Skip to content
Auto-CTI

Weekly dossier · 2026-W37

Joel Traber AG

07.09.2026 – 13.09.2026

Strategic overview

CRITICAL

Elevated threat activity this week. Please check the technical report for details.

Alerts
1047
CVEs
1582
KEV
11
Critical
488

Top news

  • TAKTISCH SecurityWeek
    Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks

    The vulnerability is being actively exploited by a Node.js-based RAT (PivotC2) and has been added to the CISA KEV catalog, indicating rapid proliferation and heightened risk.

    → CVE-2025-25249 affects Fortinet FortiOS and FortiSwitchManager, which are core components of the company's network infrastructure; active exploitation by PivotC2 RAT indicates imminent risk.

  • TAKTISCH The Hacker News
    CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline

    Threat actors are deliberately targeting inadequately monitored perimeter edge devices to gain initial access via these vulnerabilities and deploy post-exploitation tools such as PivotC2.

    → CISA has flagged three actively exploited vulnerabilities affecting Cisco, Citrix, and Fortinet devices with a federal patch deadline of September 12, 2026; Fortinet FortiGate is in the company's tech stack.

  • TAKTISCH ZDI: Published Advisories
    ZDI-26-662: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability

    A use-after-free vulnerability in Adobe Acrobat Reader DC enables remote code execution with CVSS 7.8, but requires user interaction (visiting a malicious page or opening a malicious file).

    → Adobe Acrobat Reader DC is explicitly listed in the company tech stack; a high-CVSS RCE vulnerability affecting this application poses direct operational risk.

  • TAKTISCH ZDI: Published Advisories
    ZDI-26-669: Adobe Acrobat Reader DC JBIG2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

    Low-severity vulnerability (CVSS 3.3) in Adobe Acrobat Reader DC with information disclosure potential through malicious PDF files, requires user interaction.

    → Adobe Acrobat Reader DC is in the company tech stack; JBIG2 parsing vulnerability with low CVSS (3.3) requires user interaction but affects information disclosure.

  • TAKTISCH ZDI: Published Advisories
    ZDI-26-495: (Pwn2Own) VMware ESXi VMXNET3 espQueueMask Out-Of-Bounds Write Local Privilege Escalation Vulnerability

    An out-of-bounds write vulnerability in VMware ESXi VMXNET3 driver enables local attackers to escalate privileges on guest virtual machines; demonstrated at Pwn2Own 2026.

    → VMware ESXi is central to the company's infrastructure (VMware vSphere 8 / ESXi, VMware vCenter Server); a local privilege escalation vulnerability in the VMXNET3 component poses significant risk.

  • TAKTISCH The Hacker News
    Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed

    A patch for CVE-2026-69414 (ShieldBreak) has not fully remediated the issue; the researcher demonstrated with ShieldCrash that the vulnerability can still be triggered under specific conditions and arbitrary files can be read with SYSTEM privileges.

    → Microsoft Defender is directly used in the company's tech stack (Microsoft Defender for Endpoint, Microsoft Defender for Office 365); a patch bypass for a critical vulnerability affecting all supported Windows versions poses a direct operational risk.

  • TAKTISCH SecurityWeek
    Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day

    Adobe releases a patch roundup report covering 170+ vulnerabilities without describing an active exploitation campaign or targeted attacks.

    → Adobe Commerce and ColdFusion are not in the company's stated tech stack, but Adobe Creative Cloud (Photoshop, Acrobat) and Adobe Acrobat Reader DC are deployed; this patch roundup covers multiple unrelated products and does not describe active exploitation.

  • OPERATIV ZDI: Published Advisories
    ZDI-26-534: (Pwn2Own) Microsoft Exchange Capture-Replay Authentication Bypass Vulnerability

    The vulnerability was demonstrated as a zero-day at Pwn2Own and allows unauthenticated bypass of Exchange authentication , an indication that patches may only become available with a delay.

    → Microsoft Exchange is tightly interlinked as an authentication backend with Active Directory, Entra ID and Microsoft 365 and is therefore potentially present in the organisation's environment.

  • TAKTISCH ZDI: Published Advisories
    ZDI-26-619: Microsoft Windows UMPDDrvStretchBltROP Improper Object Management Local Privilege Escalation Vulnerability

    Local privilege escalation in Windows graphics driver requires prior code execution capability; dangerous when chained with remote code execution vulnerabilities.

    → Local privilege escalation vulnerability in Microsoft Windows affects core operating system used throughout the company's infrastructure (Windows Server 2022, 2019).

  • TAKTISCH ZDI: Published Advisories
    ZDI-26-622: Microsoft Windows IKEv2 AES-GCM Decryption Integer Underflow Remote Code Execution Vulnerability

    Unauthenticated remote code execution in Windows IKEv2 implementation with high CVSS score (8.1), but limited attack surface due to specific IPsec configuration prerequisites.

