Threat Intel Bi-Weekly + AI Vuln Monitor | Coverage: September 14, 2026 - September 14, 2026 | Sources: NVD • CISA KEV • Microsoft MSRC • Google GTIG • Palo Alto PSIRT • BleepingComputer • OWASP LLM | Published: Monday, September 14, 2026 -12% vs prior run
[!!] ALERT THRESHOLD BREACHED

CVEs & Exploits

[CRITICAL]

CVE-2026-78510 — Microsoft Word

Zero-click remote code execution in Word with CVSS 9.8 exploitable via Preview Pane. Merely previewing a crafted document triggers code execution without user interaction, eliminating social engineering requirements for exploitation.

REMEDIATION

Disable Preview Pane in Outlook and Explorer for all users until patches deployed. Apply Office updates immediately to Microsoft 365 Apps, Office 2019, LTSC 2021 and LTSC 2024 on Windows and Mac.

Source: MSRC  •  Published: 2026-09-08

[CRITICAL]

CVE-2026-78509 — Microsoft Outlook

Critical zero-click RCE in Outlook with CVSS 9.8 exploitable through Reading Pane. No attachment open or macro prompt required - preview alone triggers arbitrary code execution. Part of 12 Preview Pane vulnerabilities in September 2026.

REMEDIATION

Immediately disable Reading Pane in Outlook for all users organization-wide. Deploy September Office security updates on emergency basis. Review email security gateway configurations for additional protection layers.

Source: MSRC  •  Published: 2026-09-08

[CRITICAL]

CVE-2026-84869 — ConnectWise ScreenConnect

Missing authorization and improper privilege management in ScreenConnect with CVSS 9.9. Allows attackers to send and execute files without authorization through active remote sessions. Worm-like propagation observed across multiple organizations distributing VBScript payloads.

REMEDIATION

Update to ScreenConnect version 26.6.5 immediately. Temporary mitigation: deselect TransferFiles permission in Administration > Security > Roles. Review audit logs for unauthorized file transfers August-September 2026. CISA KEV mandates federal patching within 3 days.

Source: CISA  •  Published: 2026-09-03

AI & Supply Chain

[CRITICAL]

MCP-Architectural-Flaw-2026 — Model Context Protocol (MCP) - All SDKs

Systemic architectural flaw in Anthropic's MCP affecting 200,000+ instances across 150M+ package downloads. 43% of MCP servers vulnerable to command injection, 36.7% to SSRF. Design default in official SDKs propagated to all downstream implementations. Over 40 CVEs disclosed Q1-Q2 2026.

REMEDIATION

Block public IP access to MCP servers immediately. Implement behavioral monitoring of agent actions. Sandbox all MCP services. Treat external configuration as untrusted input. Survey shows 82% of implementations vulnerable to path traversal.

Source: OWASP  •  Published: 2026-04-01

Threat Actors & Dark Web

[CRITICAL]

Salt-Typhoon-Telecom-2026 — Telecommunications Infrastructure - 200+ US Organizations

Chinese nation-state actor Salt Typhoon maintains persistent access across 200+ US organizations and 80 countries in telecommunications sector. FBI confirms threats remain active and ongoing. Call records and metadata for tens of millions of subscribers accessible with targeted interception capability.

REMEDIATION

Telecommunications providers must implement enhanced monitoring for lawful intercept systems, deploy behavioral analytics for administrative accounts, and segment management networks. Review CALEA system access and verify no unauthorized intercepts configured.

Source: CISA  •  Published: 2026-02-01

[CRITICAL]

Volt-Typhoon-Critical-Infrastructure-2026 — US Critical Infrastructure - Energy, Water, Communications, Transportation

Chinese nation-state actor Volt Typhoon maintains 5+ year persistent access in US critical infrastructure for pre-positioning disruption capabilities. NSA director characterizes as 'pre-positioning for disruption or destruction' in Taiwan conflict scenario. Living-off-the-land techniques leave minimal malware footprint.

REMEDIATION

Critical infrastructure operators must implement out-of-band monitoring for OT networks, deploy network traffic analysis for LOTL techniques, and establish manual operational procedures not relying on network connectivity. Review SOHO network devices used as proxy infrastructure.

Source: CISA  •  Published: 2024-02-07

[HIGH]

Ransomware-Volume-2026 — Global Organizations - 7,551 victims in 2026

Ransomware disclosures increased 24.9% in 2026 to 7,551 victims, continuing four-year upward trend. Medusa ransomware reached 500+ victim milestone targeting critical infrastructure. JADEPUFFER represents first documented AI agent orchestrating ransomware attack stages. Highest ransom paid: $75M to Devils Angels group.

REMEDIATION

Implement immutable backups with offline copies. Deploy EDR on all systems. Establish and test incident response playbooks quarterly. Focus on rapid detection and isolation to minimize dwell time and lateral movement.

Source: BleepingComputer  •  Published: 2026-08-01

Priority Action Matrix

01DO NOWCVE-2026-78510 (Microsoft Word): Disable Preview Pane in Outlook and Explorer for all users until patches deployed. Apply Office updates immediately to Microsoft 365 Apps, Office 2019, LTSC 2021 and LTSC 2024 on Windows and Mac.
02DO NOWCVE-2026-78509 (Microsoft Outlook): Immediately disable Reading Pane in Outlook for all users organization-wide. Deploy September Office security updates on emergency basis. Review email security gateway configurations for additional pr...
03DO NOWCVE-2026-84869 (ConnectWise ScreenConnect): Update to ScreenConnect version 26.6.5 immediately. Temporary mitigation: deselect TransferFiles permission in Administration > Security > Roles. Review audit logs for unauthorized file transfers Augu...
04DO NOWMCP-Architectural-Flaw-2026 (Model Context Protocol (MCP) - All SDKs): Block public IP access to MCP servers immediately. Implement behavioral monitoring of agent actions. Sandbox all MCP services. Treat external configuration as untrusted input. Survey shows 82% of impl...
05DO NOWSalt-Typhoon-Telecom-2026 (Telecommunications Infrastructure - 200+ US Organizations): Telecommunications providers must implement enhanced monitoring for lawful intercept systems, deploy behavioral analytics for administrative accounts, and segment management networks. Review CALEA sys...
06DO NOWVolt-Typhoon-Critical-Infrastructure-2026 (US Critical Infrastructure - Energy, Water, Communications, Transportation): Critical infrastructure operators must implement out-of-band monitoring for OT networks, deploy network traffic analysis for LOTL techniques, and establish manual operational procedures not relying on...
07TODAYRansomware-Volume-2026 (Global Organizations - 7,551 victims in 2026): Implement immutable backups with offline copies. Deploy EDR on all systems. Establish and test incident response playbooks quarterly. Focus on rapid detection and isolation to minimize dwell time and ...

Biggest Risk This Period

BIGGEST RISK

CVE-2026-78510: Zero-click remote code execution in Word with CVSS 9.8 exploitable via Preview Pane. Merely previewing a crafted document triggers code execution without user interaction, eliminating social engineering requirements for exploitation.