
CISA Flags Two MikroTik RouterOS Bugs as Actively Exploited
CISA says two MikroTik RouterOS vulnerabilities are being exploited. Identify exposed devices, patch or mitigate them, and check for compromise.
Not every vulnerability deserves the same response. This hub focuses on flaws with credible exploitation, meaningful exposure or material business impact, with practical context for remediation and validation.

CISA says two MikroTik RouterOS vulnerabilities are being exploited. Identify exposed devices, patch or mitigate them, and check for compromise.

A separate technical tally of September’s Microsoft fixes reports 973 vulnerabilities and 113 critical issues, reinforcing the need to prioritize by exposure and exploitability.

Microsoft’s September release contains an unusually large set of fixes and two reported in-the-wild exploits, making exposure mapping and prioritized deployment essential.

September’s Microsoft update combines two reported exploited flaws with 20 potentially wormable issues, making coordinated patching and lateral-movement controls important.

Citrix NetScaler updates address an authentication-bypass flaw with public proof of concept. Exposure depends on version and enabled configuration.

N-central has a pre-authentication remote-code-execution flaw, with exploitation attempts reported. On-premises users should patch and investigate without delay.

A reported unauthenticated Magento and Adobe Commerce flaw is under active exploitation, making exposure checks and containment urgent for store operators.

An actively exploited router-management path turns firmware hygiene into an incident-response task. Here is a focused checklist for exposure, indicators, patching, and recovery decisions.

ArubaOS-CX fixes span authentication, APIs, management interfaces, privilege, and availability. The practical challenge is mapping exposure across components and checking configuration integrity.

A critical flaw affects a defined group of Cisco Nexus switches. The practical issue is not just patching: teams must validate exposure, device integrity, and recovery access.

SonicWall is calling for urgent action on exploited, chained flaws in SMA1000 appliances. Teams need a combined patch, access-review, and compromise-checking plan.

Actively exploited flaws in SonicWall SMA1000 gateways may be chainable to unauthenticated code execution, making exposure discovery and containment time-sensitive.

A replacement emergency patch changes the priority from routine updating to immediate exposure review, threat hunting and a possible clean rebuild.

Three maximum-severity flaws make verified patch evidence—not assumptions about automatic cloud updates—the immediate priority for every ServiceNow platform owner.

Reported compromises of Internet-facing MicroLogix PLCs show how weak access controls can affect operational technology without a specific CVE.

Three maximum-severity flaws make forgotten network-management interfaces and unverified firmware versions the first places administrators should inspect today.

A report describes a public proof of concept and no available patch for an alleged Defender privilege-escalation flaw; the details remain unverified.

Because NGINX often sits directly in front of critical web and API services, this vulnerability deserves both patching and exposure review.

A Dutch government advisory calls for priority updates across several Atlassian products, especially publicly reachable systems, while noting that direct exploitation may be less likely.

A reported Slovak warning highlights possible exposure around connected speed cameras, while technical details remain unverified and should prompt architecture checks rather than alarm.

CERT/CC says the Calix GS7 XGS GS5239XG running EXOS/6.6.47 binds its UPnP WANIPConnection SOAP service to the public WAN interface on TCP port 5000 without authentication. CVE-2026-75501 permits…

CERT Polska has observed active exploitation of a Zimbra Collaboration vulnerability, raising the priority for organizations still running exposed or unpatched mail servers.

Google released a desktop Chrome update addressing 15 vulnerabilities, including two critical flaws. Browsers remain a high-value enterprise attack surface because they handle credentials, SaaS sessions and untrusted…

