The Signal, An Offensive Intelligence Digest (Volume 003)
Welcome to the 3rd edition of The Signal, a newsletter designed to improve your signal-to-noise ratio. A monthly digest curated by our Offensive Security Operations Center (OSOC), delivering timely insights into emerging vulnerabilities, threat trends, and the exposures that matter most.
Two Citrix NetScaler zero-days exploited for three weeks before anyone disclosed them. A CVSS 10.0 in Cisco's firewall management plane, hit by a Sandworm-linked group and a ransomware affiliate in the same month. Forty-three new entries on CISA's Known Exploited Vulnerabilities catalog, 23 of them Critical. September belonged to the edge.
Each month, Evolve Security's Offensive Security Operations Center (OSOC) tracks the vulnerabilities and threat actors doing the most damage in the wild, not just the ones making headlines. Here's what mattered in September 2026, and what to do about it.
By the numbers
5 vulnerabilities confirmed exploited in the wild: 4 Critical, 1 High
43 new CISA KEV additions: 23 Critical, 18 High, 2 Medium
10.0: the highest CVSS score of the month (Cisco Secure FMC authentication bypass)
3 distinct threat actors tracked: 2 nation-state groups and 1 ransomware operator
4 of 5: top exploited flaws that hit perimeter or security-management appliances
Threat actors to watch
UAT-11823 (Sandworm-linked; overlaps with APT44 / GRU Unit 74455) · Nation-State
Russia-attributed by Cisco Talos. Exploited Cisco FMC flaws to gain root, deployed Cyclops Blink for persistence, and harvested the configurations of every firewall FMC manages. Motivation: espionage and pre-positioning for disruption. Signature techniques include edge appliance auth bypass, netcat reverse shells, and DNS-over-HTTPS command and control.
Qilin (aka Agenda; affiliate tracked as UAT-11988) · Ransomware
Russian-speaking RaaS operation with a heavy focus on industrial and manufacturing targets. A Qilin affiliate used the same Cisco FMC flaws for initial access, tunneled out via SOCKS5 and reverse SSH, and ran AV and EDR killers before encryption. Expect NTDS.dit dumping and Rclone exfiltration ahead of double extortion.
JungleBamboo (APT31; aka Violet Typhoon, TA412), alongside UTA0560 and UTA0565 · Nation-State
Three China-nexus groups shared a single Chrome and Windows zero-day chain, delivered through spear-phishing with news-themed lures, to install credential-stealing Chrome extensions disguised as Gemini. Targets: government, diplomatic organizations, NGOs, and Asian governments. C2 ran over Cloudflare Tunnel.
The pattern worth noting: state actors and ransomware operators are now converging on the same entry points, in the same month.
Top 5 actively exploited vulnerabilities
Active exploitation in the wild, not disclosure alone, was the bar for this list.
1. CVE-2026-88771 / CVE-2026-88772: Citrix NetScaler ADC and Gateway | CVSS 9.8 | Critical
Two zero-days exploited for roughly three weeks before disclosure on September 27. CVE-2026-88771 allows unauthenticated command execution in the default configuration; CVE-2026-88772 corrupts packet-engine memory over DTLS for pre-auth root RCE. Attackers, suspected state-sponsored per Mandiant, dropped the WHIPSHOT web shell and SLAPSHOT tunneler and stole ns.conf, certificates, and SSH keys from dozens of government, finance, telecom, and legal organizations across North America and Europe. Mass exploitation followed disclosure.
Action: Upgrade to 14.1-73.41+ or 13.1-64.28+ (CTX697096). Patching does not remove backdoors. Hunt for .deb/.sig files executing as PHP, SUID on /bin/sh, and /tmp/.uxdport. Rotate admin, LDAP/RADIUS, and certificate credentials. If patching is delayed, disable DTLS or block UDP/443.
2. CVE-2026-20079: Cisco Secure Firewall Management Center | CVSS 10.0 | Critical
Crafted HTTP requests give unauthenticated root script execution on FMC. Cisco Talos reported on September 9 that three separate clusters were attacking the firewall management plane at once: the Sandworm-linked UAT-11823 deployed Cyclops Blink and harvested managed-firewall configurations, while a Qilin affiliate used companion flaw CVE-2026-20316 to stage ransomware. Disclosed in July; September marked the escalation to state and ransomware exploitation.
Action: Upgrade to 7.0.9, 7.2.11, 7.4.6, 7.6.5, 7.7.12, or 10.0.1 and apply Cisco hotfixes. Deploy the Talos Snort SIDs. Remove FMC management interfaces from internet exposure and review managed-device configurations for tampering.
