September 16, 2026 | Jonathan Brown
Command View
Verification cutoff
September 16, 2026, 13:10 UTC.
This edition covers material verified through the cutoff above. “Active exploitation,” affected-version, and remediation statements are tied to named primary sources. Honeypot observations, exposure estimates, attacker claims, victim-confirmed impact, and government catalog status are identified separately.
Priority posture
- RED: CISA lists CVE-2026-84869 as exploited; the flaw lets a low-privilege participant in an active ScreenConnect session transfer and execute files without host confirmation. CISA now flags VMware vCenter CVE-2026-59310 as used in ransomware campaigns. Acronis reports limited, targeted exploitation of CVE-2026-87886 against its Backup plugin for cPanel & WHM.
- AMBER: Honeypot telemetry shows forged administrative JWTs targeting WSO2 CVE-2026-5430, but no production-victim compromise is publicly confirmed. CenterPoint Energy confirms that an intruder obtained some customer personal information through one external-facing system; electric and gas delivery remained operational and undisrupted.
- WATCH: Oracle’s September Critical Security Patch Update contains 673 new security patches across identity, database, middleware, banking, communications, supply-chain, utility, and virtualization products. Google says CVE-2026-58704 may be under limited, targeted exploitation on supported Pixel devices.
No newly verified destructive OT event, safety-system outage, or interruption of essential service met the inclusion threshold by the cutoff.
Today’s decisions
- RED — MSP and remote-support owners: upgrade every on-premises ScreenConnect deployment to 26.6.5 or later, refresh host clients and access agents, and review active sessions, technicians, roles, audit history, transfers, and endpoint execution. Removing
TransferFilesis temporary risk reduction, not a patch. - RED — Virtualization owners: patch vCenter to the fixed release for its branch—9.1.0.0300, 9.0.2.0100, 8.0 U3k, or 8.0 U2f—and hunt for unauthorized
reverse_sshdeployment and unexplained outbound control channels. There is no vendor workaround. - RED — Hosting and backup owners: update Acronis Backup plugin for cPanel & WHM to 1.9.3 HF3, build 1.9.3.1021, and the Plesk extension to 1.8.11, build 638. Because exploitation requires a low-privilege foothold, investigate how any suspicious local account or process first arrived.
- AMBER — API platform owners: apply the exact WSO2 update level or open-source fixes for CVE-2026-5430; search gateway and identity logs for unsupported JWT algorithms, unexpected administrator tokens, new applications, credentials, subscriptions, and secret access.
- AMBER — Energy-sector and public-facing application owners: use CenterPoint’s disclosure to verify internet-facing customer systems, enforce IT/OT separation, preserve web/API and identity telemetry, and rotate exposed credentials or tokens. Do not infer an OT compromise from the customer-data incident.
- WATCH — Oracle product owners: map the September CSPU to actual product/version inventory and prioritize externally reachable identity, WebLogic, E-Business Suite, communications, banking, utility-management, and database components. Oracle did not report active exploitation of the newly patched September flaws.
- WATCH — Managed mobile fleets: move supported Pixel devices to security patch level 2026-09-05 or later, prioritizing privileged, executive, journalist, government, and incident-response users.
Threat and Resilience Ledger
RED — Remote support and managed-service trust | Global — ScreenConnect file transfer and execution flaw is exploited
CVE-2026-84869, CWE-862/CWE-269, CVSS 3.1: 9.9 Critical, affects ConnectWise ScreenConnect versions before 26.6.5. Through an active Remote Access Support or Access session, an attacker with basic privileges can transfer and execute files without authorization or host confirmation. ConnectWise says ScreenConnect servers themselves are not affected; the exposed trust boundary is the client/session workflow and the endpoints reachable through it.
Upgrade on-premises deployments to 26.6.5 or later. Cloud instances are vendor-upgraded, but ConnectWise instructs customers to reinstall host clients and update access agents after the service update. If immediate patching is impossible, remove TransferFiles from every role and session-group permission set until the update is complete. Then review users, roles, permissions, sessions, audit logs, transferred files, endpoint process creation, and downstream credentials. Suspected compromise requires isolation, evidence preservation, full-scope incident response, and rebuild criteria—not only a version check.
