Top Cyber Security Vulnerabilities – September 2026 Roundup

CVE-roundup-september-2026

September 2026 brought the largest Microsoft Patch Tuesday on record and a steady run of exploited flaws in network edge and management products. CISA added 43 vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog during the month, and 35 of them carried a three-day remediation deadline for US federal agencies under Binding Operational Directive 26-04.

Microsoft fixed more than 960 CVEs on 8 September, a rise that follows its adoption of an AI-assisted vulnerability discovery system. Two of those flaws, both Windows privilege escalation bugs, were already being exploited. Outside Microsoft, attackers targeted products that sit at the edge of the network or manage many other systems: Citrix NetScaler, Check Point gateways and management servers, F5 BIG-IP APM, Cisco Secure Email Gateway, and the N-able N-central and ConnectWise ScreenConnect remote management tools.

Several of these flaws were exploited before a patch existed, and others were attacked within hours or days of a fix being published. The nine entries below cover the vulnerabilities most relevant to enterprise environments, with the affected versions and the actions needed to close each one.

Windows ALPC and Windows Update Stack Elevation of Privilege Zero-Days – CVE-2026-85880 and CVE-2026-81963

Overview: Two local privilege escalation flaws fixed in the September Patch Tuesday release were already being exploited when Microsoft published them. CVE-2026-85880 is in Windows Advanced Local Procedure Call (ALPC), the mechanism Windows processes use to communicate with each other. CVE-2026-81963 is in the Windows Update Stack. Both allow an attacker who already has code running on a machine to gain SYSTEM privileges.

Severity and score: High, CVSS 7.8 for both. Microsoft rates them Important.

Type: Heap-based buffer overflow and use of uninitialised resource, CWE-122 and CWE-908 (CVE-2026-85880). Improper link resolution before file access and improper access control, CWE-59 and CWE-284 (CVE-2026-81963).

Disclosure: Microsoft patched both on 8 September 2026. It credited researchers from Volexity and Proofpoint for the ALPC flaw, and Zhang WangJunJie of Hillstone Networks, Romain Deperne and the Microsoft Threat Intelligence Center for the Update Stack flaw. The ALPC flaw affects Windows 10 and Windows Server 2012 to 2022. The Update Stack flaw affects Windows 11 and Windows Server 2025.

Exploitation: CISA added both to the KEV catalog on 8 September with a remediation date of 22 September. Microsoft has not published details of the attacks, the groups behind them or the scale of the activity. Flaws of this type are used after an attacker has gained initial access, for example through phishing or stolen credentials, to take full control of the machine.

Mitigation: Install the September 2026 cumulative updates on all supported Windows desktops and servers. Prioritise systems where users open email attachments and downloaded documents, and servers that other users can log on to. In endpoint detection tooling, review alerts for processes running as SYSTEM that were started from a standard user session.

N-able N-central Pre-Authentication Remote Code Execution – CVE-2026-86218

Overview: N-central is a remote monitoring and management (RMM) platform that managed service providers and IT teams use to administer client devices. CVE-2026-86218 allows an unauthenticated attacker to run code on the N-central server, and changes made on the server can be pushed to every device it manages. It is the third exploited N-central flaw in two months, following the authentication bypass and incomplete fix covered in our August 2026 roundup.

Severity and score: Critical, CVSS 4.0 score 10.0 (N-able). NVD lists a CVSS 3.1 score of 9.8.

Type: Static code injection, CWE-96.

Disclosure: N-able fixed the flaw in N-central 2026.3 Hotfix 4, which brings the build to 2026.3.1.14, in the first week of September. All builds before 2026.3.1.14 are affected, including 2026.3 and Hotfixes 1 to 3. Hotfix 3 fixed two further flaws, CVE-2026-86206 and CVE-2026-86207, which can be chained to bypass authentication.

Exploitation: Huntress began investigating on 4 September after a fully patched N-central environment belonging to one of its customers was compromised, although it could not confirm which vulnerability was used. N-able stated in a customer notice that CVE-2026-86218 had been observed being exploited in the wild, while its release notes said it had no confirmation of exploitation in production environments. watchTowr reproduced the flaw and confirmed it allows remote code execution with changes that propagate to connected systems. CISA added it to the KEV catalog on 8 September with a deadline of 11 September.

