CISO Risk Intel Brief: Edge Identity Takeover, Mail-Path Root, and the 17 September Deadline

This briefing covers the past week (10 September–17 September 2026) and the past month (18 August–17 September 2026). It is written for a CISO to brief a CEO or risk committee and to drive a single change window… not a CVE inventory. The picture is unchanged in kind and worse in concentration. Attackers are taking internet-facing identity, mail, hypervisor, API, and artifact-control planes. Federal clocks on two of those planes land this week. Volume is a distraction; exposure is the work.

Key Takeaways

Today’s hard clock is Cisco Secure Email Gateway CVE-2026-76461. CISA set 17 September as the federal remediation date. There is no workaround. A crafted email yields root on the appliance. If the gateway is still unpatched this morning, that is the first call.

Overnight, Cisco Identity Services Engine became the next 3-day item. CVE-2026-76460 is a maximum-severity, unauthenticated API authentication bypass of the web management interface, confirmed exploited, added to CISA’s Known Exploited Vulnerabilities catalog on 16 September, federal due 19 September. ISE sits on Zero Trust policy. Compromise is identity-plane compromise.

DevOps and API control planes are now a standing KEV class. GitLab, JFrog Artifactory, WSO2 API Manager, and ScreenConnect were all confirmed exploited in this window. These are not “developer tools.” They hold tokens, artifacts, and session rights.

August ransomware claims set a 2026 high. Trackers put claimed volume near 964–997 incidents, concentrated in a handful of groups. Edge n-days continue to feed that pipeline after the vendor patch lands. Treat “patched” as “hunt, then accept residual risk.”

EU Cyber Resilience Act reporting started 11 September. Manufacturers of products with digital elements on the EU market now run a 24-hour early-warning and 72-hour full-notice clock for actively exploited product vulnerabilities. That is a legal operations problem, not a scanner problem.

Industry KEV hygiene is the board metric. Verizon’s 2026 DBIR put vulnerability exploitation first among initial-access vectors at 31 percent. Only 26 percent of organizational KEVs were fully remediated. Median time-to-remediate rose to 43 days. Beat those two numbers or explain them.

The Past Week: What Changed Residual Risk

Period: 10–17 September 2026

Identity and mail — act today

Cisco Secure Email Gateway CVE-2026-76461 is SQL injection in email parsing on AsyncOS. Unauthenticated. Root on the underlying OS. Affects physical, virtual, and cloud SEG. Cisco has no workaround and has already upgraded cloud instances to 16.5.0-780. On-prem first-fixed builds: 15.5.5-014, 16.0.4-302, or preferably 16.5.0-780. Hunt mail_logs for unexpected SQL before and after the upgrade. Federal due date is today.

Cisco ISE / ISE-PIC CVE-2026-76460 is an incorrect use of privileged APIs. An unauthenticated remote attacker can bypass the web management interface regardless of configuration. Cisco PSIRT confirmed active exploitation. There is no workaround. First-fixed releases: 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4. Hunt access.log on every node for suspicious usernames; Cisco’s guidance if compromise is suspected is re-image and restore from configuration backup. CISA due date is 19 September. ISE is the policy brain for network access. Treat every internet-reachable or partner-reachable ISE node as an emergency change, then assume session and policy integrity until proven otherwise.

Hypervisor and remote access — still open from last week

VMware vCenter CVE-2026-59310, a Syslog path-traversal unauthenticated RCE patched on 29 July, was flagged by CISA over the 12–15 September weekend as now used by ransomware groups. Shadowserver still sees hundreds of vCenter instances on the public internet. If vCenter is reachable from untrusted networks, isolate first, patch second, hunt reverse-SSH and new tasks third.

ConnectWise ScreenConnect CVE-2026-84869 allows file transfer and execution through an active remote session without host confirmation. CISA listed it as exploited. Upgrade past 26.6.5 and review live sessions.

