This executive intelligence briefing covers from the past week (2–9 September 2026) and the past month (approximately 10 August – 9 September 2026). CISOs, start here: do not open a 974-row spreadsheet. That queue is the failure mode. This week’s material risk sits in four places you can name before noon: an unauthenticated Adobe Commerce and Magento Open Source remote code execution already exploited in the wild; a remote monitoring and management pre-authentication remote code execution with managed-estate blast radius; internet-facing SAP kernel code that fails before authentication; and package-manager intake that AI coding tools now poison at industrial scale. Patch the internet-facing exploited paths. Rotate identity after any appliance or console that was reachable after disclosure. Put Package Firewall in front of npm, PyPI, and Maven, and subscribe Security Operations to Veracode Software Supply Chain Intelligence. Name who files the EU Cyber Resilience Act 24-hour report on Friday.
TL;DR
Adobe Commerce and Magento Open Source CVE-2026-75650 (CVSS 10.0) was exploited from 4 September. Apply Adobe’s emergency hotfix APSB26-146 and the September isolated patch APSB26-138. Rotate encryption keys and tokens. CISA added it to the Known Exploited Vulnerabilities Catalog with a federal due date of 11 September.
N-able N-central CVE-2026-86218 is pre-authentication remote code execution. On-premises consoles must be on version 2026.3.1.14 today. Hosted tenants were vendor-patched; managed-service estates remain yours. Federal due date: 11 September.
Windows: two exploited local SYSTEM elevation-of-privilege zero-days — CVE-2026-85880 in Windows Advanced Local Procedure Call and CVE-2026-81963 in the Windows Update Stack — federal due date 22 September. Then the unauthenticated remote code execution cluster, with Windows DNS Server CVE-2026-69730 first on Tier-0. Enforce Chrome 153 for the seventh Chrome zero-day of 2026.
SAP OVERPASS, CVE-2026-44756 (CVSS 10.0), was unexploited at publication and is still material if SAP is internet-reachable. Apply SAP Security Note 3747649, or isolate SAP Web Dispatcher.
Package managers and artifact repositories are now initial access. JFrog Artifactory CVE-2026-82329 was exploited within days of disclosure. Google warned that AI coding tools are a primary adversary target. This week: Veracode Package Firewall at ingest, Veracode Software Composition Analysis on what is already committed, and Veracode Software Supply Chain Intelligence on the threat feed. Do not start with a historical full-portfolio static analysis campaign.
EU Cyber Resilience Act Article 14 applies from 11 September: a 24-hour early warning for actively exploited vulnerabilities in products with digital elements. The trigger owner is technical, not Legal-only.
Patch is not eviction on SonicWall SMA 1000, N-central, or self-hosted Artifactory. Rotate time-based one-time password seeds and API tokens.
Do not lead the board with “974 CVEs.” Lead with internet-facing exploited remote code execution, remote-monitoring blast radius, and the software supply-chain control plane.
The material problem this week is not Microsoft’s record CVE count. It is a short list of pre-authentication, internet-reachable, total-control paths — commerce platforms, remote monitoring and management consoles, artifact repositories, SAP kernels, and AI coding-tool supply chains — landing inside a 48-hour exploit window while EU product-security reporting starts on 11 September. Programs that treat 974 CVEs as one work queue will miss the items that change blast radius.
Executive Summary / Key Takeaways
Four CISA Known Exploited Vulnerabilities Catalog additions on 8 September set the operating queue. Adobe Commerce and Magento Open Source CVE-2026-75650 and N-able N-central CVE-2026-86218 are due 11 September for Federal Civilian Executive Branch agencies. Two exploited Windows local elevation-of-privilege zero-days — CVE-2026-81963 and CVE-2026-85880 — are due 22 September. CISA Binding Operational Directive 26-04, not CVSS alone, is the prioritization model.
Microsoft’s September release is a capacity event, not an exploit flood: about 974 CVEs, roughly 964 requiring customer action, two exploited SYSTEM elevation-of-privilege flaws, and a researcher-flagged cluster of about 20 unauthenticated remote code execution bugs. Independent Patch Tuesday analysis notes that the record count has not yet produced a matching spike in actively exploited Microsoft vulnerabilities. Treat volume as a queue-design failure mode.