Mitigation: N-able has patched hosted N-central instances. Upgrade every on-premises N-central server to 2026.3.1.14 or later. Review administrator accounts, scheduled tasks and scripts created or pushed through N-central since late August, and check managed devices for remote access software that was not deployed by your team. An RMM platform is a supplier with access to every managed endpoint, so its exposure belongs in your third-party risk reviews.

ConnectWise ScreenConnect Client Unauthorised File Execution – CVE-2026-84869

Overview: A flaw in the ScreenConnect client allows files to be transferred and executed through an active remote session without authorisation or confirmation from the host in some circumstances. ScreenConnect servers are not affected. The issue is in the client software installed on endpoints.

Severity and score: Critical, CVSS 9.9.

Type: Missing authorisation, CWE-862, and improper privilege management, CWE-269.

Disclosure: ConnectWise published the ScreenConnect 26.6.5 security bulletin on 8 September 2026. All versions before 26.6.5 are affected.

Exploitation: Huntress investigated incidents on 20 and 24 August in which rogue ScreenConnect clients ran a chain of VBScript files. Connecting to an infected client could cause the technician’s Host machine to receive and run the same chain. Huntress referred to CVE-2026-84869 as context for these incidents but did not state that they exploited it. CISA added the flaw to the KEV catalog on 11 September with a deadline of 14 September.

Mitigation: ConnectWise updated cloud-hosted instances automatically. On-premises administrators need to install 26.6.5 through the supported upgrade path and confirm that the clients on endpoints have updated. ConnectWise also advises reinstalling Host clients after the upgrade. As a temporary measure, the file transfer permission (TransferFiles, previously named TransferFilesInSession) can be removed from each role and session group under Administration > Security > Roles. Check endpoints for ScreenConnect clients that were not installed by your own IT team or service provider.

Cisco Secure Email Gateway SQL Injection to Root – CVE-2026-76461

Overview: A flaw in the email-parsing logic of Cisco AsyncOS allows an unauthenticated attacker to send a crafted email containing SQL statements through an affected gateway. A successful exploit runs commands with root privileges on the appliance. Physical and virtual appliances are affected regardless of configuration.

Severity and score: Critical, CVSS 9.8.

Type: SQL injection, CWE-89.

Disclosure: Cisco disclosed the flaw on 14 September 2026 after its Product Security Incident Response Team became aware of exploitation. Affected releases are AsyncOS 15.5 and earlier, 16.0 and 16.5. Cisco has upgraded cloud-hosted gateways to 16.5.0-780, so the action falls on customers running their own physical or virtual appliances.

Exploitation: The flaw was exploited before Cisco published a fix. CISA added it to the KEV catalog on 14 September with a deadline of 17 September. Because the attack is delivered as an email, any gateway that receives mail from the internet can be reached without access to its management interface.

Mitigation: Cisco states there are no workarounds. Upgrade to 15.5.5-014, 16.0.4-302 or 16.5.0-780. Search mail_logs for SQL statements, including the pattern COPY.*TO PROGRAM, review cluster device logs where gateways are clustered, and check firewall logs for unexpected outbound connections from the appliance. Our email security services page covers how gateway monitoring fits into mail protection.

Check Point VPN Gateway and Management Server Remote Code Execution – CVE-2026-85102 and CVE-2026-93616

Overview: Two separate flaws affected Check Point products. CVE-2026-85102 is in certificate handling during VPN negotiation on Security Gateways and Spark firewalls: an attacker can send a crafted certificate before authentication completes and run code without credentials. CVE-2026-93616 is a pre-authentication path traversal in the Check Point Management web service, which allows an attacker who can reach the server to upload and run scripts on it.

Severity and score: Critical, CVSS 9.8 for both.

Type: Improper certificate validation, CWE-295 (CVE-2026-85102). Path traversal, CWE-22 (CVE-2026-93616).

Disclosure: Check Point fixed CVE-2026-85102 on 9 September for gateways running Site-to-Site VPN or Remote Access VPN on releases up to R82.10, including the end-of-support R80.x and R81.x versions (advisory sk1000117). R82.20 is not affected. It fixed CVE-2026-93616 on 22 September for Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server and SmartEvent (advisory sk1000171).

Exploitation: Exploitation attempts against Spark customers using CVE-2026-85102 began on 12 September, three days after the fix, from VPN services and proxies. CVE-2026-93616 was exploited as a zero-day from as early as 23 July, and Check Point said it was aware of a handful of customers who had been attacked. CISA added both to the KEV catalog on 22 September with a deadline of 25 September.