Check Point Quantum VPN CVE-2026-85102 and CVE-2026-85103 remain imminent, not confirmed exploited. Both are unauthenticated RCE (certificate-trust validation and ASN.1 heap overflow). Dutch NCSC and CERT-EU told operators to apply LivePatch Take 24 immediately. Do not wait for a KEV listing to move a perimeter VPN.

Citrix NetScaler ADC/Gateway CVE-2026-19490 (AAA/Gateway authentication bypass) saw honeypot hits from 3 September and a CISA listing in this window. Confirm current recommended builds or take the Gateway off the internet.

Developer, API, and artifact planes

GitLab CE/EE CVE-2026-85706 is unauthenticated path traversal through the repository commits API (CVSS 10.0). Patched 10 September in 19.1.8 / 19.2.6 / 19.3.2. CISA listed it 11 September; federal due date was 14 September. Self-managed instances with a public project are the exposure. Secrets on disk are the blast radius. Confirm the patch landed and hunt commits-API access for file.path abuse.

JFrog Artifactory CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329 were chained between 15 August and 8 September into administrator takeover of self-hosted servers—new admin accounts, malicious Groovy plugins, backdoors. Rotate tokens. Hunt persistence. Treat the artifact store as a crown jewel, not a build convenience.

WSO2 API Manager and related gateway products, CVE-2026-5430, are under active exploitation as of 13 September. JWT authentication accepts tokens signed with unsupported algorithms. watchTowr honeypots logged forged admin JWTs. A successful token yields backend APIs, consumer keys, and secrets. The vendor patched in April. Exploitation arrived five months later. That delay is the lesson.

LiteLLM CVE-2026-59822 (MCP authentication bypass via an arbitrary Bearer token) had a federal due date of 16 September. If an AI gateway is still below 1.84.0, it is late. Rotate every model-provider key that proxy has touched.

Patch catalogs — absorb by exposure, not by count

Microsoft’s 8 September release is the largest September drop in recent memory: 964 to 974 CVEs, depending on whether cloud-only items Microsoft patches itself are counted. Two exploited local elevation-of-privilege zero-days—CVE-2026-81963 (Windows Update Stack) and CVE-2026-85880 (ALPC)—are on KEV. Federal due date is 22 September. They matter after foothold. They do not outrank unauthenticated remote control of mail, identity, or hypervisor planes. CVE-2026-69525 (unauthenticated RDS use-after-free, CVSS 9.8) should be treated as KEV-class anywhere Remote Desktop Services is reachable. Microsoft shipped out-of-band RDS stability fixes on 14 September after the security updates broke connections. Patch, then confirm RDP still works.

Oracle’s 15 September Critical Security Patch Update delivered 673 patches across 17 product families, 104 of them critical, more than 240 remotely exploitable without authentication. E-Business Suite took 159 patches; Fusion Middleware 153, including 78 unauthenticated remote flaws and five CVSS 10.0 issues in Access Manager, Forms, Internet Directory, Platform Security for Java, and WebLogic. Prioritize internet-facing middleware. Oracle has said it continues to see successful attacks where available fixes were not applied.

SAP’s 8 September patch day included maximum-severity unauthenticated issues. No confirmed in-the-wild exploitation at disclosure. If ICM or Web Dispatcher is public, it is an emergency change. If it is not, schedule it. Do not let it displace ISE or SEG.

Acronis Backup plugin CVE-2026-87886 moved from “limited targeted exploitation” to CISA KEV on 16 September, due 19 September. It is local privilege escalation on cPanel/WHM. Secondary to identity and mail, mandatory if the plugin is in production.

Japan’s Digital Agency disclosed on 11 September that a known, medium-severity VPN flaw produced possible exposure of about 246,000 official and contractor records. Detected in June, contained in July, disclosed in September. Medium plus internet-facing plus delay equals a material incident. That is the control-effectiveness case for the board, not a new technique.

UNC3569, a China-linked cluster, used CVE-2026-51990 in Tencent’s Sogou Input Method for one-click code execution and GrayRabbit deployment. Patched in April. Relevant only where that IME is present on enterprise Windows. Do not let a client-side espionage item steal tonight’s change window.