Supply-chain and third-party dwell remain the compounding risk. Self-hosted JFrog Artifactory administrator-token forgery was exploited within days of disclosure. Trezor’s shipping-provider incident expanded to about 81,000 customers after records the vendor had attested as deleted were found intact. Thomson Reuters C-Track court records across 11 U.S. states, the U.S. Virgin Islands, and Ontario show months of vendor-side dwell.
AI is now both target and accelerator. Google Threat Intelligence Group warned on 8 September that AI coding tools are a primary adversary objective. CISA, NSA, and FBI accused six China-based AI firms of industrial-scale knowledge distillation against Claude, GPT, Gemini, and Grok. AI infrastructure — including LiteLLM, Starlette/FastAPI, and Artifactory — entered the Known Exploited Vulnerabilities Catalog at scale earlier in the month.
The regulatory clock is hard. EU Cyber Resilience Act Article 14 reporting — 24-hour early warning, 72-hour notification — applies from 11 September 2026 to manufacturers of products with digital elements placed on the EU market, including products already shipped. U.S. Cyber Incident Reporting for Critical Infrastructure Act finalization remains expected this month.
Next action is sequenced, not comprehensive. Internet-facing known-exploited and pre-authentication remote code execution first. Credential and token rotation after appliance or remote-monitoring exposure. Package Firewall on npm, PyPI, and Maven, plus Software Supply Chain Intelligence on the incoming package stream, before the next AI-agent install spike. A full-portfolio historical Static Analysis campaign is the wrong week-one move.
The Past Week in Review: Critical Developments
Period: 2–9 September 2026
Microsoft September Patch Tuesday — record volume, two exploited elevation-of-privilege flaws.
Microsoft published its largest single security release: about 974 CVEs, roughly 964 requiring customer action. About 104 to 119 were rated Critical. Product mix concentrated in Windows (about 723), Office, SQL Server, and developer tools. Year-to-date Microsoft CVE volume now exceeds 2,600.
Two flaws were exploited before the patch. CVE-2026-85880 is a heap-based buffer overflow in Windows Advanced Local Procedure Call (CVSS 7.8): local SYSTEM, AppContainer sandbox escape, no extra user interaction. CVE-2026-81963 is improper link resolution before file access (CWE-59) in the Windows Update Stack (CVSS 7.8): local SYSTEM via the mechanism used to install updates. Both are in the CISA Known Exploited Vulnerabilities Catalog with a federal due date of 22 September. They are post-foothold amplifiers, not remote initial access. They matter because ransomware and state actors already have phishing, infostealer, and appliance paths; SYSTEM on the Update Stack complicates eviction.
Independent researchers flagged about 20 unauthenticated, no-interaction remote code execution bugs as potentially wormable. Highest-signal items: CVE-2026-69730 in Windows DNS Server (CVSS 9.8, unauthenticated packet, characterized as a SigRed-class successor and likely to be exploited) and CVE-2026-69829 in Windows Shell (CVSS 9.8). These are not confirmed self-propagating worms. They are internet-facing service risks if DNS Server, Remote Desktop Protocol, or related roles are exposed.
Residual risk after patching: local elevation-of-privilege zero-days still require endpoint hygiene and privilege discipline. The Update Stack flaw warrants forensic review before declaring a host clean — the patch path is the abused component.
CISA Known Exploited Vulnerabilities Catalog, 8 September — four additions under Binding Operational Directive 26-04.
CISA added four exploited vulnerabilities and restated BOD 26-04 as the operating rule: asset exposure, Known Exploited Vulnerabilities Catalog status, exploit automation, and post-exploitation technical impact. The highest-risk tier is a three-day remediation window for Federal Civilian Executive Branch agencies, with an explicit expectation to check whether the asset was compromised before the patch.
