Threat Intel Bi-Weekly + AI Vuln Monitor | Coverage: September 9, 2026 - September 9, 2026 | Sources: NVD • CISA KEV • Microsoft MSRC • Google GTIG • Palo Alto PSIRT • BleepingComputer • OWASP LLM | Published: Wednesday, September 9, 2026 -23% vs prior run
[!!] ALERT THRESHOLD BREACHED

CVEs & Exploits

[CRITICAL]

CVE-2026-72982 — Windows Netlogon

Unauthenticated remote code execution vulnerability in Windows Netlogon service with CVSS 9.8. Attacker can send specially crafted packet to execute arbitrary code on target system without authentication.

REMEDIATION

Apply September 2026 Patch Tuesday updates immediately. Prioritize domain controllers and systems with Netlogon service exposed. Monitor network traffic for suspicious Netlogon packets.

Source: MSRC  •  Published: 2026-09-08

[CRITICAL]

CVE-2026-69676 — Windows Kerberos

Authentication bypass and remote code execution vulnerability in Windows Kerberos with CVSS 8.8. Attackers with low-level access can exploit capture-replay attacks to execute arbitrary code.

REMEDIATION

Deploy Microsoft September 2026 patches immediately. Enable Kerberos armoring where supported. Review authentication logs for replay attack indicators. Implement network segmentation.

Source: MSRC  •  Published: 2026-09-08

[CRITICAL]

CVE-2026-69525 — Windows Remote Desktop Services

Use-After-Free vulnerability in Remote Desktop Services enabling unauthenticated remote code execution. CVSS 9.8. Allows remote attackers to run arbitrary code on affected systems without authentication.

REMEDIATION

Patch immediately with September 2026 updates. Restrict RDP access to trusted networks via firewall rules. Enable Network Level Authentication. Deploy multi-factor authentication for remote access.

Source: MSRC  •  Published: 2026-09-08

[CRITICAL]

CVE-2026-67276 — MikroTik RouterOS

Authentication bypass in MikroTik RouterOS SSH allowing attacker to impersonate authorized users without RSA private key. Part of 'MikroTrick' exploit chain with CVSS 9.2. Actively exploited since September 2, 2026.

REMEDIATION

Update to RouterOS versions 7.25beta3, 7.24.2, 7.23.4, or 6.49.21. Check for 'ops' account creation and compromise markers. Restrict SSH to trusted networks. Audit configurations for unauthorized changes.

Source: CERT Polska  •  Published: 2026-09-03

[CRITICAL]

CVE-2026-86060 — MikroTik RouterOS

Privilege escalation vulnerability in MikroTik RouterOS enabling full administrative access when chained with CVE-2026-67276. Exploitation originated from IP 82.192.72.4 starting September 2, three days before disclosure.

REMEDIATION

Apply patches 7.25beta3, 7.24.2, 7.23.4, or 6.49.21 immediately. Check /system/device-mode/print for flagged marker. Review for unknown users, scripts, firewall rules, and configuration changes.

Source: CERT Polska  •  Published: 2026-09-03

[CRITICAL]

CVE-2026-82004 — Adobe Campaign Classic

Operating system command injection in Adobe Campaign Classic with maximum CVSS 10.0 score enabling arbitrary code execution. Part of Adobe's 170-vulnerability September 2026 Patch Tuesday release.

REMEDIATION

Apply Adobe Campaign Classic security updates within three days (Priority 1). Review system logs for suspicious command execution. Implement least-privilege access and input validation controls.

Source: Adobe  •  Published: 2026-09-08

[CRITICAL]

CVE-2026-48273 — Adobe ColdFusion

Critical arbitrary code execution vulnerability in Adobe ColdFusion with CVSS 9.9. One of two critical ColdFusion vulnerabilities in September 2026 Adobe updates affecting enterprise application servers.

REMEDIATION

Deploy Adobe ColdFusion patches within three days. Restrict administrative interface access. Review application logs for exploitation attempts. Implement web application firewall rules.

Source: Adobe  •  Published: 2026-09-08

[CRITICAL]

CVE-2026-75746 — Adobe ColdFusion

Second critical vulnerability in Adobe ColdFusion with CVSS 9.1 enabling arbitrary code execution. Part of Adobe's September 2026 security update addressing 170 vulnerabilities across product portfolio.

