Introduction
Knowing that a new critical vulnerability exists is one thing.
Knowing that it affects your environment, that attackers are actively exploiting it and that you need to act now is something very different.
That’s the gap Velma – Rootshell’s Vulnerability Enhanced Learning Machine AI – is designed to close.
Velma continuously analyzes vulnerability, exploit and threat intelligence to help Rootshell identify emerging threats that could be relevant to our clients. This gives our team the context to proactively alert clients, help prioritize remediation and continue monitoring the exposure as the threat develops.
And that proactive approach is something our clients notice.
“You guys are the only suppliers we’ve ever seen that not only personally reached out to tell us about a new CVE in our environment, but also follow up weeks later to confirm when you had seen it been fixed without us having to ask.”
– Imaginera
That feedback captures exactly what we’re trying to achieve.
Because vulnerability management shouldn’t end with adding another CVE to a dashboard.
If an emerging vulnerability creates a meaningful attack path into a client’s environment, we want them to know about it. If real-world exploitation begins, that context should influence its priority. And when the exposure has been addressed, we want to be able to validate that too.
September’s threat intelligence demonstrates exactly why this matters.
This month, Velma’s watchlist includes vulnerabilities associated with confirmed real-world exploitation, ransomware-linked operations and activity linked to sophisticated state-sponsored threat actors.
Among the intelligence we’re tracking is Sandworm-linked activity against Cisco security infrastructure, alongside intrusion activity displaying tactics consistent with Qilin ransomware affiliates.
In the latter case, the attack path progressed through reconnaissance, credential harvesting, tunneling and lateral-movement preparation toward ransomware deployment.
In other words, these aren’t simply theoretical vulnerabilities with high severity scores.
They’re potential entry points into the types of attack chains security leaders are actively trying to prevent.
That’s why Velma looks beyond CVSS.
By combining vulnerability intelligence with exploit availability, attacker activity, Internet exposure and business context, Velma helps Rootshell clients understand what requires attention now – and why.
Jump to:
Velma Threat Prioritization Matrix - September 26
Priority | Threat | CVE | Likelihood | Impact | Exploit Maturity | Velma Risk |
1 – CRITICAL | N-able N-central unauthenticated RCE | CVE-2026-86218 | Very High | Critical | Possible active exploitation / zero-day | 10.0 |
2 – CRITICAL | Cisco Secure Email Gateway root RCE | CVE-2026-76461 | Very High | Critical | Exploitable remotely | 9.9 |
3 – CRITICAL | Cisco FMC authentication bypass to root | CVE-2026-20079 | Very High | Critical | Active exploitation | 9.9 |
4 – CRITICAL | SAP Extended Passport remote command execution | CVE-2026-44756 | Very High | Critical | Remote / unauthenticated | 9.9 |
5 – CRITICAL | Check Point Quantum Gateway RCE | CVE-2026-85102 | Very High | Critical | Remote / unauthenticated | 9.8 |
6 – CRITICAL | ConnectWise ScreenConnect privilege compromise | CVE-2026-84869 | High | Critical | Elevated exploitation risk | 9.7 |
7 – CRITICAL | Avada WordPress unauthenticated RCE | CVE-2026-18431 | High | Critical | Low-complexity attack path | 9.6 |
8 – CRITICAL | KindaRails2Shell secret disclosure → RCE | CVE-2026-66066 | High | Critical | Remote / unauthenticated | 9.5 |
9 – CRITICAL | Langflow arbitrary Python execution | CVE-2026-0768 | High | Critical | Remote attack potential | 9.5 |
10 – CRITICAL | Gitea repository-write RCE | CVE-2026-60004 | High | Critical | Active exploitation reported | 9.4 |
11 – HIGH | JFrog Artifactory chained admin takeover | CVE-2026-42018 / CVE-2026-42016 | High | Critical | Active chained exploitation | 9.4 |
12 – HIGH | WordPress Pods unauthenticated admin takeover | CVE-2026-19598 | High | Critical | Remote / unauthenticated | 9.3 |
Velma Risk represents analytical prioritization rather than simply the vendor CVSS score. It considers remote accessibility, authentication requirements, technical impact, exploitability, observed exploitation and potential business impact.
Executive Summary
September 2026 represents a CRITICAL threat period, with a significant concentration of vulnerabilities capable of enabling remote code execution, authentication bypass, privilege escalation and full administrative compromise.
But the most important story this month isn’t the number of critical CVEs.
It’s who is exploiting them – and what they’re targeting.
Threat intelligence around vulnerable Cisco security infrastructure includes activity associated with multiple intrusion clusters, including Sandworm-linked activity and Qilin-linked ransomware operations.
