UK construction cyber briefing · Edition 04

Week commencing
14 September 2026

Coverage31 August – 13 September 2026
AudienceIT and security leadership · compliance and risk leads · programme directors
HandlingPublished by ClearPath Partnership
If you just remember one thing from this briefing…
A maximum-severity firewall flaw is being exploited by a Russian state actor and a ransomware gang at the same time.

Cisco confirmed CVE-2026-20079, a CVSS 10 authentication bypass in Secure Firewall Management Center, is being exploited by both a Sandworm-linked implant and Qilin ransomware affiliates. FMC controls firewalls across multi-site estates. Ask this week: is ours internet-facing, patched, and would we notice unauthorised admin access before an attacker did.

This fortnight

Incidents and sector activity

Priority9 Sep

Cisco firewall management plane exploited by state and ransomware actors

CISA added CVE-2026-20079 to its exploited catalogue on 9 September. A Sandworm-linked implant and, separately, Qilin ransomware affiliates are both using it to gain root access to FMC, which manages firewalls across distributed contractor estates.

So what: patch or isolate any internet-facing FMC today. The CVSS 10 score means root compromise, and two distinct threat types are already exploiting it.

Priority1–9 Sep

Two more VPN gateways join the exploited-vulnerability catalogue

SonicWall's chained SMA1000 zero-days (CVE-2026-83548, -83549) give unauthenticated RCE, disclosed 1 September; Citrix's NetScaler bypass (CVE-2026-19490) has been mass-exploited since 3 September. Both are remote-access gateways used for site and supplier connections.

So what: both sit at the network edge in front of remote access. Confirm patch status today — treat any unpatched internet-facing instance as compromised.

Priority13 Sep

UK scaffolding contractor named on Qilin's leak site

Qilin listed Gilco Scaffolding, a UK contractor, on its leak site on 13 September, claiming disruption to files and systems. Neither party has commented; the claim is unverified beyond the posting. Qilin is also behind this fortnight's Cisco FMC ransomware intrusions.

So what: check the name against your scaffolding, temporary works and plant-hire suppliers, and confirm Qilin has no foothold elsewhere in your chain.

Watch3 Sep

Site routers exposed as MikroTik exploit chain gives full control

A chain dubbed MikroTrick lets an unauthenticated attacker fully compromise internet-reachable MikroTik RouterOS devices via SSH, combining CVE-2026-67277 with privilege escalation CVE-2026-86060. MikroTik patched both on 3 September; over 122,000 devices remain exposed worldwide.

So what: site cabins and compounds often run consumer-grade routers with SSH left open. Check yours are patched and not internet-reachable.

ClearPath Partnership · UK construction cyber briefing · Edition 041 of 2
UK construction cyber briefing · Edition 04Actions, regulatory watch and outlook
Action queue

Changes and vulnerabilities to act on this fortnight

Change or vulnerabilityWhat it applies toWhy it matters on a projectAct by
CVE-2026-20079Cisco Secure FMCRoot-level compromise, exploited by state and ransomware actors alike.Overdue
CVE-2026-83548/9SonicWall SMA1000Chained flaws give unauthenticated RCE on VPN gateways.Immediate
CVE-2026-19490Citrix NetScaler ADC/GatewayMass-exploited auth bypass on SSL VPN and remote-access paths.Immediate
Cyber Security and Resilience BillCNI-adjacent and critical suppliersLords Committee Stage under way; widens NIS duties and powers.Monitor
Building Safety LevyNew-build schemes over 10 dwellingsNew payment condition before completion certificates issue.1 Oct 2026

Identifiers as published in the CISA KEV catalogue. Confirm applicability against your own asset inventory before acting.

Regulatory and sector watch

What changed, and what is coming

In force now

  • Gateway 2 requirements dispensed with from 1 September for fibre cabling and rooftop mast work; competence and golden thread duties still apply.
  • Cyber Security and Resilience Bill entered Lords Committee Stage 1 September, widening NIS duties to "critical suppliers" and data centres.
  • Procurement Act 2023 debarment list remains empty 19 months in.

Approaching

  • Second staircase mandate takes effect 30 September for new residential buildings over 18 metres.
  • Building Safety Levy takes effect 1 October for new-dwelling and student schemes over 10 units.
  • Pre-27 April 2026 Cyber Essentials accounts must move to v3.3 by around 26 October.

Standing watch — golden thread data custody. No BSR enforcement action yet turns on failing to hand over digital building information, but the duty is live for every occupied higher-risk building. Confirm who owns access to yours.

Recommended

Three things to do before the next edition

Outlook — next fortnight

We assess it is highly likely a further edge or VPN product joins the exploited-vulnerability catalogue before the next edition, and a realistic possibility another UK construction supplier is named on a leak site, given Qilin's pace against the sector.

Next edition

Monday 28 September 2026. Send additions, corrections or sector intelligence to your ClearPath engagement lead.

ClearPath Partnership
ClearPath Partnership · clearpathpartnership.com · Judgements are analytical assessments, not statements of fact.2 of 2
← All briefings Download PDF