If you just remember one thing from this briefing…
A maximum-severity firewall flaw is being exploited by a Russian state actor and a ransomware gang at the same time.
Cisco confirmed CVE-2026-20079, a CVSS 10 authentication bypass in Secure Firewall Management Center, is being
exploited by both a Sandworm-linked implant and Qilin ransomware affiliates. FMC controls firewalls across
multi-site estates. Ask this week: is ours internet-facing, patched, and would we notice unauthorised admin
access before an attacker did.
Priority9 Sep
Cisco firewall management plane exploited by state and ransomware actors
CISA added CVE-2026-20079 to its exploited catalogue on 9 September. A Sandworm-linked implant and,
separately, Qilin ransomware affiliates are both using it to gain root access to FMC, which manages
firewalls across distributed contractor estates.
So what: patch or isolate any internet-facing FMC today. The CVSS 10 score means root
compromise, and two distinct threat types are already exploiting it.
Priority1–9 Sep
Two more VPN gateways join the exploited-vulnerability catalogue
SonicWall's chained SMA1000 zero-days (CVE-2026-83548, -83549) give unauthenticated RCE, disclosed
1 September; Citrix's NetScaler bypass (CVE-2026-19490) has been mass-exploited since 3 September. Both are
remote-access gateways used for site and supplier connections.
So what: both sit at the network edge in front of remote access. Confirm patch status
today — treat any unpatched internet-facing instance as compromised.
Priority13 Sep
UK scaffolding contractor named on Qilin's leak site
Qilin listed Gilco Scaffolding, a UK contractor, on its leak site on 13 September, claiming disruption to
files and systems. Neither party has commented; the claim is unverified beyond the posting. Qilin is also
behind this fortnight's Cisco FMC ransomware intrusions.
So what: check the name against your scaffolding, temporary works and plant-hire
suppliers, and confirm Qilin has no foothold elsewhere in your chain.
Watch3 Sep
Site routers exposed as MikroTik exploit chain gives full control
A chain dubbed MikroTrick lets an unauthenticated attacker fully compromise internet-reachable MikroTik
RouterOS devices via SSH, combining CVE-2026-67277 with privilege escalation CVE-2026-86060. MikroTik
patched both on 3 September; over 122,000 devices remain exposed worldwide.
So what: site cabins and compounds often run consumer-grade routers with SSH left
open. Check yours are patched and not internet-reachable.