If you just remember one thing from this briefing…
The fortnight's biggest UK aviation disruption was a one-millisecond software bug, not an attacker.
A NATS flight-data processing fault on 8 September cancelled over 2,000 flights and stranded roughly
330,000 passengers, worst at Heathrow, Gatwick, Manchester and Birmingham. NATS and the UK's air traffic
chief ruled out hostile interference; that took hours to say with confidence. Ask your team: could we tell
an accident from an attack that fast, and who is authorised to say so in public.
Priority9–16 Sep
Two maximum-severity Cisco zero-days reach the KEV catalogue within a week
CISA added Cisco Secure Firewall Management Center authentication-bypass flaw CVE-2026-20079 on 9
September — already exploited by nation-state and ransomware actors since August — then Identity
Services Engine flaw CVE-2026-76460 on 16 September. Both are CVSS 10.0 and give unauthenticated root
access.
So what: FMC sets firewall policy; ISE sets network admission. Confirm both are
patched or isolated before anything else this week.
Priority9 Sep
Citrix NetScaler authentication bypass under active exploitation
Citrix's critical NetScaler ADC/Gateway flaw CVE-2026-19490 (CVSS 9.3) moved from patched to
in-the-wild exploitation within days; CISA catalogued it on 9 September, covering AAA and Gateway
virtual servers used for SSL VPN, ICA Proxy and RDP Proxy.
So what: NetScaler commonly carries supplier and remote-engineer access. Treat
any unpatched internet-facing unit as already compromised.
Priority9 Sep
Fortinet FortiOS heap overflow added with a forensic-triage requirement
CISA catalogued CVE-2025-25249, a heap-based buffer overflow in FortiOS and FortiSwitchManager (CVSS
9.8), on 9 September, with a 12 September remediation deadline and an unusual instruction: check for
prior compromise, not just patch.
So what: if this sits at your network boundary, patch and investigate for
existing compromise, not one or the other.
Watch7 Sep
Metaencryptor lists aerospace supplier SIFCO Industries
Metaencryptor, previously focused on healthcare, listed Ohio aerospace, energy and defence supplier
SIFCO Industries on its leak site on 7 September alongside two other new victims. The claim is
unverified beyond the listing; no data sample has been confirmed.
So what: a healthcare-focused group diversifying into aerospace suppliers is an
unknown quantity. Check tier-2/3 supplier notification clauses.