KEV plus multiple independent consults

Positive

Strong

Cisco Secure Email vendor plus KEV plus CERT alerts

Positive

Strong

Microsoft official Patch Tuesday plus same day KEV

Positive

Strong

Google Pixel bulletin plus KEV plus targeted use statement

Positive

Strong

GitLab advisory plus KEV plus 24 hour exploitation reporting

Positive

Strong

Huntress Settra TTPs plus corroborating consults

Positive

Strong

Talos FMC three cluster narrative

Positive

Moderate. Second major house thin

Acronis KEV listing

Positive

Moderate. Vendor text thin here

MikroTik CERT Polska plus Bishop Fox persistence

Positive

Moderate

Orkes Empirical plus Fortinet numbers

Positive

Moderate. Some relayed through trade press

Check Point as exploited

Negative

Not observed

Apache Nutch exploitation

Negative

None known

CaptiveCrunch Midnight Blizzard link

Negative

Single vendor

Cyclops Blink IP fragments

Negative

Single consult

ShinyHunters Kimberly-Clark theft

Negative

Claim only

Withheld ISE request shape and missing hashes

Negative

Limits detection precision

Attribution gaps on most exploit clusters

Negative

Caps score under 90

[+] Net: exploitation status is solid for the KEV set and for Settra tradecraft. Actor names and atomic IOC depth are not. Keep the score in the mid 80s until Cisco, CISA, or Talos publish indicators or a second house restates the Sandworm overlap.