Evidence: ConnectWise published the patch on September 8 and assigned Priority 1–High. CISA’s September 11 item-specific alert added the CVE to the Known Exploited Vulnerabilities catalog and required U.S. federal remediation by September 14. A September 16 BleepingComputer report provides a forwarding-safe account of the CISA status and cites Shadowserver tracking more than 1,000 still-exposed vulnerable instances. The exposure count is not a victim count.
Attribution: unknown.
Confidence: high for the flaw, version boundary, fix, and exploitation status; these are documented by ConnectWise and CISA.
Uncertainty: neither ConnectWise nor CISA has publicly identified the attackers, victim count, initial session-access route, payload set, or confirmed ransomware use for this CVE.
Sources: ConnectWise security bulletin; CISA item-specific alert; CVE Program record; BleepingComputer forwarding-safe report.
RED — Virtualization control plane | Global — CISA marks VMware vCenter CVE-2026-59310 as used in ransomware campaigns
CVE-2026-59310, CVSS 3.1: 9.8 Critical, is a directory-traversal flaw in the vCenter Syslog server. An unauthenticated actor with network access to vCenter can execute arbitrary code. Broadcom lists no workaround. A compromised vCenter management plane can expose virtual-machine inventory, administrative credentials, configuration, snapshots, and a path toward broad service disruption.
Fixed vCenter releases are 9.1.0.0300, 9.0.2.0100, 8.0 U3k, and 8.0 U2f, according to the deployed branch. vCenter 7.0 customers require an extended-support contract and Broadcom guidance. VMware Cloud Foundation 5.x and VMware Telco Cloud products have separate vendor patch paths. Patch immediately, remove direct internet reachability, restrict management-plane access, and search appliance and egress telemetry for unexpected binaries, SSH processes, new keys, outbound tunnels, and reverse_ssh behavior.
Evidence: Broadcom’s VMSA-2026-0006.2 establishes the flaw, attack path, affected branches, fixed releases, and absence of a workaround. QUIRSO previously reported 361 compromised IP addresses across 47 countries and observed reverse_ssh persistence beginning five days after disclosure; it explicitly cautions that IP counts do not equal unique organizations. CISA later added the CVE to KEV and, over the September 12–13 weekend, marked known ransomware-campaign use. CISA has not published case detail; the ransomware status is therefore authoritative catalog metadata without a public incident narrative.
Attribution: CISA has not named a ransomware group. QUIRSO separately assesses a suspected Chinese-nexus actor in the earlier reverse-SSH campaign; that assessment must not be conflated with the unspecified ransomware activity.
Confidence: high for exploitation, fixed versions, and CISA’s ransomware-use flag; moderate for the relationship, if any, among the observed campaigns.
Uncertainty: ransomware operators, victim organizations, entry timing, payloads, and operational impact remain undisclosed.
Sources: Broadcom VMSA-2026-0006.2; QUIRSO primary research; BleepingComputer forwarding-safe report of CISA’s ransomware status; CVE Program record.
RED — Backup and hosting control plane | Global — Acronis reports limited targeted exploitation of local privilege escalation
CVE-2026-87886, CVSS: 7.8 High, is an insecure-file-permissions vulnerability that can let a low-privilege local actor elevate privileges on Linux servers using Acronis hosting-control-panel integrations. Acronis reports exploitation against its Backup plugin for cPanel & WHM; it has not reported exploitation of the Plesk extension.
Affected and fixed builds are:
- Acronis Backup plugin for cPanel & WHM: builds earlier than 1.9.3.1021; fixed in 1.9.3 HF3, build 1.9.3.1021.
- Acronis Backup extension for Plesk: builds earlier than 1.8.11.638; fixed in 1.8.11, build 638.
Update immediately. Inventory shared-hosting nodes, reseller environments, and backup integrations; review low-privilege accounts, control-panel logins, package and file-permission changes, privileged child processes, backup configuration, and access to stored data or credentials. If escalation is suspected, preserve evidence and determine the initial foothold before rebuilding and rotating secrets. The flaw is not an unauthenticated remote entry point on its own.
Evidence: Acronis says exploitation was detected “in limited, targeted attacks” against cPanel/WHM deployments. In its response to BleepingComputer, the company said this assessment rests on a single report from a potentially affected customer. Acronis has not released indicators or described attacker outcomes.
Attribution: unknown.