CVE-2026-75650 in Adobe Commerce and Magento Open Source is improper neutralization of special elements used in a template engine (CWE-1336) leading to unauthenticated remote code execution (CVSS 10.0), exploited from 4 September, federal due date 11 September. CVE-2026-86218 in N-able N-central is static code injection leading to pre-authentication remote code execution (CVSS 9.8–10.0), hotfix 2026.3.1.14, federal due date 11 September. The two Windows elevation-of-privilege flaws above are due 22 September. Private-sector programs should adopt the same four-factor tree. CVSS-sorted queues will bury Commerce and N-central under hundreds of Important Windows flaws.
Adobe Commerce and Magento Open Source — StyleSmuggler, highest application-security item of the week.
CVE-2026-75650 is unauthenticated remote code execution in Adobe Commerce and Magento Open Source versions 2.4.4 through 2.4.9 and corresponding B2B lines. Researchers observed exploitation from 4 September — three days before Adobe’s emergency hotfix APSB26-146 on 7 September. Attackers used Magento style-property handling to inject code that executes via the Payment Transaction Failed Reminder path, then planted webshells and backdoors, including command-and-control disguised as Network Time Protocol traffic.
Adobe’s regularly scheduled September isolated patch, APSB26-138 on 8 September, does not include the StyleSmuggler hotfix. Both must be applied. Adobe instructs operators to rotate encryption keys, administrator passwords, GraphQL and OAuth tokens, payment-gateway credentials, database credentials, and SSH and API keys. Patching a store that was internet-reachable between 4 and 7 September without rotation is incomplete remediation. This is internet-facing, unauthenticated, total control of payment and customer data.
N-able N-central — remote monitoring and management as blast-radius multiplier.
CVE-2026-86218 is pre-authentication remote code execution. CISA listed it on 8 September with an 11 September federal deadline. N-able’s on-premises fix is 2026.3 Hotfix 4, build 2026.3.1.14. Hosted tenants were patched by the vendor; on-premises and managed-service estates are the residual. This is the fourth hotfix in roughly five weeks on the same product family. Incident responders reported investigation of a fully patched environment on 4 September; N-able has not confirmed production compromise in public statements reviewed for this briefing. Treat that disagreement as unresolved pending vendor and forensic closure, and hunt anyway. Reported scan source: 23.234.64.0/18. Adjacent authentication-bypass issues CVE-2026-86206 and CVE-2026-86207 remain in the same operational cluster.
Board implication: compromise of a remote monitoring and management platform is not one server. It is administrative reach into every managed endpoint.
SAP OVERPASS — CVSS 10.0, unexploited at publication, still material.
CVE-2026-44756, SAP Security Note 3747649, named OVERPASS by the researchers who reported it to SAP, is pre-authentication memory corruption in SAP Extended Passport processing inside shared kernel code, including kernel lines 7.22 through 9.20. Extended Passport data is parsed as the session opens — before user locks, roles, authorization objects, or logon policy. The flaw is reachable over HTTP and HTTPS, SAP GUI, and Remote Function Call. Researchers estimate more than 10,000 internet-facing SAP web interfaces; that figure is a scan estimate, not a victim count. No confirmed in-the-wild exploitation as of 8–9 September. A companion critical issue, CVE-2026-58240 (CVSS 9.8), affects the SAP NetWeaver Message Server.
Treat internet-reachable SAP as a pre-catalog emergency. Do not wait for a Known Exploited Vulnerabilities Catalog listing to isolate SAP Web Dispatcher or restrict Extended Passport-bearing protocols if the kernel patch cannot land this week.
Browser and edge — two Chrome zero-days in five days; appliance chains continue.
oogle Chrome 153 patched CVE-2026-87491, an exploited V8 out-of-bounds write — the seventh Chrome zero-day of 2026. Days earlier, CVE-2026-85046, a V8 type confusion, was also exploited. Microsoft Edge inherits Chromium fixes; confirm enterprise channel enforcement, not just the presence of chrome.exe.
Still in the week and month window, and still exploited or recently added to the Known Exploited Vulnerabilities Catalog: SonicWall SMA 1000 CVE-2026-83548 (pre-authentication server-side request forgery, CVSS 10.0) and CVE-2026-83549 (post-authentication OS command injection). Both were exploited as zero-days. A patch is not eviction if time-based one-time password seeds were stolen.