Mitigation: Install the fixes listed in sk1000117 and sk1000171. LivePatch covers CVE-2026-85102 but not CVE-2026-93616, which needs the Jumbo Hotfix or Security Hotfix listed in sk1000171. Keep Management Servers behind a gateway and limit access to them, including TCP port 19009 and SmartConsole Trusted Clients, to trusted internal IP addresses. On gateways, review logs for certificate-based Mobile Access logins, including the certificate subjects CN=vpn,OU=users,O=global, CN=vpn-user,OU=users,O=global and CN=vpnuser,OU=users,O=global. Check Point advises not limiting the search to these subjects. On management servers, follow the hunting guidance in sk1000171.

F5 BIG-IP APM OAuth Heap Overflow – CVE-2026-94127

Overview: A flaw in BIG-IP Access Policy Manager (APM) allows an unauthenticated attacker to run code by sending crafted traffic to a virtual server. Only systems where APM acts as an OAuth Authorization Server, with an access policy and an OAuth profile on the same virtual server, are exposed. Deployments that use APM only as an OAuth client or resource server are not affected.

Severity and score: Critical, CVSS 9.8 (CVSS 4.0: 9.3).

Type: Heap-based buffer overflow, CWE-122.

Disclosure: F5 published its advisory on 22 September 2026 after finding that the flaw was already being exploited. Affected releases are BIG-IP 21.1.0, 17.5.0 to 17.5.1 and 17.1.0 to 17.1.3.

Exploitation: The flaw was exploited as a zero-day. CISA added it to the KEV catalog on the day of the advisory with a deadline of 25 September.

Mitigation: Check whether any virtual server uses APM as an OAuth Authorization Server. If so, apply the engineering hotfixes F5 has released for the 21.1, 17.5 and 17.1 branches, or request an iRule from F5 Support to reduce exposure until the fix is installed. Monitor for repeated OAuth authentication failures, unexpected commands in audit logs and TMM SIGABRT events.

WordPress Core File Inclusion to Remote Code Execution – CVE-2026-87902

Overview: When WordPress decides which template to use for a page, get_page_template() builds a filename from the pagename request parameter. Path traversal sequences in that parameter allow an unauthenticated attacker to make WordPress include a PHP file from outside the theme directories. On servers where certain conditions are met, this becomes remote code execution.

Severity and score: Critical, CVSS 4.0 score 9.2 (WordPress). CISA lists a CVSS 3.1 score of 8.1.

Type: Improper control of filename for an include statement (PHP file inclusion), CWE-98.

Disclosure: Robert Ressl reported the flaw through HackerOne on 20 July 2026. WordPress fixed it on 22 September in versions 7.1.2, 7.0.6, 6.9.9 and 6.8.10, with backports to every branch down to 4.7.37. All versions from 4.7.0 to 7.1.1 are affected.

Exploitation: The first exploitation attempts were recorded within hours of the fix on 22 September. CrowdSec observed 30,813 unique IP addresses sending matching requests by 28 September. Attackers are targeting PEAR’s pearcmd.php, which leads to code execution when the active theme contains a top-level folder whose name starts with page- and PHP’s register_argc_argv setting is enabled. CISA added the flaw to the KEV catalog on 25 September with a deadline of 28 September.

Mitigation: Confirm every WordPress site is on a fixed release. Sites with automatic minor updates enabled will have received the fix; sites where automatic updates are switched off need a manual update. Where an update cannot be applied straight away, disable register_argc_argv and remove pearcmd.php from the server. These steps block the known exploitation route, but the inclusion flaw remains until WordPress is updated.

Microsoft SharePoint Server Code Injection – CVE-2026-65660

Overview: A code injection flaw in SharePoint Server allows an authenticated attacker with low-level access to run code on the server by sending a crafted request. SharePoint does not escape quotes inside attribute values when it rebuilds Register directives for web-part markup, which allows arbitrary .NET classes to be loaded. Chained with other SharePoint flaws, it can give code execution without authentication on servers that allow anonymous access.

Severity and score: High, CVSS 8.8. Microsoft rates it Important.

Type: Code injection, CWE-94.

Disclosure: Microsoft fixed the flaw in its 11 August 2026 updates and first listed it as a spoofing issue with a CVSS score of 6.5. The flaw was later reclassified as remote code execution with a score of 8.8. It was found by Dinh Ho Anh Khoa of Viettel Cyber Security and affects SharePoint Server 2016, 2019 and Subscription Edition.