3. CVE-2026-85102 / CVE-2026-93616: Check Point Security Gateway and Management | CVSS 9.8 | Critical
CVE-2026-85102 is a VPN certificate-validation flaw exploited globally against Spark and Quantum gateways from September 12; attackers authenticated to Mobile Access with forged certificates and scanned internal networks. CVE-2026-93616 is a path traversal on the Management/Log Server that allows unauthenticated script execution. It was targeted since July but undisclosed until September 22. Attacks are unattributed and sourced from VPN and proxy infrastructure.
Action: Install the Jumbo Hotfix or Security Hotfix (LivePatch alone does not fix CVE-2026-93616). Hunt per sk1000171 and sk1000117 for certificate-based Mobile Access logins with CN=vpn, vpn-user, or vpnuser.
4. CVE-2026-94127: F5 BIG-IP APM | CVSS 9.8 | Critical
A heap-based buffer overflow in the BIG-IP data plane allows unauthenticated remote code execution. Only systems where APM acts as an OAuth Authorization Server are exposed. F5 found the flaw internally and confirmed it was already being exploited as a zero-day; CISA set a three-day federal deadline.
Action: Apply engineering hotfixes 21.1.0.2.0.30.22, 17.5.1.9.0.160.12, or 17.1.3.5.0.41.14, or the F5 iRule mitigation. Review /var/log/apm for OAuth token errors and investigate TMM crashes. Preserve core files before remediating.
5. CVE-2026-85046 / CVE-2026-87491: Google Chrome V8 + Windows ALPC chain | CVSS 8.8 | High
Volexity reported on September 9 that JungleBamboo, UTA0560, and UTA0565 used the same zero-day chain in spear-phishing from September 1 to 4: V8 type confusion (CVE-2026-85046), a sandbox escape (CVE-2026-87491), and the Windows ALPC privilege escalation patched September 8 (CVE-2026-85880). Payloads included malicious Chrome extensions posing as Gemini that steal credentials.
Action: Update Chrome to 153.0.8010.36 or later and apply the September Windows cumulative update. Audit managed browsers for unapproved extensions, especially any posing as Gemini.
CISA KEV: the rest of September's additions
Beyond the nine KEV entries tied to the five above, CISA added 34 more in September. Critical-severity additions included SonicWall SMA1000, Sangoma Switchvox, N-able N-central, Adobe Commerce and Magento (two CVEs), Fortinet FortiOS / FortiSwitchManager / FortiSASE, MikroTik RouterOS, GitLab, ConnectWise ScreenConnect, Cisco Secure Email Gateway, Cisco ISE, Cisco Catalyst SD-WAN Manager, WSO2, and Arista VeloCloud Orchestrator.
AI and LLM infrastructure entered KEV in force. LiteLLM, Kestra, Starlette, and JFrog Artifactory were all added on September 2 after attackers harvested API keys and deployed cryptominers. If your teams are self-hosting AI gateways, workflow engines, or artifact repositories, those are now proven targets.
High-severity additions spanned three Linux kernel flaws, Microsoft SharePoint, WordPress Core, the Windows Update Stack, Apple CoreGraphics, Google Pixel, Zyxel GS1900 switches, and Acronis Backup plugins.
Under BOD 26-04, the highest-risk entries now carry three-day federal remediation deadlines. Every organization, regardless of mandate, should treat KEV inclusion as a high-priority remediation signal.
What actually moves your risk
Exposure to September's activity isn't uniform. The variables that determine yours:
Internet exposure of NetScaler, Check Point, F5, Cisco FMC/ISE/SD-WAN, and MikroTik management interfaces. Whether a post-patch compromise assessment was performed, since patching does not remove web shells or implants. Credential, certificate, and key rotation after any suspected appliance compromise. Exposure of self-hosted AI/LLM gateways, workflow engines, and artifact repositories. And browser and OS patch latency against chained client-side zero-days.
What we're watching in October
Expect continued mass exploitation of the NetScaler flaws through October, compounded by a third NetScaler zero-day (CVE-2026-88779) disclosed October 4. Our OSOC is tracking attribution of the state-sponsored NetScaler cluster, ransomware groups adopting September's appliance CVEs for initial access, exploitation of exposed AI/LLM infrastructure in client environments, and public exploit releases for the Check Point and F5 flaws.
The Takeaway
Four of September's five most exploited vulnerabilities hit the devices meant to protect the network: firewalls, VPN gateways, and security management planes. EDR doesn't run on them, and compromise routinely goes unnoticed. The NetScaler zero-days sat undetected for three weeks.
Treat perimeter appliances as assume-breach assets. Patch, then verify nothing was left behind. Evolve Security's Continuous Penetration Testing (CPT) validates that exposed services and compensating controls actually hold between patch cycles, not just whether a box got checked at the last audit.
Questions or Need Help Remediating?
Our team is here for yours. If any of the above touches your environment, reach out to talk with Evolve Security, we'll help you validate the exposure and prioritize what to fix first.
Start Playing Offense. Contact Evolve Security's Offensive Security Operations Center to talk through this month's findings.





