Weekly review

ThreatNoir Afternoon Brief — September 10

2026-09-10Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — September 10, 2026

The cybersecurity landscape faces mounting pressure as federal agencies confront multiple critical vulnerabilities demanding immediate remediation. Today's threat landscape reveals a coordinated pattern of exploitation across enterprise infrastructure, with government authorities issuing urgent patch deadlines and security researchers uncovering new zero-day threats targeting core Windows security mechanisms.

CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline

The U.S. Cybersecurity and Infrastructure Security Agency added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog, each impacting Cisco, Citrix, and Fortinet products. Federal Civilian Executive Branch agencies face a mandatory patch deadline of September 12, 2026, to remediate these critical flaws. The vulnerabilities tracked include CVE-2026-20079 with a CVSS score of 10.0, along with CVE-2025-25249 and CVE-2026-19490. The threat actor PivotC2 has been observed leveraging these vulnerabilities in active campaigns. Source: CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline

CISA: WatchGuard RCE Flaw Now Exploited in Ransomware Attacks

The Cybersecurity and Infrastructure Security Agency confirmed that ransomware gangs are actively exploiting a critical remote code execution vulnerability in WatchGuard Firebox firewalls. The vulnerability, initially flagged as actively exploited in December, continues to pose significant risk to organizations operating unpatched firewall infrastructure. Multiple CVEs associated with WatchGuard products have been identified in ransomware campaigns, including CVE-2022-23176, CVE-2025-14733, and CVE-2025-9242. Source: CISA: WatchGuard RCE flaw now exploited in ransomware attacks

New 'ShieldCrash' Zero-Day Exploit Targets Microsoft Defender

Security researchers have disclosed a new zero-day vulnerability affecting Microsoft Defender that grants attackers full system privileges on Windows machines running the September 2026 patches. The exploit, designated ShieldCrash, represents a significant gap in endpoint protection mechanisms and poses an elevated risk to organizations relying on Microsoft's native security solutions. The vulnerability is tracked under CVE-2026-50656 and CVE-2026-69414. Source: New 'ShieldCrash' Zero-Day Exploit Targets Microsoft Defender

Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks

A high-severity unauthenticated code execution vulnerability in Fortinet products, tracked as CVE-2025-25249, continues to be exploited in the wild despite being patched in January 2026. Threat actors are leveraging this flaw to deploy the PivotC2 remote access trojan, establishing persistent backdoor access to compromised infrastructure. Organizations that have not applied the January 2026 patches remain at immediate risk of compromise. Source: Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks

Today's threat intelligence underscores the critical importance of rapid patch deployment and continuous vulnerability monitoring. Organizations must prioritize remediation of the CISA-mandated vulnerabilities before the September 12 deadline while simultaneously addressing the emerging ShieldCrash zero-day and ongoing WatchGuard exploitation campaigns affecting their security posture.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).