JFrog Artifactory CVE-2026-82329 (CVSS 9.8, CWE-287) allows forged administrator tokens on self-hosted instances under a default join-key condition. Researchers observed token minting within days of disclosure. Cloud tenants were vendor-patched. If a self-hosted instance was internet-reachable after disclosure, assume repository integrity is unverified until rebuild and attestation.
MikroTik RouterOS chaining — authentication bypass plus configuration overwrite — also featured this week, with large SSH-reachable populations reported by public scanners.
Third-party and identity.
Thomson Reuters C-Track was disclosed 2–3 September. Unauthorized activity was detected 30 June in a cloud environment; investigation found file access dating to March. Affected courts include 11 U.S. states, the U.S. Virgin Islands, and Ontario’s three court levels. Data classes include names and personal information; some courts flagged possible sealed or redacted records. No operational outage was reported. This is a four-month vendor dwell problem, not a missed application scan.
Trezor’s official updates through 4 September expanded a shipping-provider breach to roughly 81,000 customers after about 67,000 additional U.S. records from November 2019 to August 2021 — records the fulfillment partner had attested as deleted — appeared in the stolen set. Trezor states its own systems and devices were not compromised. Follow-on phishing calls and letters were reported by 8 September. Reporting ties the entry path to unauthenticated SQL injection in a Metabase instance, associated with CVE-2026-72898 (CVSS 10.0, already in the Known Exploited Vulnerabilities Catalog). The control failure is retention evidence, not a contract clause.
Other week signals, measured: Baylor Genetics disclosed 2.8 million affected after June access, including protected health information and some Social Security numbers. An education platform reported more than one million affected via a self-hosted Metabase pattern. A phishing-as-a-service operation tracked as BigBear 2.0 stole more than 5,000 Microsoft 365 credentials. A claimed theft of Florida driver records remains unverified pending agency confirmation. France announced a dedicated government cyber incident-response unit after a tax-authority attack. A £26 million UK privacy settlement against a consumer application is an enforcement-cost signal, not a breach write-up.
State-actor and AI-specific developments.
On 8 September, CISA, NSA, and FBI issued a joint advisory accusing DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI of industrial-scale knowledge distillation against U.S. frontier models — Claude, GPT, Gemini, and Grok variants — since at least late 2024, “likely with Chinese government awareness.” Pathways cited include native APIs, remote cloud providers, and third-party aggregators that obfuscate user metadata. This is API governance, terms-of-service enforcement, and model-output logging. It is not a Static Analysis finding.
Google Threat Intelligence Group, same week: AI-assisted coding tools and their dependency ecosystems — PyPI, npm, Docker Hub, Model Context Protocol servers — are now a primary target. A cluster tracked as UNC6780 harvests AI-tool credentials for resale into ransomware and extortion markets. Peer-reviewed research recirculated this week found that about 19.7 percent of packages recommended by code-generating models do not exist — the precondition for slopsquatting. A 7 September research paper found security defects in 16 percent of 3,171 public AI-agent setups, including unpinned Model Context Protocol servers and pre-approved shell grants. The UK National Cyber Security Centre separately warned on 7 September that unsanctioned shadow AI creates unmanaged data-exfiltration paths.
Public research also documented a Democratic People’s Republic of Korea-linked Linux toolkit compiled into HAProxy 2.8.12 — not an HAProxy CVE, a binary replacement after initial access — used for TLS-termination wiretaps against South Korean automotive and media victims, with nine to ten months of dwell. Disk-centric incident response and Software Composition Analysis of declared dependencies will miss a recompiled load-balancer binary.
Inference: attacker economics have moved upstream from application CVEs to the tools that write, build, route, and terminate application traffic.
The Past Month: Trends and Persistent Risks
Period: 10 August–9 September 2026
What accelerated.
Vulnerability production outran operations. The second quarter of 2026 posted 20,755 new National Vulnerability Database CVEs, up 36 percent quarter-on-quarter. Microsoft’s last three Patch Tuesdays — 622 in July, 421 in August, 974 in September — are the visible operational consequence of AI-assisted discovery. CISA Known Exploited Vulnerabilities Catalog additions stayed elevated. One mid-month batch put AI-stack components — LiteLLM CVE-2026-59822, Starlette/FastAPI CVE-2026-48710, Artifactory CVE-2026-82329, and Kestra CVE-2026-49869 — at nearly half the additions. That is a category shift: model gateways and artifact control planes are now known-exploited infrastructure.