Governance this week

CISA Binding Operational Directive 26-04 is now the language on every new KEV: public exposure, known exploitation, automatable exploit, and total post-exploitation control. The 3-day tier is small by design. SEG’s 17 September date and ISE’s 19 September date are the live examples. Forensic triage is required when the asset was publicly exposed—patching without looking is incomplete.

EU CRA Article 14 reporting has been live since 11 September for manufacturers. Early warning in 24 hours, fuller notice in 72 hours, final report within 14 days of a corrective measure for exploited product vulnerabilities. Products already on the EU market are in scope for reporting. Full product obligations remain December 2027. Name a duty officer this week if you ship digital products into the Union.

The Past Month: Velocity, Not Noise

Period: 18 August–17 September 2026

Ransomware claims accelerated in August. Comparitech logged 997 claimed attacks, 32 per day, up 23 percent from July. Other trackers landed near 964 claimed victims and 83 active groups, up from 66. Qilin led. The Gentlemen followed. Methodologies differ; say “claimed,” not “confirmed.” Healthcare remained a preferred target. New brands reached meaningful volume in weeks.

The exploit window on edge devices compressed to days. SonicWall SMA 1000 flaws were exploited from 22 June—three weeks before disclosure—and continued to feed access brokers and extortion through August. Fortinet credential-exposure residue remains reusable. vCenter moved from July patch to August KEV to September ransomware flag. That conveyor is now the default, not the exception.

Software ingest trust failed in public. In early August a self-replicating npm worm moved through hundreds of packages in under four hours. Root packages sat in a large share of cloud environments. Stolen maintainer tokens plus legitimate CI produced valid build attestations on malicious content. On 31 August a trusted Terraform module registry path was altered for roughly fourteen hours and served credential-stealing modules—valid TLS, trusted hostname. Detection after download is the failed control. Prevention at ingest is the control that changes residual risk.

Time-to-exploit collapsed. China-nexus clusters have been observed weaponizing critical flaws within 24 hours of public proof-of-concept. GitLab’s maximum-severity issue was KEV-listed the day after the patch. Artifactory’s authentication bypass was exploited within days of disclosure. Defender process time is no longer the constraint. Minutes of exposure are.

Identity federation did not reset. A Dropbox disclosure covering 4–21 August access via a partner single sign-on path was an identity-binding failure, not a novel malware family. JWT and SSO defects in WSO2 and ISE this week are the same class at higher privilege.

AI gateways and Model Context Protocol servers are now a recurring KEV class. They concentrate provider keys and tool permissions. Inventory them as production applications. Do not make them the lead story. Do not leave them off the asset list.

What stabilized is elevated, not calm. Vulnerability exploitation is the leading initial-access vector in the current Verizon DBIR. Third-party involvement remains near half of breaches in 2026 industry compilations. Mean time to identify and contain lengthened. Those are directional board figures, not this organization’s numbers.

Signals for the Next 30–90 Days

Expect another identity or mail appliance zero-day to land on KEV with a 3-day clock. ISE this week followed SEG by two days. The pattern is the forecast.

Expect the next supply-chain event to look compliant. Build attestations authenticate the pipeline, not the maintainer after token theft. Ingest-time policy—malware, typosquat, secrets, new-package age—is what reduces residual risk. Pair that block with a live threat feed, not a static allow-list.

Expect MCP and AI-gateway KEVs to continue. One proxy holds every upstream key. Treat that host as an identity boundary.

Expect the first awkward CRA filings this quarter. Organizations that brand software or connected products for the EU need a decision tree that distinguishes “exploited in our product” from “CVE exists in a dependency.” US incident-reporting regimes remain organizational. Dual playbooks.

Expect vulnerability volume to stay high. Microsoft and Oracle are on monthly cadences that no longer fit a quarterly change culture. A single ranked queue is the only way KEV time-to-remediate beats the 43-day industry median.

Watch items, not predictions: public exploit code for the Check Point VPN pair; named victim disclosures on WSO2; any federal note on a missed 17 September SEG item; first CRA filings that surface through CSIRT channels.