Confidence: high for the affected/fixed builds and vulnerability mechanics; moderate for campaign scale because the exploitation statement is based on one potentially affected-customer report.
Uncertainty: initial access, victim identity, attack date, payload, persistence, and any data or backup impact are unknown.
Sources: Acronis advisory UPD-2609-3d72-20a7; CVE Program record; BleepingComputer and SecurityWeek corroboration.
AMBER — API management and identity | Global — Forged administrative JWTs target WSO2 authentication bypass
CVE-2026-5430, WSO2 advisory WSO2-2026-5328, is a JWT authentication bypass: a token signed with an unsupported algorithm can be accepted, enabling unauthorized access, administrative-account compromise, and full account takeover. WSO2 scores the issue CVSS 3.1: 10.0 in multi-tenant deployments and 9.8 in single-tenant deployments.
Affected products are WSO2 API Control Plane 4.5.0 and 4.6.0; API Manager 4.1.0–4.6.0 in the vendor-listed release set; Traffic Manager 4.5.0 and 4.6.0; and Universal Gateway 4.5.0 and 4.6.0. Subscription customers must reach at least these update levels:
- API Control Plane: 4.6.0 UL22 or 4.5.0 UL58.
- API Manager: 4.6.0 UL21; 4.5.0 UL57; 4.4.0 UL72; 4.3.0 UL108; 4.2.0 UL197; 4.1.0 UL257.
- Traffic Manager: 4.6.0 UL21 or 4.5.0 UL56.
- Universal Gateway: 4.6.0 UL21 or 4.5.0 UL57.
Open-source users should apply WSO2’s two public code fixes or migrate to the latest unaffected release. Review JWT-validation errors and unsupported algorithms, unexpected administrator claims, token issuers and audiences, new applications/subscriptions, credential or consumer-key access, and API calls inconsistent with the asserted identity. Rotate exposed secrets if unauthorized administrative access is found.
Evidence: WSO2’s May 3 advisory establishes the vulnerability, products, versions, scores, and fixes. watchTowr reported honeypot receipt of forged JWTs containing baked-in administrator privileges on September 13. This establishes exploitation attempts against monitored infrastructure, not successful compromise of a production victim.
Attribution: unknown.
Confidence: high for vulnerability and remediation; high for observed exploit attempts; low for successful production compromise because none is publicly confirmed.
Uncertainty: attacker identity, target selection, successful access, stolen secrets, and downstream API abuse remain unverified.
Sources: WSO2 advisory WSO2-2026-5328; CVE Program record; The Hacker News and SecurityWeek reporting of watchTowr telemetry.
AMBER — Energy customer systems | United States — CenterPoint confirms personal-information theft without service disruption
CenterPoint Energy disclosed that an unauthorized third party obtained personal information relating to a portion of customers through one external-facing system. The company activated incident response, engaged third-party experts, notified law enforcement, and is determining the affected population and data types. It states that electric and gas delivery was not impacted and remained operational and undisrupted.
Energy-sector operators should preserve public-application, API gateway, WAF, identity, database, and egress logs; inventory customer portals and guest-payment paths; test whether application identities can reach operational networks; and validate token, credential, and third-party access boundaries. Customer-data compromise at a utility warrants sector attention, but the public record does not establish OT access, grid manipulation, or service risk.
Evidence: CenterPoint’s September 14 Form 8-K confirms unauthorized acquisition of personal information and absence of service impact. The filing does not quantify affected customers or identify data fields. An attacker claimed nearly 7.5 million records and published an archive; those figures and the alleged content remain unverified by the company and are not treated here as confirmed impact.
Attribution: unknown.
Confidence: high for a breach of an external-facing system, some customer-personal-information loss, and no operational disruption; low for attacker-claimed scope.
Uncertainty: entry method, affected application, dwell time, exact records, customer count, and whether credentials or reusable tokens were obtained remain under investigation.
Sources: CenterPoint Energy Form 8-K filed with the U.S. SEC; CenterPoint investor-relations filing index; SecurityWeek and Reuters corroboration.
