10 min read
Stay ahead of the game
Loading

click here to copy URL

Introduction

Knowing that a new critical vulnerability exists is one thing.

Knowing that it affects your environment, that attackers are actively exploiting it and that you need to act now is something very different.

That’s the gap Velma – Rootshell’s Vulnerability Enhanced Learning Machine AI – is designed to close.

Velma continuously analyzes vulnerability, exploit and threat intelligence to help Rootshell identify emerging threats that could be relevant to our clients. This gives our team the context to proactively alert clients, help prioritize remediation and continue monitoring the exposure as the threat develops.

And that proactive approach is something our clients notice.

“You guys are the only suppliers we’ve ever seen that not only personally reached out to tell us about a new CVE in our environment, but also follow up weeks later to confirm when you had seen it been fixed without us having to ask.”

– Imaginera

That feedback captures exactly what we’re trying to achieve.

Because vulnerability management shouldn’t end with adding another CVE to a dashboard.

If an emerging vulnerability creates a meaningful attack path into a client’s environment, we want them to know about it. If real-world exploitation begins, that context should influence its priority. And when the exposure has been addressed, we want to be able to validate that too.

September’s threat intelligence demonstrates exactly why this matters.

This month, Velma’s watchlist includes vulnerabilities associated with confirmed real-world exploitation, ransomware-linked operations and activity linked to sophisticated state-sponsored threat actors.

Among the intelligence we’re tracking is Sandworm-linked activity against Cisco security infrastructure, alongside intrusion activity displaying tactics consistent with Qilin ransomware affiliates.

In the latter case, the attack path progressed through reconnaissance, credential harvesting, tunneling and lateral-movement preparation toward ransomware deployment.

In other words, these aren’t simply theoretical vulnerabilities with high severity scores.

They’re potential entry points into the types of attack chains security leaders are actively trying to prevent.

That’s why Velma looks beyond CVSS.

By combining vulnerability intelligence with exploit availability, attacker activity, Internet exposure and business context, Velma helps Rootshell clients understand what requires attention now – and why.

Jump to:

Velma Threat Prioritization Matrix - September 26

Priority

Threat

CVE

Likelihood

Impact

Exploit Maturity

Velma Risk

1 – CRITICAL

N-able N-central unauthenticated RCE

CVE-2026-86218

Very High

Critical

Possible active exploitation / zero-day

10.0

2 – CRITICAL

Cisco Secure Email Gateway root RCE

CVE-2026-76461

Very High

Critical

Exploitable remotely

9.9

3 – CRITICAL

Cisco FMC authentication bypass to root

CVE-2026-20079

Very High

Critical

Active exploitation

9.9

4 – CRITICAL

SAP Extended Passport remote command execution

CVE-2026-44756

Very High

Critical

Remote / unauthenticated

9.9

5 – CRITICAL

Check Point Quantum Gateway RCE

CVE-2026-85102

Very High

Critical

Remote / unauthenticated

9.8

6 – CRITICAL

ConnectWise ScreenConnect privilege compromise

CVE-2026-84869

High

Critical

Elevated exploitation risk

9.7

7 – CRITICAL

Avada WordPress unauthenticated RCE

CVE-2026-18431

High

Critical

Low-complexity attack path

9.6

8 – CRITICAL

KindaRails2Shell secret disclosure → RCE

CVE-2026-66066

High

Critical

Remote / unauthenticated

9.5

9 – CRITICAL

Langflow arbitrary Python execution

CVE-2026-0768

High

Critical

Remote attack potential

9.5

10 – CRITICAL

Gitea repository-write RCE

CVE-2026-60004

High

Critical

Active exploitation reported

9.4

11 – HIGH

JFrog Artifactory chained admin takeover

CVE-2026-42018 / CVE-2026-42016

High

Critical

Active chained exploitation

9.4

12 – HIGH

WordPress Pods unauthenticated admin takeover

CVE-2026-19598

High

Critical

Remote / unauthenticated

9.3

 

Velma Risk represents analytical prioritization rather than simply the vendor CVSS score. It considers remote accessibility, authentication requirements, technical impact, exploitability, observed exploitation and potential business impact.

Executive Summary

September 2026 represents a CRITICAL threat period, with a significant concentration of vulnerabilities capable of enabling remote code execution, authentication bypass, privilege escalation and full administrative compromise.

But the most important story this month isn’t the number of critical CVEs.

It’s who is exploiting them – and what they’re targeting.

Threat intelligence around vulnerable Cisco security infrastructure includes activity associated with multiple intrusion clusters, including Sandworm-linked activity and Qilin-linked ransomware operations.

Other attacks remain unattributed, including exploitation affecting N-able N-central, JFrog Artifactory and Gitea.

The common thread is significant.

Attackers are increasingly targeting infrastructure that already occupies a position of trust: firewalls, security-management platforms, remote-management systems, software repositories and development infrastructure.