    → Microsoft Windows IKEv2 vulnerability affects core infrastructure component (Windows Server 2022/2019) used in company tech stack; CVSS 8.1 with unauthenticated RCE potential requires monitoring, but exploitation limited to specific IPsec configurations.

  • TAKTISCH The Hacker News
    SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

    A CVSS-10.0 vulnerability in SAP Extended Passport Processing enables complete remote code execution without authentication and requires immediate patch implementation for all SAP instances.

    → SAP Business One is documented in Joel Traber AG's technology stack; a CVSS-10.0 vulnerability in SAP Extended Passport Processing enabling unauthenticated remote code execution poses a critical risk to ERP security.

  • TAKTISCH SecurityWeek
    Check Point Patches Critical VPN Vulnerabilities

    The alert provides no details on active exploitation, affected versions, or patch urgency , it is a generic patch announcement without context on threat activity or deployment timeline.

    → Check Point VPN products are widely used in enterprise environments for remote access; critical RCE vulnerabilities in VPN infrastructure pose direct operational risk to organizations using these solutions.

  • OPERATIV ZDI: Published Advisories
    ZDI-26-571: Linux Kernel Net Scheduler Packet Classifier API Use-After-Free Local Privilege Escalation Vulnerability

    The flaw allows local attackers to escalate privileges in the Linux kernel and affects unpatched Ubuntu systems.

    → The vulnerability affects the Linux kernel used by Ubuntu 24.04 LTS in the company's server infrastructure, allowing local privilege escalation.

  • TAKTISCH Tenable Blog
    Microsoft's September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)

    The largest Patch Tuesday release with 964 CVEs, including 104 critical vulnerabilities, addresses privilege escalation in Windows Update Stack and authentication bypass in Exchange Server, requiring immediate evaluation and prioritization.

    → Microsoft Patch Tuesday covers 964 CVEs including critical elevation-of-privilege and authentication-bypass vulnerabilities affecting Windows Server, Exchange Server, and other core components in the company's tech stack.

  • TAKTISCH Rapid7 Cybersecurity Blog
    Patch Tuesday - September 2026

    Two Windows EoP zero-days (ALPC, Update Stack) with active exploitation are addressed in Microsoft Patch Tuesday September 2026; CVSS 7.8 may understate operational risk for systems vulnerable to locally-exploitable privilege-escalation vectors.

    → Microsoft Patch Tuesday September 2026 includes multiple zero-day elevation-of-privilege vulnerabilities (CVE-2026-85880, CVE-2026-81963) in Windows ALPC and Update Stack with active exploitation detected; Windows Server 2022/2019 are directly in the company tech stack.

Research Deep Dives

View all →
  • TENABLE BLOG 08/09/2026
    Microsoft's September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)

    The largest Patch Tuesday release with 964 CVEs, including 104 critical vulnerabilities, addresses privilege escalation in Windows Update Stack and authentication bypass in Exchange Server, requiring immediate evaluation and prioritization.

  • RAPID7 CYBERSECURITY BLOG 08/09/2026
    Patch Tuesday - September 2026

    On September 2026 Patch Tuesday, Microsoft published 999 vulnerabilities total: 974 in its own products including 723 Windows vulnerabilities, plus fixes for 25 non-Microsoft CVEs. This is the largest single-day CVE release ever. Microsoft confirmed active exploitation for two zero-days: CVE-2026-85880 in Windows ALPC and CVE-2026-81963 in the Windows Update Stack, both enabling privilege escalation to SYSTEM. Windows 11 and Server 2025 do not receive patches for CVE-2026-85880, likely due to Rust-based memory safety improvements.

  • MALWAREBYTES 09/09/2026
    Microsoft fixes record 964 flaws, including 2 exploited zero-days

    Microsoft's September 2026 Patch Tuesday fixes 964 CVEs, the largest release on record, including 104 rated critical and 860 rated important. The update addresses two actively exploited zero day vulnerabilities that allow local privilege escalation to SYSTEM, but provide no remote access by themselves. It also includes high severity remote code execution flaws in Windows DNS Server and Remote Desktop Services, along with fixes for Exchange Server, SharePoint, SQL Server, Office, and core Windows components. Customers should apply the updates via Windows Update and verify that their systems are up to date.

Top vendors

  • Microsoft 806
  • Google 77
  • Adobe 68
  • Sap 16
  • Fortinet 15
  • Linux 10

Top CVEs

  • CVE-2025-25249 CVE-2025-25249 , Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability 8.1
  • CVE-2026-81963 CVE-2026-81963 , Microsoft Windows Link Following Vulnerability 7.8
  • CVE-2026-85880 CVE-2026-85880 , Microsoft Windows Heap-Based Buffer Overflow Vulnerability 7.8
  • CVE-2026-20079 CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline 10.0
  • CVE-2026-78510 CVE-2026-78510: Heap-based Buffer Overflow in Microsoft Office Word Allows Remote Code Execution 9.8
  • CVE-2026-69556 CVE-2026-69556: Heap-based Buffer Overflow in Microsoft Office Word Allows Remote Code Execution 8.8
ESC