WATCH — Enterprise and critical-sector suppliers | Global — Oracle releases 673-patch September CSPU
Oracle’s September 15 Critical Security Patch Update contains 673 new security patches spanning identity, database, middleware, E-Business Suite, PeopleSoft, communications, banking, supply-chain, utilities, and virtualization products. Material critical-systems inventory includes Oracle Access Manager 12.2.1.4.0, 14.1.2.0.0, 14.1.2.1.0; Database Server 19.3–19.32, 21.3–21.23, 23.4.0–23.26.3; E-Business Suite 12.2.3–12.2.15 and V16; Enterprise Manager 13.5 and 24.1; WebLogic Server 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0; PeopleTools 8.61–8.63; VirtualBox 7.2.16; and multiple Oracle Utilities Network Management System branches.
There is no single universal “fixed version.” Product owners must use the applicable Oracle Patch Availability Document and My Oracle Support instructions. Prioritize internet-facing identity, middleware, and communications services; systems holding privileged database or enterprise-management access; and utility, banking, or supply-chain applications with high consequence of compromise. For Oracle Database, the release includes 11 new patches, five for flaws remotely exploitable without authentication; CVE-2026-83351 is an unauthenticated network flaw rated CVSS 8.1 affecting Database Server 23.4.0–23.26.3.
Evidence: Oracle’s primary advisory documents the patch count, products, version ranges, risk matrices, and mitigation guidance.
Exploitation status: Oracle warns generally that attackers exploit previously patched Oracle weaknesses when customers fail to patch. Neither the advisory nor Oracle’s release material identifies active exploitation of a vulnerability newly fixed in this September CSPU. Do not convert that general warning into a current exploitation claim.
Confidence: high for the patch inventory and affected supported releases.
Uncertainty: estate-specific exposure and exploitability depend on deployed components, privileges, protocols, and network reachability.
Sources: Oracle September 2026 CSPU advisory; Oracle Security blog; SecurityWeek summary.
WATCH — Privileged mobile endpoints | Global — Google patches Pixel modem flaw with limited targeted exploitation indication
Google says CVE-2026-58704, a High-severity elevation-of-privilege flaw in the Pixel modem, may be under limited, targeted exploitation. Google provides no attacker, target, exploit-chain, or impact detail. Supported Pixel devices at security patch level 2026-09-05 or later address the issue and all vulnerabilities in the September Pixel and Android bulletins.
Prioritize managed Pixel devices used by administrators, executives, government personnel, journalists, incident responders, and others likely to face targeted exploitation. Verify patch level through mobile-device management rather than assuming automatic rollout completion; restrict or quarantine noncompliant privileged devices according to fleet policy.
Evidence: Google’s September Pixel Update Bulletin is the primary source for the exploitation indication, severity, component, and fixed patch level.
Attribution: unknown.
Confidence: high for Google’s limited-targeted-exploitation indication and patch level; low for any inference about victim or campaign scope.
Uncertainty: affected Pixel models, delivery vector, prerequisites, and exploit-chain role are not publicly detailed in the bulletin.
Sources: Google Pixel Update Bulletin—September 2026; CVE Program record; BleepingComputer corroboration.
Defensive Posture Changes
Remote support and MSP access
- Move ScreenConnect from patch-only handling to session and endpoint compromise assessment. The server may be unaffected while endpoints reached through authorized sessions are not.
- Require evidence that cloud/on-premises service versions, host clients, and access agents are all current. Review roles and
TransferFilespermission after the upgrade rather than leaving broad temporary access in place.
Virtualization and backup control planes
- Remove vCenter from direct internet exposure, enforce management-network allowlists, and correlate appliance logs with network egress because appliance-local evidence may be altered.
- Treat backup-plugin privilege escalation as a two-stage incident: identify both the initial low-privilege foothold and subsequent root-level activity. Validate restoration integrity and rotate secrets accessible to the backup integration.
API identity and token validation
- Reject unsupported JWT algorithms explicitly and alert when a token claims administrative roles inconsistent with its issuer, audience, client, or normal behavior.
- After WSO2 remediation, invalidate suspect sessions and review newly created applications, subscriptions, keys, and secrets; patching does not undo previously issued or stolen credentials.
Energy customer platforms and IT/OT separation
- Preserve telemetry before making broad portal changes. Validate that customer-service applications cannot reach operational identity, management, or control networks through inherited trust.
- Keep customer-data breach response and OT incident response connected but evidentially distinct; current reporting confirms the former and does not establish the latter.