REMEDIATION

Apply ColdFusion security updates immediately (Priority 1 - within 3 days). Audit for unauthorized file system modifications. Enable detailed logging and monitoring for suspicious activity.

Source: Adobe  •  Published: 2026-09-08

AI & Supply Chain

[CRITICAL]

CVE-2026-24301 — Microsoft Copilot Personal

One-click vulnerability in Microsoft Copilot Personal dubbed 'CoSnitch' enabling silent data exfiltration from enterprises without obvious indicators. Attack chain executes through malicious content triggering automated Copilot actions.

REMEDIATION

Apply Microsoft patches released August 18, 2026. Review Copilot activity logs for suspicious data access patterns. Implement data loss prevention controls. Restrict Copilot access to sensitive data sources.

Source: Varonis  •  Published: 2026-08-18

[CRITICAL]

SUPPLY-CHAIN-SHAI-HULUD-2026 — npm packages (keyv, TanStack)

Supply chain attack on keyv package (127M weekly downloads) and TanStack ecosystem stealing GitHub credentials, cloud secrets, SSH keys, and CI/CD tokens. Compromised maintainer account distributed malicious versions. Exposed 33,185 secrets across 20,649 repositories. OpenAI confirmed employee device compromise.

REMEDIATION

Audit all npm dependencies immediately. Implement SBOM tracking. Use package lock files with integrity hashes. Enable npm audit. Review CI/CD logs. Rotate all credentials and API keys.

Source: CM Alliance  •  Published: 2026-08-04

Priority Action Matrix

01DO NOWCVE-2026-72982 (Windows Netlogon): Apply September 2026 Patch Tuesday updates immediately. Prioritize domain controllers and systems with Netlogon service exposed. Monitor network traffic for suspicious Netlogon packets.
02DO NOWCVE-2026-69676 (Windows Kerberos): Deploy Microsoft September 2026 patches immediately. Enable Kerberos armoring where supported. Review authentication logs for replay attack indicators. Implement network segmentation.
03DO NOWCVE-2026-69525 (Windows Remote Desktop Services): Patch immediately with September 2026 updates. Restrict RDP access to trusted networks via firewall rules. Enable Network Level Authentication. Deploy multi-factor authentication for remote access.
04DO NOWCVE-2026-67276 (MikroTik RouterOS): Update to RouterOS versions 7.25beta3, 7.24.2, 7.23.4, or 6.49.21. Check for 'ops' account creation and compromise markers. Restrict SSH to trusted networks. Audit configurations for unauthorized chan...
05DO NOWCVE-2026-86060 (MikroTik RouterOS): Apply patches 7.25beta3, 7.24.2, 7.23.4, or 6.49.21 immediately. Check /system/device-mode/print for flagged marker. Review for unknown users, scripts, firewall rules, and configuration changes.
06DO NOWCVE-2026-82004 (Adobe Campaign Classic): Apply Adobe Campaign Classic security updates within three days (Priority 1). Review system logs for suspicious command execution. Implement least-privilege access and input validation controls.
07DO NOWCVE-2026-48273 (Adobe ColdFusion): Deploy Adobe ColdFusion patches within three days. Restrict administrative interface access. Review application logs for exploitation attempts. Implement web application firewall rules.
08DO NOWCVE-2026-75746 (Adobe ColdFusion): Apply ColdFusion security updates immediately (Priority 1 - within 3 days). Audit for unauthorized file system modifications. Enable detailed logging and monitoring for suspicious activity.
09DO NOWCVE-2026-24301 (Microsoft Copilot Personal): Apply Microsoft patches released August 18, 2026. Review Copilot activity logs for suspicious data access patterns. Implement data loss prevention controls. Restrict Copilot access to sensitive data s...
10DO NOWSUPPLY-CHAIN-SHAI-HULUD-2026 (npm packages (keyv, TanStack)): Audit all npm dependencies immediately. Implement SBOM tracking. Use package lock files with integrity hashes. Enable npm audit. Review CI/CD logs. Rotate all credentials and API keys.

Biggest Risk This Period

BIGGEST RISK

CVE-2026-72982: Unauthenticated remote code execution vulnerability in Windows Netlogon service with CVSS 9.8. Attacker can send specially crafted packet to execute arbitrary code on target system without authentication.