Other attacks remain unattributed, including exploitation affecting N-able N-central, JFrog Artifactory and Gitea.
The common thread is significant.
Attackers are increasingly targeting infrastructure that already occupies a position of trust: firewalls, security-management platforms, remote-management systems, software repositories and development infrastructure.
Compromising these systems can give an attacker considerably more than access to a single server.
It can provide a route into the wider organization.
Threat Actor Intelligence: Who Is Actually Exploiting These Vulnerabilities?
UAT-12197 – Targeting Cisco Security Infrastructure
Cisco Talos has identified activity associated with UAT-12197 targeting vulnerable Cisco Secure Firewall Management Center infrastructure.
Following exploitation, the actor deployed web-shell and command-execution capabilities before accessing internal FMC information, including authentication and credential-related data.
For security leaders, this is an important distinction.
This isn’t simply automated Internet scanning.
The vulnerable security infrastructure is being used as an initial foothold for deeper compromise.
Velma Assessment: CONFIRMED ACTIVE EXPLOITATION
UAT-11823 – Sandworm-Linked Activity
One of September’s most strategically significant developments involves intrusion activity tracked as UAT-11823.
Post-compromise tooling observed against Cisco security infrastructure has included reverse shells, proxy infrastructure, configuration harvesting and persistent command-and-control capabilities.
Most notably, the activity has involved Cyclops Blink malware.
Cyclops Blink has previously been associated with the Russian state-sponsored Sandworm threat group.
The tooling overlap is significant, although the available intelligence supports describing the campaign as Sandworm-linked activity rather than definitively attributing every intrusion to Sandworm.
For CISOs, the implication is clear: vulnerabilities affecting security appliances aren’t only attractive to opportunistic attackers. They can also become relevant to sophisticated state-sponsored operations.
Velma Assessment: HIGH-CONFIDENCE APT / STATE-SPONSORED-LINKED ACTIVITY
UAT-11988 – Qilin-Linked Ransomware Activity
September also provides another reminder of how quickly perimeter compromise can develop into a ransomware incident.
A Cisco intrusion cluster tracked as UAT-11988 has demonstrated activity consistent with Qilin ransomware affiliates.
Observed activity includes:
- Active Directory reconnaissance
- Credential harvesting
- Network discovery
- Proxy deployment
- Reverse SSH tunneling
- Lateral movement preparation
- Endpoint targeting
- Ransomware deployment
The initial access involved a related Cisco FMC vulnerability rather than CVE-2026-20079 alone, so this should be viewed as intelligence around the broader Cisco FMC attack surface, rather than direct attribution to one CVE.
What matters from a business-risk perspective is the attack path.
Perimeter compromise → credential access → lateral movement → ransomware.
Velma Assessment: HIGH-CONFIDENCE RANSOMWARE ACTIVITY
N-able N-central – Exploitation Without Attribution
CVE-2026-86218 is arguably the most urgent individual vulnerability on September’s watchlist.
The vulnerability carries a Velma Risk score of 10.0 and may allow an unauthenticated attacker to achieve remote code execution.
Possible exploitation as a zero-day has also been reported.
At present, reliable attribution to a recognized named threat group isn’t available.
But lack of attribution shouldn’t be mistaken for lack of risk.
N-central is a remote monitoring and management platform. Successful compromise could put an attacker in a highly privileged position from which downstream systems can potentially be targeted.
Velma Assessment: ACTIVE/POSSIBLE ZERO-DAY EXPLOITATION – ATTRIBUTION UNKNOWN
JFrog Artifactory – The Software Supply Chain
Attackers have also been observed chaining vulnerabilities affecting self-hosted JFrog Artifactory infrastructure.
The attack path can progress from unauthenticated access through privilege escalation to administrator-level control.
Post-compromise activity includes rogue administrator creation, long-lived access tokens, malicious plugins, arbitrary command execution, web-shell deployment, credential theft, SSH persistence and backdoor deployment.
There isn’t currently one established threat actor responsible for the overall activity.
The potential business impact, however, is significant.
Compromised repositories can contain source code, credentials, configuration information and software artifacts subsequently consumed by CI/CD environments.
Velma Assessment: CONFIRMED ACTIVE EXPLOITATION
Other Top Threats This Month
Cisco Secure Email Gateway – CVE-2026-76461
An unauthenticated remote attacker may be able to exploit vulnerable Cisco AsyncOS email parsing simply by sending a specially crafted email through an affected Secure Email Gateway.
Successful exploitation can result in arbitrary command execution with root privileges.
Because email gateways are intentionally exposed to untrusted Internet traffic, affected systems should be treated as a high-priority remediation target.