Exploitation: Technical details and exploit markup became public on 22 September. Previdian recorded exploitation attempts against its SharePoint honeypot from 24 September, including an attempt to create a webshell at /_layouts/15/sphealth.aspx. Microsoft confirmed it had observed exploitation, and CISA added the flaw to the KEV catalog on 25 September with a deadline of 28 September.

Mitigation: Confirm SharePoint builds are at or above 16.0.19725.20522 for Subscription Edition (KB5002893), 16.0.10417.20198 for 2019 and 16.0.5565.1001 for 2016. Enable AMSI integration with full request-body scanning, restrict access to Central Administration, and check for unexpected .aspx files under /_layouts/15/ and POST requests to AddGallery.aspx and designgallery.aspx. Our Microsoft security services cover SharePoint and Microsoft 365 configuration reviews.

Citrix NetScaler ADC and Gateway Zero-Days – CVE-2026-88771 and CVE-2026-88772

Overview: Citrix security bulletin CTX697096 fixed eight NetScaler ADC and NetScaler Gateway vulnerabilities, two of which were being exploited. CVE-2026-88771 is an input validation flaw that allows an unauthenticated attacker to execute commands, and it affects all configurations, including the default. CVE-2026-88772 is a memory overflow that can lead to remote code execution or denial of service when DTLS is enabled, which it is by default on VPN virtual servers.

Severity and score: Critical, CVSS 4.0 score 9.5 for both.

Type: Improper input validation, CWE-20 (CVE-2026-88771). Improper restriction of operations within the bounds of a memory buffer, CWE-119 (CVE-2026-88772).

Disclosure: Citrix published the bulletin on 27 September 2026. Fixed builds are 14.1-73.37 and 13.1-64.23, with 14.1-73.37 FIPS and 13.1-37.279 for FIPS and NDcPP deployments.

Exploitation: Both flaws were exploited as zero-days during September before the bulletin. Attackers planted a unique webshell on each compromised device and ran commands to delete forensic artefacts. After watchTowr Labs published a proof-of-concept for CVE-2026-88771, exploitation attempts began within minutes and spread to mass scanning. Censys counted around 42,000 internet-facing NetScaler instances at the time. CISA added both to the KEV catalog on 27 September with a deadline of 30 September. A separate NetScaler authentication bypass, CVE-2026-19490, had already been added to the catalog on 9 September.

Mitigation: CISA warns that updating can remove forensic evidence, so preserve logs and device state on any appliance that may already be compromised, then upgrade to the fixed builds and check for signs of compromise as Citrix advises. Because each webshell is unique, it cannot be found by scanning from outside. Review the file system and logs on each appliance, and include NetScaler devices in network penetration testing scope after patching.

What September Showed

Many of the vulnerabilities exploited in September were in systems that control access to other systems: VPN gateways, an email gateway, an access policy manager, firewall management servers and remote management tools. A compromise of one of these products can give an attacker a route to many other devices on the same network.

The time between a fix and the first attack was short. The Check Point VPN flaw was attacked three days after its patch and the WordPress flaw on the day of its fix. Mass exploitation of NetScaler began within minutes of a public proof-of-concept. The Check Point management server flaw, the F5 APM flaw, the Cisco email gateway flaw and the NetScaler flaws were all exploited before a patch was available. CISA set three-day deadlines for 35 of the 43 vulnerabilities it added during the month.

Microsoft’s record release added to the workload. The Zero Day Initiative noted that the rise in AI-assisted discovery has not yet produced a matching rise in active exploitation, but larger monthly releases mean more testing and deployment work for patch teams. Ordering that work by KEV listing, internet exposure and the role of each system, such as gateway, management server or identity service, helps teams decide what to patch first.

Where iConnect Fits In

iConnect’s vulnerability assessment and penetration testing services identify internet-facing systems that run affected versions, including VPN gateways, email gateways and management interfaces. Our SOC services monitor for the indicators listed in this roundup, and our managed security services team can help prioritise patching and check affected devices for signs of compromise. Contact us to review your exposure to the vulnerabilities covered here.

Contact us

Talk to our team about your requirement

We’re happy to answer any questions you may have and help you determine which of our services best fit your needs.

Our Value Proposition

What happens next?

1

We’ll arrange a call at your convenience.

2

We do a discovery and consulting meeting 

3

We’ll prepare a detailed proposal tailored to your requirements.

Schedule a Free Consultation