How Leading AppSec Programs are Responding

Application risk programs that are keeping pace are not “scanning more.” They are ranking exposure the way BOD 26-04 ranks it, blocking bad packages before the pipeline, informing SOC and AppSec from a live supply-chain threat feed, and putting a single remediation queue over every finding source.

The current Veracode Application Risk Management platform, retrieved 17 September 2026 from official documentation and the platform page, includes Risk Manager, Fix, Static Analysis, Pipeline Scan, SCA, DAST, EASM, Package Firewall, Container Security / IaC / secrets, CLI, Integrations, Policies, SBOM / supply-chain management, and Software Supply Chain Intelligence (SSCI) with the Veracode Threat Research feed.

Honest limit: an application platform does not patch Cisco ISE, SEG, Check Point, or vCenter. Those are vendor and change-control problems. The platform reduces the software, package, API, and infrastructure residue behind those appliances—and stops the next worm at ingest.

Detect, prevent, and inform the supply chain

August’s npm worm, the 31 August trusted-registry module incident, Artifactory admin takeover, and LiteLLM-class PyPI dependencies are one problem with three controls.

Detect with SCA. Inventory what already landed. Map direct and transitive dependencies. Generate SBOMs as evidence. Use Fix for SCA to produce a safe upgrade path instead of ticket churn.
SCA agent-based scans · Fix for SCA · SBOMs

Prevent with Package Firewall. Put the firewall in front of npm, PyPI, Maven, NuGet, Go, Cargo, and RubyGems. Enable malware, typosquat, and secrets policies. Warn, then block, young packages. Mean time to block falls from the incident write-up to the install.
Package Firewall · firewall policies · artifact repositories · package managers

Inform with Software Supply Chain Intelligence and the Threat Research feed. SSCI is the intelligence layer—not the scanner and not the block. The Veracode Threat Research team curates a proprietary feed of malicious and suspicious open-source packages, with continuous registry monitoring and real-time alerts. Core covers malware detection. Pro adds reputation across vulnerabilities, license and compliance, engineering risk, author and contributor risk, and indicators of malicious behavior. Delivery is API-first (DirectFlow for the enterprise; PartnerPulse for marketplace partners) so the feed lands in SIEM, SOC workflows, and Package Firewall policy—not in another unread dashboard. Use it this week to subscribe hunt and AppSec to worm and registry-hijack indicators, to flag author-risk on packages that ship a burst of versions in minutes, and to give Firewall current block rules instead of a static allow-list. It is also the evidence trail for DORA, GDPR, and CRA conversations that will ask what you knew and when.
Secure the software supply chain — Detect / Prevent / Inform · Platform overview · SSCI datasheet · Spring 2026 Threat Research

Expected outcome: malicious packages never reach the pipeline; SOC sees the campaign hours earlier; Legal has a dated feed record when a regulator asks. Measurable: percent of install attempts blocked, time from SSCI alert to Firewall policy update, percent of production repos with a current SBOM.

Find the forgotten internet app, then test it

Maps to WSO2, GitLab, WordPress plugin RCEs, SAP web interfaces, exposed MCP and AI gateways.

Run EASM Deep Discovery against the corporate domain set. Enroll every new admin path, API gateway, and login host into DAST within 72 hours. Authenticated API scans for JWT and authorization defects.
EASM · EASM quickstart · DAST for web and APIs

Expected outcome: unknown external apps stop being discovered by attackers first. Measurable: percent of internet-facing apps with a current DAST; time from EASM discovery to first DAST.

Gate images, Terraform, and secrets before deploy

Maps to malicious modules on trusted registry paths, containerized AI gateways, secrets in CI tokens.

Add container and infrastructure-as-code scanning in CI with secret rules. Fail the pipeline on critical misconfiguration, embedded secrets, and known-exploited image CVEs.
Container Security · run scans · CLI scan · CLI install

Expected outcome: secret-bearing or hostile modules never reach the state store. Measurable: pipeline-fail rate on IaC and container policy; secrets detected pre-merge.