Ransomware volume hit a 2026 high in August. Public leak-site trackers counted roughly 964 to 1,046 claimed victims, up 18 to 19 percent from July, across more than 80 groups. Qilin led; TheGentlemen held second; CL0P returned, with enterprise product-lifecycle software featured in reporting. Healthcare was the most-hit vertical in one major tracker cut. These are claimed leak-site counts, not independently confirmed breaches. Payment rates continue to fall even as large-enterprise payouts remain material. Backups alone are an incomplete control against double extortion.
Edge appliances industrialized into access-broker pipelines. SonicWall SMA 1000 zero-days fed ransomware affiliates. Earlier Fortinet credential-reuse campaigns left a reusable pool of virtual private network footholds. N-able’s multi-hotfix drumbeat is the remote-monitoring analogue. Patch application on an appliance that held time-based one-time password seeds or session material is not eviction.
The software supply chain stayed hot. Month-window incidents included a LiteLLM and scanner-toolchain maintainer-credential cascade involving malicious PyPI versions, with reporting citing more than 2,000 organizations exposed to stolen secrets; npm worm activity; compromised Rust crates attributed to North Korean operators; and source-control public-project rewrite risk. An earlier developer-toolchain compromise measured in hundreds of millions of downstream downloads remains the scale benchmark for hours of compromise and months of residue.
Identity remained the dominant ransomware initial-access path in monthly reporting, now paired with phishing-as-a-service industrialization and federation-broker incidents.
What stabilized.
Record Microsoft CVE volume has not yet produced a matching spike in exploited Microsoft zero-days. That observation is the one piece of good news in the patch-queue story — and it is conditional. Exchange CVE-2026-62911, an authentication bypass by capture-replay patched on 11 August that allows mailbox takeover, still showed about 21,899 internet-facing unpatched addresses on public scans as of 31 August–2 September, with the United States near 6,200 and Germany near 5,100. Germany’s national cyber authority put unpatched on-premises Exchange in-country near 85 percent. Extended Security Updates for Exchange Server 2016 and Exchange Server 2019 end in October 2026. That hangover is a persistent risk, not a new one.
Law-enforcement action against one prolific open-source malware cluster late in the month is a rare supply-chain enforcement signal. It is not a threat reduction.
What is compounding.
Disclosure-to-exploit compression continues. Month-period reporting still cites sub-48-hour weaponization for published proof-of-concept code. Artifactory and StyleSmuggler both moved from disclosure to exploitation inside that window.
AI-generated code volume is colliding with a flat security pass rate. Veracode’s 2026 GenAI Code Security Report found that the average security pass rate across more than 100 models remains 56 percent — essentially unchanged while AI-generated code volume has surged. Combined with slopsquatting and unpinned Model Context Protocol servers, this is a structural intake problem, not a tooling preference.
Vendor attestation is not a control. Written deletion confirmations failed in the shipping-provider case. C-Track’s dwell ran from March to June before detection. Boards should stop treating certification clauses and deletion letters as residual-risk reductions.
Memory-resident and binary-implant persistence is now a pattern. Follow-on webshells in previously exploited application-delivery controllers, and the compiled-in load-balancer implant described above, survive disk scanners and some upgrade images.
Regulatory stacking is live. The EU NIS2 Directive is in active national enforcement — the Netherlands entered force on 15 August with no transition period. Cyber Resilience Act Article 14 starts 11 September. FedRAMP is aligning vulnerability detection and response rules to Binding Operational Directive 26-04 by 7 December 2026. Cyber Incident Reporting for Critical Infrastructure Act finalization is expected this month per the federal Unified Agenda — expected, not published.
Strategic Foresight: Signals for the Next 30–90 Days
Confidence labeled. Sources are public and contemporaneous.
Binding Operational Directive 26-04 becomes the de facto private-sector patch language. High confidence.