Patch orchestration
- Use Oracle’s product-specific patch documents; do not treat “September CSPU applied” as a single binary fleet state.
- Accelerate Pixel patch verification for high-risk users while avoiding unsupported claims about a broad Android issue; Google’s active-exploitation note is specific to the Pixel bulletin entry.
Regional and Sector Pulse
North America — RED
CenterPoint confirms customer-information theft in a U.S. energy utility without electric or gas delivery disruption. North America also contains most of the still-exposed ScreenConnect population in the cited Shadowserver snapshot. VMware, WSO2, Acronis, Oracle, and Pixel actions apply globally.
Latin America and the Caribbean — CONTEXT
No independently verified new region-specific critical-systems compromise met the cutoff. ScreenConnect, vCenter, WSO2, Oracle, and hosting-control-panel exposure remain applicable to regional operators and service providers.
Europe — RED
QUIRSO’s earlier vCenter campaign telemetry placed Germany and France among the five countries with the most observed compromised IPs; shared or hosted IPs do not equal unique organizations. CISA’s later ransomware-use flag increases urgency for European virtualization estates.
Africa — CONTEXT
No independently verified new Africa-specific critical-systems incident met the cutoff. The absence of a qualifying public report is not evidence of low activity; apply global remote-support, virtualization, API, Oracle, and hosting controls based on local exposure.
Middle East — RED
QUIRSO’s vCenter telemetry included Iran among the five most represented countries by compromised IP address. This is geographic victim-infrastructure reporting, not attacker attribution. No additional independently verified regional operational impact met the cutoff.
Asia — AMBER
WSO2, headquartered in Sri Lanka and widely deployed internationally, faces observed exploitation attempts against its API-management trust boundary. Acronis’s cPanel/WHM issue is particularly relevant to hosting providers; no public victim geography is available.
Russia — CONTEXT
No independently verified new Russia-specific critical-systems development met the cutoff. Hosting or source-IP geography in global exploitation should not be used as actor attribution.
China — CONTEXT
No new China-specific critical-systems event met the cutoff. QUIRSO’s separate suspected Chinese-nexus assessment for an earlier vCenter campaign does not attribute CISA’s newly flagged ransomware activity.
Indo-Pacific, including India — WATCH
Google’s Pixel exploitation indication matters most to high-risk managed mobile users across government, media, technology, and incident response. No independently verified India-specific critical-systems compromise met the cutoff; global WSO2, Oracle, ScreenConnect, VMware, and Acronis remediation still applies.
Vulnerability and Supplier Watchlist
ConnectWise ScreenConnect
Issue: CVE-2026-84869, CWE-862/CWE-269; unauthorized file transfer and execution through an active session.
Affected scope: ScreenConnect versions before 26.6.5; Remote Access Support and Access sessions; cloud and on-premises deployments. Server software itself is not the vulnerable execution target described by the vendor.
Fixed release: 26.6.5 or later; refresh host clients and access agents.
Severity: CVSS 3.1: 9.9 Critical; ConnectWise Priority 1–High.
Status: RED — CISA KEV; exploitation confirmed.
VMware vCenter Server
Issue: CVE-2026-59310; unauthenticated arbitrary code execution through directory traversal in the Syslog server.
Affected scope: vCenter 9.1.x, 9.0.x, 8.0, 7.0, and vCenter-containing Cloud Foundation, vSphere Foundation, and listed Telco products per VMSA-2026-0006.2.
Fixed release: vCenter 9.1.0.0300, 9.0.2.0100, 8.0 U3k, or 8.0 U2f; extended-support/vendor paths apply to 7.0 and product bundles.
Severity: CVSS 3.1: 9.8 Critical.
Status: RED — actively exploited; CISA flags ransomware-campaign use; no workaround.
Acronis Backup integrations
Issue: CVE-2026-87886; insecure file permissions leading to local privilege escalation on Linux.
Affected scope: cPanel & WHM plugin builds before 1.9.3.1021; Plesk extension builds before 1.8.11.638.
Fixed release: cPanel & WHM 1.9.3 HF3/build 1.9.3.1021; Plesk 1.8.11/build 638.
Severity: CVSS: 7.8 High.
Status: RED — Acronis reports limited targeted cPanel/WHM exploitation; local foothold required.
