Skip to content
Cyber Times

Independent threat intelligence for security leaders.

Go back

CISO Intelligence Update — Friday, 11 September 2026

🛡️ Cyber Times — CISO Intelligence Update

Friday, 11 September 2026 · Coverage: 10 Sep 2026 08:00 IST → 11 Sep 2026 08:00 IST

The high-confidence sweep produced 35 publishable records. This edition presents 11 source-linked updates across 3 security domains; 9 are marked for priority review.

🔴 Critical Threats & Active Exploitation

CVE-2026-86060 added to CISA KEV — MikroTik RouterOS

CRITICAL — MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacked to change the trusted RouterOS policy mask, leading to privilege escalation. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics…

Defender action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for…

Validation: primary source · Published: 10 Sep 2026 05:30 IST Sources: CISA KEV

CVE-2026-67277 added to CISA KEV — MikroTik RouterOS

CRITICAL — MikroTik RouterOS contains a missing authenticaion for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in…

Defender action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for…

Validation: primary source · Published: 10 Sep 2026 05:30 IST Sources: CISA KEV

🛡️ Vulnerabilities Worth Attention

CVE-2026-89094 — Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.

CRITICAL — NVD CVSS 9.9 (critical). Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 11 Sep 2026 02:47 IST Sources: NVD

CRITICAL — NVD CVSS 9.9 (critical). A Time-of-check Time-of-use (TOCTOU) race condition leading to insecure symlink following in Plesk causes local privilege escalation to root via arbitrary file/directory ownership takeover.

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 10 Sep 2026 22:47 IST Sources: NVD

CVE-2026-68487 — Path traversal in Plesk’s Backup Manager causes arbitrary file write as root by an authenticated customer.

CRITICAL — NVD CVSS 9.9 (critical). Path traversal in Plesk’s Backup Manager causes arbitrary file write as root by an authenticated customer.

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 10 Sep 2026 22:47 IST Sources: NVD

CVE-2026-19583 — Velociraptor allows some sensitive artifacts to be gated by additional permissions

CRITICAL — NVD CVSS 9.9 (critical). Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell artifact allows arbitrary command execution on endpoints, and so it requires the EXECVE permission to schedule. However, no such check was implemented for client monitoring artifacts. Additionally there was no requirement that client monitoring artifacts carry the…

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 10 Sep 2026 08:46 IST Sources: NVD

CVE-2026-81204 — IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary code due to code injection during graph construction.

CRITICAL — NVD CVSS 9.8 (critical). IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary code due to code injection during graph construction.

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 11 Sep 2026 03:47 IST Sources: NVD

CVE-2026-79724 — IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in…

CRITICAL — NVD CVSS 9.8 (critical). IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 11 Sep 2026 03:47 IST Sources: NVD

CVE-2026-78573 — IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 could allow a remote attacker to gain administrative access due to the use of default credentials.

CRITICAL — NVD CVSS 9.8 (critical). IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 could allow a remote attacker to gain administrative access due to the use of default credentials.

Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.

Validation: primary source · Published: 11 Sep 2026 03:46 IST Sources: NVD

🧪 Threat Intelligence & Attack Research

Detect and disrupt AI-themed attacks with Microsoft Defender

INFORMATIONAL — See how Microsoft Defender detects and disrupts AI-themed phishing, malware, and multi-stage attacks across the attack chain. The post Detect and disrupt AI-themed attacks with Microsoft Defender appeared first on Microsoft Security Blog .

Defender action: Review the linked evidence, confirm organizational exposure, and update detections or mitigations where applicable.

Validation: direct source · Published: 10 Sep 2026 21:30 IST Sources: Microsoft Security

The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE

INFORMATIONAL — Learn how root access on a compromised K8s node allows attackers to utilize SPIFFE/SPIRE metadata to spoof and harvest co-located workload identities. The post The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE appeared first on Unit 42 .

Defender action: Review the linked evidence, confirm organizational exposure, and update detections or mitigations where applicable.

Validation: direct source · Published: 10 Sep 2026 15:30 IST Sources: Palo Alto Unit 42

💡 Defensive Priority

Open the linked primary or corroborating evidence before changing production systems. Confirm asset exposure, use vendor guidance for remediation, and retain the source links with the operational change record.


Collection: 2,758 records inspected · 142 passed collection filters · 35 passed the high-confidence evidence gate · 27/28 source endpoints available. Automated intelligence is a triage aid; verify exposure and remediation against the linked primary advisory.


Topics in this briefing

Share this post on:

Previous Post
CISO Intelligence Update — Saturday, 12 September 2026
Next Post
CISO Intelligence Update — Thursday, 10 September 2026