Every new Known Exploited Vulnerabilities Catalog notice now cites exposure, catalog status, automatability, and technical impact. FedRAMP has pulled its vulnerability-detection mandate forward to 7 December. Boards that still receive “percent Critical CVSS closed” as the vulnerability KPI will be answering the wrong question by the fourth quarter. Primary references: CISA Binding Operational Directive 26-04, CISA 8 September catalog alert, FedRAMP public notice NTC-0014.
Artifact repositories and AI coding harnesses join virtual private networks and remote monitoring and management platforms as Tier-0. High confidence.
Artifactory token-forging, LiteLLM and Starlette catalog listings, Google’s reporting on AI-tool targeting, and the 16 percent defect rate in public agent setups are the same pattern: the build and agent-configuration plane is now an initial-access surface. Expect more catalog listings against Model Context Protocol servers, model gateways, and package-registry control planes through the fourth quarter. Primary references: CISA catalog additions of 2 and 8 September; Google Threat Intelligence Group, 8 September.
Cyber Resilience Act Article 14 will create a 24-hour reporting failure class. High confidence on the date; medium on enforcement shape.
From 11 September, manufacturers must file an early warning of actively exploited vulnerabilities and severe product-security incidents via the European Union Agency for Cybersecurity Single Reporting Platform. Commission guidance confirms the duty covers products already on the market and continues after support ends. Organizations that leave the trigger inside Legal will miss the technical 24-hour clock. Primary references: Regulation (EU) 2024/2847 Article 14; ENISA Single Reporting Platform factsheet.
Appliance implants will outlast the CVE that admitted them. Medium-high confidence.
SMA 1000, N-central, application-delivery webshells, and compiled-in load-balancer implants all illustrate the same residual: patch is not eviction. Incident-response playbooks should add identity reset, seed rotation, and binary-integrity checks as mandatory companions to known-exploited patching.
Exchange Server and other end-of-support collaboration stacks become structural zero-days. High confidence.
About 22,000 internet-facing Exchange servers remain unpatched for CVE-2026-62911. Extended Security Updates for 2016 and 2019 end in October 2026. Isolation or replacement, not another deferred change window, is the 90-day decision. Primary reference: public internet-wide scans published 1–2 September.
Distillation and API-abuse campaigns will pull security leaders into AI governance they do not own today. Medium confidence on tempo; high on the advisory itself.
The 8 September CISA, NSA, and FBI advisory is specific — named firms, named U.S. model families, named pathways. Enterprises exposing internal models or frontier-API keys through aggregators should assume they are in scope for the same techniques. This is key hygiene, output monitoring, and third-party aggregator review — not a new Static Analysis rule. Primary reference: CISA joint advisory, 8 September.
What is not a 30–90 day forecast: a self-propagating Windows worm from this Patch Tuesday. The potentially wormable cluster is real exposure on internet-facing Windows roles. It is not confirmed malware in the wild.
How Leading Programs Are Responding
Veracode Package Firewall — stop malicious packages at ingest.
This is the prevent control that matches Google’s warning. Point package managers and artifact repositories at Package Firewall instead of public registries. Enable policies for malware, typosquat, secrets in non-test files, and data-exfiltration techniques. Keep license rules in warn-only for two weeks so developers do not route around the control. JFrog Artifactory and Sonatype Nexus Repository are first-class repository targets — material given CVE-2026-82329.
Start here: Package Firewall · Manage firewall policies · Configure a package manager · Configure an artifact repository · Product overview
Expected outcome: malicious and typosquat versions never enter continuous integration. Track blocked-package count and the share of npm, PyPI, and Maven traffic passing through the firewall.
Veracode Software Supply Chain Intelligence — real-time package threat feed.
SSCI is the inform control. It is not Software Composition Analysis and it is not Package Firewall. Curated by the Veracode Threat Research team and delivered through a proprietary threat feed, SSCI gives Security Operations and AppSec real-time, high-fidelity intelligence on malicious open-source packages as they appear in public registries. Core covers malware detection. Pro adds reputation across five domains: vulnerabilities, license and compliance risk, engineering risk, author and contributor risk, and indicators of malicious behavior. Use it this week to watch npm, PyPI, Maven, and AI-stack packages — LiteLLM-class components, slopsquat names, and wormable registry activity — and to drive Package Firewall policy updates instead of waiting for a CVE.