Absorb catalog volume without losing the 3-day items

Maps to Microsoft’s September drop, Oracle’s 673 patches, and a week of new KEVs.

Use Risk Manager as the single next-action queue. Weight internet-facing plus KEV plus automatable plus total control above raw CVSS. Grace periods for the rest.
Risk Manager · VRM getting started · policies

Expected outcome: KEV-class application findings move inside an internal SLO that beats the 43-day industry median. Measurable: KEV time-to-remediate; percent of KEVs fully closed.

Compress first-party fix time

Maps to custom JWT and auth code, and to injection and path-traversal classes that became this week’s KEVs in other people’s products.

Keep Pipeline Scan in the pull request. Invoke Fix in the IDE or CLI. Policy-fail path traversal, injection, and authentication-bypass on business-critical applications.
Static Analysis · Fix · Pipeline Scan · integrations

Expected outcome: auth-bypass and injection defects stop shipping. Measurable: median hours from SAST finding to merged fix on policy-fail items.

Treat AI toolchains as production apps

Discover exposed MCP and gateway hosts with EASM. DAST the authenticated surface. SCA plus Package Firewall the dependencies. Container-scan the runtime. Subscribe SSCI to the ecosystems those agents pull from. Same policy as a customer-facing API.

What to Do Now

One queue. One owner per item. One change window for internet-facing KEVs. Everything else is backlog with an SLA.

Next 24 hours. Confirm patch and forensic triage on Cisco Secure Email Gateway CVE-2026-76461. Confirm presence and start the ISE CVE-2026-76460 change for 19 September. Isolate any internet-facing vCenter that is not on a fixed build. Apply Check Point LivePatch Take 24. Confirm GitLab, Artifactory, WSO2, ScreenConnect, FMC, and NetScaler exposure. Hunt before you declare clean.

This week. Microsoft’s two exploited elevation flaws fleet-wide (federal due 22 September); RDS CVE-2026-69525 anywhere the service is reachable; Oracle internet-facing Fusion Middleware and E-Business Suite. Turn on Package Firewall for npm, PyPI, and Maven. Subscribe SSCI / Threat Research feed into SOC and Firewall policy. SCA and SBOM refresh on production repositories. Rotate CI, cloud, and model-provider tokens for any pipeline that pulled public packages during the early-August worm window or the 31 August registry window. Inventory federated identity providers and require phishing-resistant MFA plus a binding step-up on new SSO links.

This month. A single ranked remediation queue aligned to exposure, KEV status, automation, and total control. Container and IaC gates in CI with no exception for “platform” repositories. If you manufacture or brand products with digital elements for the EU market, stand up the CRA 24/72/14 playbook with Legal and Product Security. Publish two numbers to the risk committee: percent of KEVs fully remediated, and median KEV time-to-remediate against the 43-day industry baseline.

Failure mode to refuse. Treating ~970 Microsoft CVEs as equal to an unpatched mail gateway or identity engine. That is how the 3-day items slip. Second failure mode: composition analysis after the fact with no Firewall and no threat feed. That is how the next worm arrives with a green attestation.


The residual risk after this week’s patches is structural. Edge and identity appliances are being converted into access inventory faster than change windows clear them. Developer ecosystems will keep delivering malware with valid provenance. Regulatory clocks now run in hours for product vendors. Scanning faster does not close those gaps. Ranked exposure, ingest-time prevention, a live supply-chain threat feed, and one remediation queue do.

Update the P0 list against CISA KEV and vendor advisories before close of business 17 September, then again before the ISE deadline on 19 September.


This report is provided for informational purposes only and is not intended as legal, technical, or professional advice. While we strive for accuracy, Veracode does not warrant the completeness or accuracy of the information. Recipients should not rely solely on this report and must conduct their own thorough investigation and verification. Please work with your internal teams and relevant stakeholders to properly assess, implement, and remediate any identified threats or vulnerabilities. The information has been compiled from multiple sources, and Veracode assumes no liability for any errors, omissions, or actions taken based on this content.