GitLab Community and Enterprise Editions
Issue: CVE-2026-85706; unauthenticated path traversal/arbitrary file read through the repository commits API.
Affected scope: all 18.7 releases before 19.1.8; 19.2 before 19.2.6; 19.3 before 19.3.2.
Fixed release: 19.1.8, 19.2.6, or 19.3.2 and later in the respective branches. GitLab.com and GitLab Dedicated were patched by GitLab.
Severity: CVSS 3.1: 10.0 Critical.
Status: RED carry-forward with a defensive update — exploited/KEV; GitLab’s patch page now includes three threat-detection queries for LFI/file-path attempts.
WSO2 API platform
Issue: CVE-2026-5430 / WSO2-2026-5328; unsupported JWT algorithm permits authentication bypass and account takeover.
Affected scope: API Control Plane 4.5.0/4.6.0; API Manager 4.1.0–4.6.0 in the vendor-listed release set; Traffic Manager 4.5.0/4.6.0; Universal Gateway 4.5.0/4.6.0.
Fixed release: apply the exact subscription update level listed in the ledger or WSO2’s two public fixes; otherwise migrate to the latest unaffected release.
Severity: CVSS 3.1: 10.0 multi-tenant; 9.8 single-tenant.
Status: AMBER — honeypot exploit attempts observed; no confirmed production compromise disclosed.
Oracle September 2026 CSPU
Issue: 673 new patches across numerous product families, including unauthenticated network flaws.
Affected scope: product- and version-specific; use Oracle’s September advisory and Patch Availability Documents.
Fixed release: no universal release; apply the applicable CSPU patches and vendor instructions.
Severity: varies by CVE and product; includes critical-severity issues.
Status: WATCH — broad preventive patch event; no Oracle claim of active exploitation for newly fixed September flaws.
Google Pixel
Issue: CVE-2026-58704; elevation of privilege in the Pixel modem.
Affected scope: supported Pixel devices covered by the September Pixel bulletin; model-level detail is not public in the entry.
Fixed release: security patch level 2026-09-05 or later.
Severity: High.
Status: WATCH — Google indicates limited, targeted exploitation.
Outlook and Uncertainty
Next 24 hours
ScreenConnect incident detail. Watch for ConnectWise, CISA, or incident-response reporting that identifies the session-access route, payloads, victims, or ransomware use. Any change to the affected-version boundary or client-refresh requirements warrants immediate correction.
vCenter ransomware disclosure. Expect vendor or responder detail to clarify which ransomware operators use CVE-2026-59310 and whether exploitation precedes encryption, credential theft, snapshot deletion, or ESXi access. Treat current CISA metadata as urgent but incomplete.
Acronis validation. A second independently verified victim, vendor indicators, or evidence of backup/configuration access would materially strengthen the campaign assessment. Until then, retain the single potentially affected-customer qualifier.
WSO2 escalation. A confirmed production compromise, CISA KEV addition, or published indicators would move this from observed attempts to confirmed exploitation impact. Monitor for exploit reuse after wider publication.
CenterPoint scope. Company notifications or an amended filing may establish customer count and data fields. Do not adopt attacker or plaintiff estimates as fact without victim confirmation.
Oracle deployment risk. Internet scanning or exploit publication may rapidly reprioritize individual September CSPU CVEs. Patch sequencing should remain exposure- and consequence-led.
What is not known
The actors, victims, and payloads exploiting ScreenConnect CVE-2026-84869.
The ransomware groups, victim count, and operational effects tied to vCenter CVE-2026-59310.
The initial foothold, attacker, payload, and outcome in Acronis’s reported cPanel/WHM exploitation.
Whether observed WSO2 forged-token attempts produced a successful production compromise.
CenterPoint’s affected-customer count, data fields, entry vector, and any credential or token loss.
Whether any newly patched Oracle September CSPU flaw is already exploited.
The targets, delivery path, prerequisites, and chain role of Pixel CVE-2026-58704.
Trigger for escalation
Unauthorized ScreenConnect transfers, endpoint execution, technician/session anomalies, or new persistence after an active remote-support session.
Unexpected vCenter outbound SSH, reverse_ssh, new keys, binaries, or evidence of ESXi/VM administrative changes.
Privileged child processes or backup-configuration access originating from Acronis cPanel/WHM or Plesk components.