Start here: Software Supply Chain Intelligence · SSCI datasheet · Secure the software supply chain
Expected outcome: mean time from malicious-package publication to blocked-in-pipeline; number of SSCI-sourced policy updates applied to Package Firewall in the next 10 business days.
Veracode Software Composition Analysis and software bills of materials — what is already in the tree.
Run SCA Agent-based Scan on every AI-assisted repository and on release trains. Generate CycloneDX 1.6 and SPDX 2.3 software bills of materials from the SCA agent and from Veracode Container Security. Use the Veracode Vulnerability Database, including Known Exploited Vulnerabilities Catalog matching, to prioritize reachable, exploited components over raw CVE counts. Pair SCA with Veracode Fix for SCA so upgrade merge requests replace tickets.
Start here: SCA Agent-based Scan · Software Composition Analysis · SCA quickstart · Choose SCA scan type · Generate an SBOM with the SCA agent · Veracode Vulnerability Database
Expected outcome: time-to-detect a newly listed exploited component in first-party repositories; software bill of materials coverage on customer-facing products before the 11 September reporting clock.
Veracode Dynamic Analysis and Veracode External Attack Surface Management — StyleSmuggler-class storefronts and forgotten APIs.
Run an External Attack Surface Management Deep Discovery scan against primary domains this week. Enroll discovered storefronts and APIs as Dynamic Analysis candidates. Do not wait for the application-inventory meeting.
Start here: Discover your attack surface · EASM quickstart · Scan web applications and APIs · Dynamic Analysis quickstart · API scanning
Expected outcome: internet-facing commerce and API inventory completeness within 48 hours; discovered high-trust web applications under continuous Dynamic Analysis.
Veracode Container Security, Infrastructure as Code, secrets, and the Veracode CLI — build images and leaked keys.
Gate image and directory scans in continuous integration with the Veracode CLI scan command. Generate image software bills of materials. Turn on secrets and Infrastructure as Code rules in Veracode Repository Scanning. Honest limit: Software Composition Analysis and Container Security will not detect a recompiled infrastructure binary that never entered the image registry as a declared package.
Start here: Container Security · Run Container Security scans · CLI scan · Install the Veracode CLI · CLI reference
Expected outcome: policy-fail rate on new images; secrets findings closed before merge; a software bill of materials artifact on every release image.
Veracode Risk Manager — turn 974 CVEs into a next-best-action queue.
Risk Manager is Veracode’s Application Security Posture Management capability. Connect existing scanners. Use Best Next Action and owner mapping so the board sees residual risk by asset criticality, not ticket volume. Defer low-exposure items the same way Binding Operational Directive 26-04 tells federal agencies to defer them.
Start here: Veracode Risk Manager · Get started with Risk Manager · Manage risk
Expected outcome: share of open findings that are internet-facing, exploited, and total-control; mean time from discovery to assigned owner.
Veracode Fix, Veracode Static Analysis, and Veracode Pipeline Scan — first-party injection classes and AI-generated code.
Run Pipeline Scan on every pull request for internet-facing applications. Enable Veracode Fix in the IDE and CLI so developers apply patches without leaving the branch. Use Veracode Fix for SCA to open upgrade merge requests rather than tickets. Full-portfolio historical Static Analysis is a 30-day program, not a Tuesday morning task.
Start here: About Veracode Fix · Fix for SAST · Fix for SCA · Fix quickstart · Scan source code · Pipeline Scan
Expected outcome: median hours from a critical finding to a merged fix on Tier-0 applications; policy-pass rate on release trains.
Policies, integrations, and analytics.
Encode Known Exploited Vulnerabilities Catalog-class and internet-facing rules in application security policy. Push findings into the existing ticketing system. Watch Package Firewall usage, Fix usage, and Software Supply Chain Intelligence-driven blocks so adoption is visible.
Start here: Application security policies · Integrations · CI/CD integrations · IDE integrations
Detect, prevent, inform — use the three supply-chain controls as a set. Software Composition Analysis detects what is already in the tree. Package Firewall prevents the next malicious version from entering the pipeline. Software Supply Chain Intelligence informs both, in real time. Do not collapse those three into one ticket labeled “SCA.”
What this platform does not do this week, state it: it does not patch Windows Advanced Local Procedure Call, Exchange Server, SonicWall SMA 1000, or N-able N-central. Those are infrastructure and vendor-hotfix actions. Claiming otherwise destroys program credibility.
What CISOs Should Do Now
Prioritized from the combined week and month picture. Capacity-safe. Ten business days, not a transformation program.
Next 72 hours. Four moves only.
Confirm every on-premises N-central console is on 2026.3.1.14. If the estate is managed-service, demand written patch attestation today. Hunt 23.234.64.0/18, unrecognized local administrator accounts, and new automation users. Rotate console credentials. Failure mode: treating “hosted is patched” as coverage of on-premises and downstream managed endpoints.
On Adobe Commerce and Magento Open Source, apply APSB26-146 and APSB26-138. Rotate encryption keys and every token listed in Adobe’s remediation note. Run External Attack Surface Management against known and adjacent storefront domains. Assume compromise if the instance was internet-reachable 4–7 September. Failure mode: applying only the monthly isolated patch.
On SAP OVERPASS, identify internet-reachable and Remote Function Call-exposed systems. Apply SAP Security Note 3747649. If a change freeze blocks the kernel, isolate SAP Web Dispatcher and restrict Extended Passport-bearing protocols. Failure mode: waiting for a catalog listing while more than 10,000 internet-facing SAP interfaces exist.
On Windows, Chrome, and leftover Exchange Server: patch the two exploited elevation-of-privilege flaws and the unauthenticated remote code execution cluster, with Windows DNS Server CVE-2026-69730 first on Tier-0. Enforce Chrome 153 or the equivalent Microsoft Edge channel. Isolate or patch Exchange CVE-2026-62911 if any instance is still internet-facing. Failure mode: opening a 974-row spreadsheet and calling that a plan.
This week.
For any SMA 1000, N-central, or self-hosted Artifactory instance that was reachable after disclosure, rotate time-based one-time password seeds, API tokens, repository credentials, and federated secrets. Patch is not remediation if session material survived.
Put Package Firewall on npm, PyPI, and Maven. Block malware and typosquat immediately; warn on license. Stand up Software Supply Chain Intelligence so Security Operations sees newly published malicious packages the same day the Veracode Threat Research team does, and push those signals into firewall policy.
Name the Cyber Resilience Act Article 14 technical trigger owner, the Single Reporting Platform submitter, and the 24-hour communications path before Friday. One exploited-vulnerability workflow shared by product security, incident response, and legal.
Next 10 business days.
Stand up Risk Manager, or an equivalent four-factor queue, so September’s CVE flood cannot flatten priority. Run Software Composition Analysis and Veracode Fix on AI-assisted repositories. Scan build images with Container Security. Put continuous Dynamic Analysis on every External Attack Surface Management-discovered customer-facing web application and API. Open a third-party file for court-system software-as-a-service, fulfillment processors, and internet-exposed business-intelligence tools. Require deletion evidence, not deletion clauses.
Do not do this week: a full-portfolio historical Static Analysis campaign, a ransomware tabletop that displaces the known-exploited cell, or a board slide that leads with “974 vulnerabilities.”
Record patch volume is a prioritization test. The programs that will look competent in 30 days are the ones that closed internet-facing exploited remote code execution, rotated identity after appliance exposure, put Package Firewall and Software Supply Chain Intelligence in front of the package managers their AI tools use, and built a 24-hour exploited-vulnerability reporting path before the Cyber Resilience Act clock started. Everything else is a backlog that can wait until the control plane is no longer on fire.
This report is provided for informational purposes only and is not intended as legal, technical, or professional advice. While we strive for accuracy, Veracode does not warrant the completeness or accuracy of the information. Recipients should not rely solely on this report and must conduct their own thorough investigation and verification. Please work with your internal teams and relevant stakeholders to properly assess, implement, and remediate any identified threats or vulnerabilities. The information has been compiled from multiple sources, and Veracode assumes no liability for any errors, omissions, or actions taken based on this content.