CISO Risk Intel Brief: Edge Control Failure, Third-Party Access Abuse, and the Veracode Control Stack

Week of 30 September–7 October 2026, read against 7 September–7 October 2026. Prepared for the board risk committee, the CEO, and peer CISOs. Facts are from vendor advisories, CISA Known Exploited Vulnerabilities additions, and contemporaneous reporting. No finding below is inferred past those sources.

The decision this brief supports. Material residual risk this cycle sits in two places: unauthenticated control of internet-facing management planes, and legitimate third-party access abused at scale. The program response is not another scan. It is a sequenced control stack on the Veracode Application Risk Management platform: isolate and prove the edge, block packages before ingest, test the external surface that is actually reachable, scan containers and infrastructure before deploy, fix with reviewable patches, verify AI-assisted code for intent and logic, and rank what remains by business exposure.

Constraints. Patch windows on appliances are shorter than most change cycles. Third-party access abuse is not closed by code scanning. A full-portfolio rescan in the same week as an edge incident creates debt, not control. Success is time-to-isolate for KEV-listed edge devices, the share of package pulls mediated by Package Firewall, and the share of critical findings with a named owner and either a verified fix or an accepted residual.

Executive takeaways

The week confirmed the month. FortiMail CVE-2026-104286 (CVSS 9.8, CWE-22 and CWE-158) allows unauthenticated arbitrary file write and was exploited in the wild; CISA set a 4 October federal deadline. Cisco Catalyst SD-WAN Manager CVE-2026-76504 (CVSS 9.8, CWE-177) grants unauthenticated admin API access, was exploited in September, and has no workaround. Denmark’s Central Person Register lost names, addresses, and CPR numbers on about 8.8 million people through a private company’s lawful lookup rights, detected by an invoice, not by a security control. Atlassian CVE-2026-21589 (CVSS 9.3) gives unauthenticated file access across eight Data Center products; no in-the-wild use was confirmed at publication, which is not a reason to leave those instances on the internet. Arizona courts copied data on roughly 1.3 million people, including Social Security numbers and foster-care records, after a phishing click.

Across the month, Citrix NetScaler CVE-2026-88771 and CVE-2026-88772 were exploited before patch, entered the KEV catalog on 27 September, and were followed by further NetScaler issues into early October. The same window added F5 BIG-IP APM CVE-2026-94127, Check Point management-plane flaws, WSO2 JWT bypass CVE-2026-5430 at CVSS 10, and Adobe Commerce authorization issues. CISA recorded on the order of 41 KEV additions in September. TeamCity CVE-2026-63077, patched in July, is now ransomware feedstock. A single operator using AI agents skimmed more than 600,000 cards at a cost of tens of dollars per target. The backlog from a near-1,000-CVE Microsoft Patch Tuesday makes CVSS-only ranking indefensible.

The past week, in operating terms

Fortinet confirmed exploitation of CVE-2026-104286. An unauthenticated attacker can write arbitrary files to FortiMail through crafted HTTP or HTTPS requests. Fixed releases were not universally available at disclosure. The immediate control was the vendor workaround plus removal of the interface from the internet. An email gateway that accepts unauthenticated writes is not a control until forensic triage shows no implant.

Cisco disclosed CVE-2026-76504 on 30 September. Improper URI-encoding handling lets a remote attacker reach the API login handler as admin, regardless of configuration. PSIRT observed exploitation in September. Fixed trains exist. There is no workaround. Administrative control of SD-WAN Manager is control of the fabric.

Danish authorities stated that unauthorized persons used a private company’s authorized access to the Central Person Register for roughly ten days in September and extracted identity data on approximately 8.8 million registered persons. The register had no alarm on that lookup method. Discovery was an anomalous invoice. This is a governance failure on lasting third-party rights. No application scan would have caught it.

Atlassian patched CVE-2026-21589 across Jira, Confluence, Bitbucket, Bamboo, Crowd, Jira Service Management, Crucible, and Fisheye Data Center. Exploitation requires a known path and does not allow directory listing. Atlassian and WatchTowr reported no confirmed exploitation at publication. Bitbucket, Bamboo, and Crowd sit on source, build, and identity. Internet-reachable instances should be restricted until the fixed builds are applied.

The Arizona court copy, executed 24 September and detailed in early October, followed an employee phishing click and included long-retention case data and foster-care material on roughly 1.3 million people. Encryption at rest does not retire notification or identity-fraud exposure.

The month underneath the week

Perimeter appliances were the preferred initial-access class. Citrix confirmed pre-patch exploitation of NetScaler ADC and Gateway CVE-2026-88771 and CVE-2026-88772, unauthenticated remote code execution near CVSS 9.5. Both entered the KEV catalog on 27 September under a three-day federal clock. Follow-on NetScaler flaws continued into this week. F5 BIG-IP APM CVE-2026-94127, Check Point management servers, WSO2 CVE-2026-5430, and Adobe Commerce authorization bugs joined the exploited set. The cycle is now stable: targeted use, bulletin, KEV listing, mass scanning once a proof of concept lands. Implants on these appliances routinely survive the first patch. Isolation plus forensic triage is the control. Patch-and-close is not.

Supply chain remained a persistence path. TeamCity CVE-2026-63077, CVSS 9.8 and patched in July, is in ransomware use, with internet-exposed unpatched servers still in the low hundreds. Maintainer compromise and worm-style package campaigns continued to land malicious or vulnerable components in downstream builds. Detection after the lockfile is written does not restore pipeline integrity.

AI changed scale, not the control principle. Gambit documented open-source agent harnesses used for research, exploitation, and skimmer orchestration. More than 600,000 card records were taken from a subset of victims. Per-target cost was on the order of tens of dollars. The gap is coverage and speed on externally reachable commerce and APIs.

Thirty- to ninety-day signals

Confidence is high on continued KEV tempo against network and email appliances, and medium on the exact next CVE. Expect follow-on flaws in NetScaler, Fortinet mail and VPN planes, and SD-WAN managers. Prepare isolation runbooks, not only upgrade tickets. Package-ecosystem abuse will stay cheaper than custom malware; the control point is the artifact proxy. KEV deadlines and European product-security reporting already turn a missed edge patch into a governance event. After an identity-register incident, the board question will be third-party access review, not a scan score. AI-assisted exploit development compresses the window on both first-party code and open source. Logic flaws, broken authorization, and insecure direct object references in AI-assisted changes are poorly served by pattern matching alone.

The Veracode control stack, mapped to this exposure

The live platform is Risk Manager, Fix, Static Analysis, Software Composition Analysis, Dynamic Analysis, External Attack Surface Management, Package Firewall, Software Supply Chain Intelligence, Container Security and Infrastructure-as-Code scanning, the CLI, integrations, and policy. The Veracode Marketplace, launched 30 July 2026 with DryRun Security as inaugural partner, extends that platform with contextual analysis of code intent, behavior, and exploitability, anchored back to Veracode findings under one contract.

Use the tools in this order.

First, prove the edge you already know and find the edge you do not. External Attack Surface Management continuously discovers managed and unmanaged internet-facing assets, including shadow applications, open ports, outdated software, and exposed data, then ranks them by severity and business context. Dynamic Analysis tests the confirmed web applications and APIs for runtime flaws that source review cannot see. That pairing is the correct response to NetScaler-class gateways once they are patched, to Atlassian Data Center that must remain reachable, and to the commerce and API estates hit by agent-driven skimming. Discover at Discover your attack surface. Test at Scan web applications and APIs. Outcome: a quantified external exposure list, and runtime findings only on assets an attacker can reach.

Second, stop untrusted code at ingest. Package Firewall sits in front of artifact repositories and package managers and denies packages that fail policy before they enter the pipeline. It integrates with JFrog Artifactory, Sonatype Nexus, Azure Artifacts, developer endpoints, and direct registries for npm, PyPI, Cargo, and Maven. Default policy can be replaced with Open Policy Agent rules in Rego. Exceptions require an approver. Agent-based Software Composition Analysis covers repositories already in the estate. Software Supply Chain Intelligence supplies the researcher-curated feed so policy is not waiting on a public advisory. Overview: Block malicious packages. Setup: Set up Package Firewall. Validate: Create and test a firewall. Policy: Manage firewall policies. Integrate: Integrate Package Firewall. Composition analysis: Agent-based scans. Outcome: the board metric is the percentage of package pulls mediated by the firewall, and a measurable drop in malicious or out-of-policy components reaching builds. Package Firewall is a Commercial-region capability today.

Third, gate what you deploy. Container Security scans images, Infrastructure as Code, and embedded secrets and produces a software bill of materials before promotion. Run it from the CLI so the gate is automatic rather than requested. Scan containers, IaC, and secrets. Veracode CLI. Outcome: critical misconfiguration and secret exposure fail the pipeline, and an SBOM exists for customer and regulatory requests.

Fourth, keep deterministic static analysis on first-party code, in the IDE and in the pipeline, with policy that can break the build. Scan source code. Veracode Fix then generates reviewable patches for those static findings in the IDE and the CLI, and for dependency upgrades through the remote Fix-for-SCA agent, including breaking-change handling. About Veracode Fix. Outcome: shorter mean time to a reviewed fix, without asking every developer to hand-author the patch.

Fifth, where assistants write material code, add contextual verification. DryRun, through the Veracode Marketplace, analyzes intent, behavior, and exploitability—logic flaws, broken authentication, insecure direct object references—that pattern-based static analysis misses. Feedback lands in GitHub and GitLab pull requests and in repository-wide DeepScans. Native coverage includes Claude Code, Cursor, and Codex. Findings connect back to the Veracode platform for one audit trail. Marketplace: veracode.com/partners/marketplace. Joint control: Veracode and DryRun. Outcome: AI-era logic risk caught before merge, with repeatable evidence for audit, without a second program.

Sixth, aggregate and govern. Risk Manager correlates static, composition, dynamic, infrastructure, and connected-tool findings, assigns the owner, and ranks the next action by business exposure rather than raw CVSS. Integrations carry the same policy into the tools developers already use. Risk Manager: Veracode Risk Manager. Platform context: Manage risk. Integrations: Veracode Integrations. Outcome: a residual-risk statement the board can audit. Third-party access abuse of the Denmark type is outside this stack. It remains least privilege, time-bound credentials, and anomaly detection on volume.

Ordered actions

This week, inventory every internet-facing FortiMail, Cisco Catalyst SD-WAN Manager, Citrix NetScaler, and Atlassian Data Center instance. Isolate or patch within 72 hours. Require forensic review for webshells and unauthorized writes before the ticket closes. Do not run a full-portfolio rescan in that window.

In the same week, review every partner with bulk read rights to identity, employee, or customer data. Confirm least privilege, expiry, and volume anomaly detection.

Next business week, enforce Package Firewall on the registries that feed production, with agent-based composition analysis on the same paths. Report the share of pulls that traverse the control. Turn on Software Supply Chain Intelligence so the policy is fed by the research team, not only by public CVEs.

After the edge window, run External Attack Surface Management and targeted Dynamic Analysis on commerce, API, and collaboration applications that are intentionally reachable. Prioritize KEV-mapped issues.

Fail the pipeline on critical container and Infrastructure-as-Code misconfigurations and on embedded secrets. Retain the bill of materials. Where AI assistants generate material changes, enable the Marketplace DryRun integration so logic findings land in the same trail as static and composition results. Feed all of it into Risk Manager.

Report two numbers upward: time-to-isolate for KEV edge assets, and the percentage of package pulls mediated by Package Firewall. Do not report raw open-finding counts as control effectiveness.

Isolation of gateways can interrupt remote access and mail. Leaving an exploited management plane online is the larger outage. Sequence the work so recovery systems and the change freeze are not collapsed by parallel rescans.

The past week did not introduce a new attacker class. It confirmed that unauthenticated control of the edge, and lasting third-party read rights, still outrun most remediation programs. The defensible residual next quarter belongs to the program that isolates exploited management planes, blocks untrusted packages at ingest with Package Firewall, tests the real external surface with External Attack Surface Management and Dynamic Analysis, gates containers and infrastructure before deploy, fixes with Veracode Fix, verifies AI-assisted logic through the Marketplace, and ranks what remains in Risk Manager by business exposure. The next 30 to 90 days are more of this tempo, not a pause.


This report is provided for informational purposes only and is not intended as legal, technical, or professional advice. While we strive for accuracy, Veracode does not warrant the completeness or accuracy of the information. Recipients should not rely solely on this report and must conduct their own thorough investigation and verification. Please work with your internal teams and relevant stakeholders to properly assess, implement, and remediate any identified threats or vulnerabilities. The information has been compiled from multiple sources, and Veracode assumes no liability for any errors, omissions, or actions taken based on this content.