Velma Assessment: CRITICAL
SAP Extended Passport – CVE-2026-44756
This maximum-severity vulnerability is remotely exploitable without authentication and may allow arbitrary operating-system commands to execute with SAP administrative privileges.
Successful exploitation could compromise both the SAP host and the business processes and data it supports.
Velma Assessment: CRITICAL
Check Point Quantum Gateway – CVE-2026-85102
An unauthenticated remote attacker may be able to execute arbitrary code during VPN negotiation, potentially resulting in complete gateway compromise.
Again, the location of the vulnerability matters as much as its severity: attackers gaining control of security infrastructure can obtain an extremely valuable position inside the network.
Velma Assessment: CRITICAL
Development Infrastructure Under Pressure
September also contains significant vulnerabilities affecting Gitea, JFrog Artifactory, Rails and Langflow.
These environments can hold source code, cloud credentials, API keys, build artifacts and deployment access.
Of particular note is Langflow. CVE-2026-0768 may allow an attacker to execute arbitrary Python code in the context of the root user.
As AI development and orchestration platforms become more widely deployed, organizations should increasingly treat them as privileged enterprise infrastructure, rather than isolated development tools.
September Threat Themes
1. Security Infrastructure Is Becoming an Attack Surface
Cisco Secure Email Gateway, Cisco FMC and Check Point Quantum Gateway all feature prominently this month.
This is strategically important.
Firewalls, VPN gateways and security-management systems are designed to protect the organization. That also makes them extremely valuable targets.
Compromise can potentially place an attacker directly inside the infrastructure responsible for controlling or monitoring network access.
2. Remote Management Remains Highly Attractive
N-able N-central and ConnectWise ScreenConnect demonstrate continued attacker interest in remote-management infrastructure.
These platforms inherently possess powerful administrative capabilities, meaning an authentication bypass or RCE vulnerability can have consequences far beyond the initial server.
3. Ransomware Attack Paths Start Before the Ransomware
Qilin-linked activity demonstrates why vulnerability management and ransomware defense shouldn’t be treated as separate disciplines.
The ransomware payload is often the end of an attack chain.
The real attack may have begun much earlier through vulnerable perimeter infrastructure, followed by credential theft, reconnaissance and lateral movement.
4. State-Sponsored Actors Are Watching the Same Attack Surface
The Sandworm-linked activity is another reminder that exploitable security infrastructure is relevant to sophisticated state-sponsored operators as well as financially motivated cybercriminals.
5. Development Infrastructure Is High-Value Infrastructure
Gitea, JFrog Artifactory, Rails and Langflow reinforce the growing importance of protecting the software-development environment.
Compromise here can potentially extend into source code, credentials, cloud infrastructure and the software supply chain.
What Should Security Teams Do?
Organizations should prioritize vulnerabilities according to active exploitation, Internet exposure, authentication requirements and potential business impact rather than relying on CVSS alone.
Immediate investigation should focus particularly on Internet-facing instances of N-able N-central, Cisco Secure Firewall Management Center, Cisco Secure Email Gateway, affected SAP systems, Check Point Quantum Security Gateway, ConnectWise ScreenConnect, JFrog Artifactory, Gitea and Langflow.
But patching may not be enough.
If vulnerable infrastructure was externally accessible before remediation, organizations should consider whether compromise may already have occurred.
Threat hunting should look for unexpected administrative accounts, web shells, new authentication tokens, unusual outbound connections, reverse tunnels, credential access, configuration changes and unexpected processes.
September 2026 Risk Outlook
Overall Velma Threat Level: CRITICAL
September’s threat landscape brings together:
Active exploitation + ransomware activity + state-sponsored-linked activity + unauthenticated RCE + privileged infrastructure targeting.
The key takeaway for security leaders isn’t another list of CVE numbers.
It’s that vulnerabilities in highly trusted infrastructure are actively providing attackers with potential routes into enterprise environments.
And in several cases, we can see what happens next: web shells, credential theft, persistence, lateral movement and ultimately ransomware.
Security teams therefore need to move beyond asking:
“How severe is this vulnerability?”
And start asking:
“Is it exposed, is it exploitable, who is using it, and what could they reach next?”
That’s the context Velma is designed to provide.
Say hello to Velma
Hello, I’m Velma, Rootshell’s Platform Vulnerability Enhanced Learning Machine AI.
My purpose is to identify significant technical vulnerabilities and exploits that require immediate attention through patching or configuration changes.
Like a human security analyst, I continuously analyze vulnerability and threat intelligence to help security teams understand not only which vulnerabilities exist, but which ones attackers are actually using.
Because knowing a CVE exists is useful.
Knowing who’s exploiting it – and what they’re trying to achieve – is far more valuable.