Compromising these systems can give an attacker considerably more than access to a single server.

It can provide a route into the wider organization.

Threat Actor Intelligence: Who Is Actually Exploiting These Vulnerabilities?

UAT-12197 – Targeting Cisco Security Infrastructure

Cisco Talos has identified activity associated with UAT-12197 targeting vulnerable Cisco Secure Firewall Management Center infrastructure.

Following exploitation, the actor deployed web-shell and command-execution capabilities before accessing internal FMC information, including authentication and credential-related data.

For security leaders, this is an important distinction.

This isn’t simply automated Internet scanning.

The vulnerable security infrastructure is being used as an initial foothold for deeper compromise.

Velma Assessment: CONFIRMED ACTIVE EXPLOITATION


UAT-11823 – Sandworm-Linked Activity

One of September’s most strategically significant developments involves intrusion activity tracked as UAT-11823.

Post-compromise tooling observed against Cisco security infrastructure has included reverse shells, proxy infrastructure, configuration harvesting and persistent command-and-control capabilities.

Most notably, the activity has involved Cyclops Blink malware.

Cyclops Blink has previously been associated with the Russian state-sponsored Sandworm threat group.

The tooling overlap is significant, although the available intelligence supports describing the campaign as Sandworm-linked activity rather than definitively attributing every intrusion to Sandworm.

For CISOs, the implication is clear: vulnerabilities affecting security appliances aren’t only attractive to opportunistic attackers. They can also become relevant to sophisticated state-sponsored operations.

Velma Assessment: HIGH-CONFIDENCE APT / STATE-SPONSORED-LINKED ACTIVITY


UAT-11988 – Qilin-Linked Ransomware Activity

September also provides another reminder of how quickly perimeter compromise can develop into a ransomware incident.

A Cisco intrusion cluster tracked as UAT-11988 has demonstrated activity consistent with Qilin ransomware affiliates.

Observed activity includes:

  • Active Directory reconnaissance
  • Credential harvesting
  • Network discovery
  • Proxy deployment
  • Reverse SSH tunneling
  • Lateral movement preparation
  • Endpoint targeting
  • Ransomware deployment

The initial access involved a related Cisco FMC vulnerability rather than CVE-2026-20079 alone, so this should be viewed as intelligence around the broader Cisco FMC attack surface, rather than direct attribution to one CVE.

What matters from a business-risk perspective is the attack path.

Perimeter compromise → credential access → lateral movement → ransomware.

Velma Assessment: HIGH-CONFIDENCE RANSOMWARE ACTIVITY


N-able N-central – Exploitation Without Attribution

CVE-2026-86218 is arguably the most urgent individual vulnerability on September’s watchlist.

The vulnerability carries a Velma Risk score of 10.0 and may allow an unauthenticated attacker to achieve remote code execution.

Possible exploitation as a zero-day has also been reported.

At present, reliable attribution to a recognized named threat group isn’t available.

But lack of attribution shouldn’t be mistaken for lack of risk.

N-central is a remote monitoring and management platform. Successful compromise could put an attacker in a highly privileged position from which downstream systems can potentially be targeted.

Velma Assessment: ACTIVE/POSSIBLE ZERO-DAY EXPLOITATION – ATTRIBUTION UNKNOWN


JFrog Artifactory – The Software Supply Chain

Attackers have also been observed chaining vulnerabilities affecting self-hosted JFrog Artifactory infrastructure.

The attack path can progress from unauthenticated access through privilege escalation to administrator-level control.

Post-compromise activity includes rogue administrator creation, long-lived access tokens, malicious plugins, arbitrary command execution, web-shell deployment, credential theft, SSH persistence and backdoor deployment.

There isn’t currently one established threat actor responsible for the overall activity.

The potential business impact, however, is significant.

Compromised repositories can contain source code, credentials, configuration information and software artifacts subsequently consumed by CI/CD environments.

Velma Assessment: CONFIRMED ACTIVE EXPLOITATION

Other Top Threats This Month

Cisco Secure Email Gateway – CVE-2026-76461

An unauthenticated remote attacker may be able to exploit vulnerable Cisco AsyncOS email parsing simply by sending a specially crafted email through an affected Secure Email Gateway.

Successful exploitation can result in arbitrary command execution with root privileges.

Because email gateways are intentionally exposed to untrusted Internet traffic, affected systems should be treated as a high-priority remediation target.

Velma Assessment: CRITICAL


SAP Extended Passport – CVE-2026-44756

This maximum-severity vulnerability is remotely exploitable without authentication and may allow arbitrary operating-system commands to execute with SAP administrative privileges.

Successful exploitation could compromise both the SAP host and the business processes and data it supports.

Velma Assessment: CRITICAL


Check Point Quantum Gateway – CVE-2026-85102

An unauthenticated remote attacker may be able to execute arbitrary code during VPN negotiation, potentially resulting in complete gateway compromise.

Again, the location of the vulnerability matters as much as its severity: attackers gaining control of security infrastructure can obtain an extremely valuable position inside the network.

Velma Assessment: CRITICAL


Development Infrastructure Under Pressure

September also contains significant vulnerabilities affecting Gitea, JFrog Artifactory, Rails and Langflow.

These environments can hold source code, cloud credentials, API keys, build artifacts and deployment access.

Of particular note is Langflow. CVE-2026-0768 may allow an attacker to execute arbitrary Python code in the context of the root user.

As AI development and orchestration platforms become more widely deployed, organizations should increasingly treat them as privileged enterprise infrastructure, rather than isolated development tools.

September Threat Themes

1. Security Infrastructure Is Becoming an Attack Surface

Cisco Secure Email Gateway, Cisco FMC and Check Point Quantum Gateway all feature prominently this month.

This is strategically important.

Firewalls, VPN gateways and security-management systems are designed to protect the organization. That also makes them extremely valuable targets.

Compromise can potentially place an attacker directly inside the infrastructure responsible for controlling or monitoring network access.

2. Remote Management Remains Highly Attractive

N-able N-central and ConnectWise ScreenConnect demonstrate continued attacker interest in remote-management infrastructure.

These platforms inherently possess powerful administrative capabilities, meaning an authentication bypass or RCE vulnerability can have consequences far beyond the initial server.

3. Ransomware Attack Paths Start Before the Ransomware

Qilin-linked activity demonstrates why vulnerability management and ransomware defense shouldn’t be treated as separate disciplines.

The ransomware payload is often the end of an attack chain.

The real attack may have begun much earlier through vulnerable perimeter infrastructure, followed by credential theft, reconnaissance and lateral movement.

4. State-Sponsored Actors Are Watching the Same Attack Surface

The Sandworm-linked activity is another reminder that exploitable security infrastructure is relevant to sophisticated state-sponsored operators as well as financially motivated cybercriminals.

5. Development Infrastructure Is High-Value Infrastructure

Gitea, JFrog Artifactory, Rails and Langflow reinforce the growing importance of protecting the software-development environment.

Compromise here can potentially extend into source code, credentials, cloud infrastructure and the software supply chain.


What Should Security Teams Do?

Organizations should prioritize vulnerabilities according to active exploitation, Internet exposure, authentication requirements and potential business impact rather than relying on CVSS alone.

Immediate investigation should focus particularly on Internet-facing instances of N-able N-central, Cisco Secure Firewall Management Center, Cisco Secure Email Gateway, affected SAP systems, Check Point Quantum Security Gateway, ConnectWise ScreenConnect, JFrog Artifactory, Gitea and Langflow.

But patching may not be enough.

If vulnerable infrastructure was externally accessible before remediation, organizations should consider whether compromise may already have occurred.

Threat hunting should look for unexpected administrative accounts, web shells, new authentication tokens, unusual outbound connections, reverse tunnels, credential access, configuration changes and unexpected processes.

September 2026 Risk Outlook

Overall Velma Threat Level: CRITICAL

September’s threat landscape brings together:

Active exploitation + ransomware activity + state-sponsored-linked activity + unauthenticated RCE + privileged infrastructure targeting.

The key takeaway for security leaders isn’t another list of CVE numbers.

It’s that vulnerabilities in highly trusted infrastructure are actively providing attackers with potential routes into enterprise environments.

And in several cases, we can see what happens next: web shells, credential theft, persistence, lateral movement and ultimately ransomware.

Security teams therefore need to move beyond asking:

“How severe is this vulnerability?”

And start asking:

“Is it exposed, is it exploitable, who is using it, and what could they reach next?”

That’s the context Velma is designed to provide.

Say hello to Velma

Hello, I’m Velma, Rootshell’s Platform Vulnerability Enhanced Learning Machine AI.

My purpose is to identify significant technical vulnerabilities and exploits that require immediate attention through patching or configuration changes.

Like a human security analyst, I continuously analyze vulnerability and threat intelligence to help security teams understand not only which vulnerabilities exist, but which ones attackers are actually using.

Because knowing a CVE exists is useful.

Knowing who’s exploiting it – and what they’re trying to achieve – is far more valuable.

Say hello to Velma!

Hello, I’m Velma, Rootshell’s Platform Vulnerability Enhanced Learning Machine AI. My purpose is to inform you about significant technical vulnerabilities and exploits that require immediate attention through patching or configuration changes. Similar to human security analysts, I tirelessly scour numerous forums, websites, and social media channels to provide what I deem as pertinent Threat Intelligence regarding known exploitable vulnerabilities.  

Whilst I don’t yet have the ability to track data breaches in the Rootshell platform watch this space I have some powerful useful supply chain monitoring capabilities on my roadmap.

Other posts you might like