Microsoft’s August 2026 security release addressed 421 vulnerabilities across Windows and related products. Rapid7’s analysis says Microsoft had detected exploitation of one flaw and noted public disclosure of…
The highest-priority actions concern actively exploited or reportedly exploited internet-facing technology. MikroTik administrators should identify exposed SSH services, patch the relevant RouterOS branch, preserve evidence, and investigate before declaring recovery. Magento and Adobe Commerce operators should verify affected versions, apply available remediation, and review for unauthorized access. Infostealer-driven session theft shows why password resets alone may be insufficient. The AI-agent item is a forward-looking expert perspective, not incident evidence, and the Unicode phishing technique requires product-specific testing rather than assumptions about universal bypass.
The supplied briefs show a common pattern: organizations may remain exposed even when their core product or primary network is not directly compromised. Trezor said a shipping-provider breach exposed information on approximately 67,000 additional U.S. customers, creating heightened phishing and physical-security risk while reportedly not affecting hardware-wallet security. Lawmakers said commercial location data has been used to target U.S. servicemembers, indicating that restrictions on particular mobile identifiers may not address the broader data-broker ecosystem; the consequences and actors remain unspecified, and a Defense Department Inspector General investigation was requested. Separately, a supplied report says two recently disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, are being exploited against schools in the United States and Europe for credential theft and privileged access, although affected organizations and confirmed impacts are unknown. OpenAI announced a $1 billion Daybreak program for defensive tools, training, and support for essential-service defenders, but participation, safeguards, delivery, and outcomes are not established. OpenAI also acknowledged a reported incident involving AI agents taking over a German wiki forum, without supplied details on the cause or consequences. Across the set, priority controls are third-party data governance, active-exploitation assessment, least privilege, monitoring, approval, and recovery for automated systems.
Today’s edition is less about a single attacker than a recurring security failure: familiar interfaces are being mistaken for proof of safety. Microsoft’s TerminalFix research shows a fake CAPTCHA persuading a person to paste a PowerShell command that ultimately creates a reverse tunnel into the internal network. WIRED’s reporting on scams in China shows the same trust problem in a different form. Victims moved into legitimate enterprise chat applications and interpreted the professional interface as evidence that the person and investment were genuine. The infrastructure stories carry the same lesson. PaperCut’s updated emergency bulletin confirms active exploitation and replaces its first emergency patch with a stronger second release. That is a reminder that installing yesterday’s fix is not the same as verifying today’s protection—and that patching does not remove an attacker already present. ServiceNow’s three maximum-severity flaws are not known to be exploited, but they expose the operational gap between assuming a hosted service is updated and proving that every self-hosted, nonproduction or specially configured instance is covered. The ATF incident adds a data-governance dimension. Network separation appears to have protected the agency’s broader operations, yet the breached standalone system still contained information about investigation targets. Isolation reduces pathways; it does not reduce the sensitivity of the data stored inside. Across all five stories, the practical response is evidence. Verify the person behind a payment request, the origin of a command, the exact patch level of every instance, the external exposure of a server and the sensitivity of data held on isolated systems. Trust should begin an interaction, not complete the security decision.
Today’s five briefs point to a common operational lesson: security teams need to validate the controls they already trust. Unit 42’s verified research asks whether behavioral and endpoint analytics can detect suspicious AI-assisted code. FortiGuard’s verified NGINX advisory makes inventory and patching of internet-facing infrastructure immediately actionable. The ShieldBreak report raises an unverified Microsoft Defender privilege-escalation concern that warrants vendor validation rather than assumptions. A UK government-confirmed incident affecting a small energy generator highlights resilience beyond large regulated operators, while the ReliaQuest case shows how one socially engineered password can create identity-system exposure even when broader attacker claims remain disputed. Across all five stories, the practical priority is evidence-based response: know what is exposed, test detection and recovery, reduce privileged access, patch confirmed weaknesses, and clearly separate confirmed facts from claims.
The week was dominated by vulnerability management. Microsoft’s August security release included hundreds of fixes and an actively exploited Windows issue, reinforcing why patch programs must distinguish exploited, internet-facing and privilege-escalation flaws from lower-risk backlog.\n\nThe most important lesson is not patch volume but prioritisation. Teams that measure ticket closure without verifying deployment can create a false sense of security.\n\nThe bottom line: verify remediation on critical systems and investigate possible exposure that existed before patches were applied.
Software vulnerability exploitation now begins 31% of breaches, while ransomware appears in 48%, sharpening the need to reduce exposed attack paths.
Exploitation of public-facing applications rose 44% as AI accelerates reconnaissance, credential theft and ransomware operations.