WSO2 tokens using unsupported algorithms, administrator claims from unfamiliar issuers, or unexplained application/key creation.
Evidence connecting CenterPoint’s public-facing breach to operational identity or OT networks.
Vendor-confirmed active exploitation of any newly patched Oracle CSPU CVE.
Mobile-device telemetry linking Pixel CVE-2026-58704 to broader spyware or credential-access activity.
Search tags: CVE-2026-84869; ScreenConnect 26.6.5; CVE-2026-59310; VMware vCenter ransomware; CVE-2026-87886; CVE-2026-5430; CenterPoint Energy breach; Oracle September 2026 CSPU
Sources
ConnectWise ScreenConnect / CVE-2026-84869
ConnectWise primary security bulletin:
https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin
CVE Program record:
https://www.cve.org/CVERecord?id=CVE-2026-84869
CISA item-specific alert:
Forwarding-safe report reproducing the CISA exploitation status:
NHS England Digital alert and threat-update chronology:
https://digital.nhs.uk/cyber-alerts/2026/cc-4848
VMware vCenter / CVE-2026-59310
Broadcom primary advisory VMSA-2026-0006.2:
CVE Program record:
https://www.cve.org/CVERecord?id=CVE-2026-59310
QUIRSO primary campaign telemetry:
Forwarding-safe report of CISA’s ransomware-use flag:
Acronis Backup integrations / CVE-2026-87886
Acronis primary advisory UPD-2609-3d72-20a7:
https://security-advisory.acronis.com/updates/UPD-2609-3d72-20a7
CVE Program record:
https://www.cve.org/CVERecord?id=CVE-2026-87886
BleepingComputer report with Acronis’s single-report qualification:
SecurityWeek corroboration:
https://www.securityweek.com/acronis-patches-exploited-vulnerability-in-cpanel-backup-plugin/
WSO2 API platform / CVE-2026-5430
WSO2 primary advisory WSO2-2026-5328:
CVE Program record:
https://www.cve.org/CVERecord?id=CVE-2026-5430
WSO2 public fix for carbon-apimgt:
https://github.com/wso2/carbon-apimgt/pull/13752
WSO2 public fix for product-apim:
https://github.com/wso2/product-apim/pull/14167
The Hacker News report of watchTowr exploitation-attempt telemetry:
https://thehackernews.com/2026/09/active-exploitation-attempts-target.html
SecurityWeek corroboration:
https://www.securityweek.com/enterprises-warned-of-attacks-exploiting-wso2-vulnerability/
CenterPoint Energy customer-data breach
CenterPoint Energy Form 8-K on SEC EDGAR:
https://www.sec.gov/Archives/edgar/data/1130310/000110465926107560/tm2625326d1_8k.htm
CenterPoint Energy investor-relations SEC filing index:
https://investors.centerpointenergy.com/financial-information/sec-filings
SecurityWeek report separating company-confirmed impact from attacker claims:
Reuters corroboration:
Oracle September 2026 Critical Security Patch Update
Oracle primary CSPU advisory:
https://www.oracle.com/security-alerts/cspusep2026.html
Oracle Security blog:
https://blogs.oracle.com/security/september-2026-critical-security-patch-update
SecurityWeek summary:
https://www.securityweek.com/oracle-patches-800-vulnerabilities-in-september-2026-security-update/
Google Pixel / CVE-2026-58704
Google primary Pixel Update Bulletin—September 2026:
https://source.android.com/docs/security/bulletin/pixel/2026/2026-09-01
CVE Program record:
https://www.cve.org/CVERecord?id=CVE-2026-58704
BleepingComputer corroboration:
GitLab defensive detection update / CVE-2026-85706
GitLab primary patch release and threat detections:
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/
CVE Program record:
https://www.cve.org/CVERecord?id=CVE-2026-85706
CISA item-specific alert:
Forwarding-safe Rapid7 report of the KEV status:
Jonathan Brown writes independent, decision-focused analysis on cybersecurity, infrastructure resilience, and operational risk, with an emphasis on primary-source verification and explicit uncertainty.
Support this work by sharing the briefing with operators who can act on it. Corrections supported by primary evidence are welcomed; material errors should be amended transparently. Feel free to subscribe, comment, or buy us a coffee! Thanks.
© 2026 Border Cyber Group. All rights reserved.
Member discussion: