September 24, 2026
Command View
Verification cutoff
September 24, 2026, 13:05:56 UTC. This edition prioritizes observed attempts to turn a newly patched WordPress Core flaw into code execution, continued exploitation of JetBrains TeamCity with new ransomware-use reporting, and a newly published FBI/CISA account of a compromised industrial-control integrator. SolarWinds has also published fixes for two conditional remote-code-execution flaws in its self-hosted monitoring platform. A NIST operational-technology draft changes planning assumptions, not the current incident posture.
Priority posture
- RED: Patchstack observed WordPress CVE-2026-87902 traffic progress from reconnaissance to attempts to write PHP files containing command-execution code. JetBrains has confirmed exploitation of TeamCity CVE-2026-63077; September 24 reporting says CISA has newly marked the existing KEV entry for ransomware use, although the accessible vendor material does not identify ransomware actors or victims. Exposed deployments require remediation and compromise assessment.
- AMBER: SolarWinds Observability Self-Hosted CVE-2026-28324 and CVE-2026-28325 permit unauthenticated code execution under distinct configuration and access conditions; exploitation has not been established. FBI/CISA disclosed a 2025 intrusion into a U.S. industrial-control integrator in which actors staged roughly 800 customer-related files for presumed exfiltration; downstream customer compromise was not established.
- WATCH: NIST's September 21 initial public draft of SP 800-82 Revision 4 expands operational-technology guidance and is open for comment through November 30.
- CONTEXT: The CISA federal remediation date for exploited Zyxel GS1900 CVE-2026-7273 is today, September 24. This is a deadline for an already covered flaw, not a newly disclosed campaign. Yesterday's Check Point, Arista VeloCloud, and F5 response work remains urgent where exposure is unresolved.
Today's decisions
- RED — Web-platform owner and incident response: Update WordPress Core to 7.1.2 or the fixed release for the installed branch; check active-theme and PHP prerequisites, review
pagenamerequests and unexpected PHP files, and preserve evidence where a file-write stage appears. - RED — Build-platform owner: Verify every TeamCity On-Premises server is fixed at 2025.11.7, 2026.1.3, or a later fixed release, or has the vendor's applicable security patch plugin. Restrict HTTP(S) access and assess build agents, credentials, and produced artifacts if exposure predates the fix.
- AMBER — Monitoring-platform owner: Inventory Observability Self-Hosted servers at or below 2026.2.2; check each of the two vendor-described configuration conditions and upgrade affected systems to 2026.2.3.
- AMBER — OT owner and supplier-risk lead: Map integrator remote access, stored engineering files, and the ability to operate without the supplier. Require monitored, time-limited access and preserve independent recovery copies.
- RED — Network operations: Close any remaining Zyxel GS1900 federal-deadline exposure today and complete credential and configuration integrity checks on devices that may have been exploited.
Threat and Resilience Ledger
[RED] — Internet-facing web administration | Global product exposure — WordPress file-inclusion attacks advance to attempted code execution
WordPress published version 7.1.2 and advisory GHSA-7hp8-65ch-5whp on September 22 for CVE-2026-87902, an unauthenticated path traversal in get_page_template() that can include a readable local PHP file outside the theme directory. Code execution requires an active parent or child theme with a top-level directory beginning page-, plus a suitable local PHP file readable by the web server; the documented PEAR route also requires register_argc_argv to be enabled. Patchstack reports that requests it observed progressed from checking readable core files to attempts to include pearcmd.php and write attacker-controlled PHP, including command-execution payloads. This is observed exploitation activity, not proof that every request succeeded or a verified count of compromised sites. WordPress lists affected branches from 4.7 through 7.1.1 and fixes in 7.1.2 and corresponding backports through 4.7.37; releases 4.6 and earlier receive no fix. Update the matching branch, search access logs and temporary directories for the vendor/researcher-described sequence, and treat a verified unauthorized PHP write as host compromise. The WordPress advisory rates the issue CVSS v4.0 9.2; Singapore's CSA separately cites CVSS v3.1 8.1. These scores use different scoring versions.
Evidence: confirmed vendor flaw and fixes; direct Patchstack observation of reconnaissance and attempted file-write/code-execution stages.
Attribution: unknown.
Confidence: high for prerequisites, fixes, and observed traffic; moderate for success and overall victim scope.
Uncertainty: how many sites allowed successful file inclusion or attacker file writes, and whether payloads established persistence.
Sources: WordPress Security Team — “Unauthenticated path traversal in page-template resolution leading to conditional RCE,” September 22; WordPress.org — “Version 7.1.2,” September 22; Patchstack — “CVE-2026-87902: Attackers Started Probing WordPress Sites Hours After the Patch,” September 22, updated September 23; Cyber Security Agency of Singapore — “Active Exploitation of High-Severity Vulnerability in WordPress,” September 24.
[RED] — Build and release integrity | Global product exposure — TeamCity exploitation draws new ransomware-use reporting
JetBrains' earlier advisory confirms that CVE-2026-63077 permits an unauthenticated attacker with HTTP(S) access to a vulnerable TeamCity On-Premises server to abuse the agent-polling protocol and execute operating-system commands as the TeamCity server process. JetBrains subsequently reported active and attempted exploitation; the fix is in 2025.11.7 and 2026.1.3, with a dedicated patch plugin for TeamCity 2017.1 and later when an upgrade is not immediately possible. TeamCity Cloud has already been mitigated by the vendor. On September 24, BleepingComputer reported that CISA had changed this existing Known Exploited Vulnerabilities entry to mark known ransomware-campaign use. The accessible primary JetBrains guidance verifies exploitation but does not itself identify a ransomware operator, victim, or specific post-exploitation outcome; the changed CISA field could not be independently fetched at cutoff and is presented as reporting. Review TeamCity server logs and unauthorized agents using JetBrains' guidance, then validate stored credentials, build definitions, signing material, and artifacts if compromise is suspected. A patched build server cannot automatically vouch for artifacts created during its vulnerable period.
Evidence: confirmed vendor vulnerability and exploitation; ransomware-use designation reported by BleepingComputer, not independently retrieved from CISA's current record at cutoff.
Attribution: unknown; no specific ransomware group established here.
Confidence: high for exposure, fixes, and active exploitation; moderate for the newly reported ransomware designation.
Uncertainty: which intrusions reached secrets, source, build agents, signing keys, or downstream releases.
Sources: JetBrains — “Critical Security Issue Affecting TeamCity On-Premises (CVE-2026-63077) – Update to 2025.11.7 or 2026.1.3 Now,” July 27; JetBrains — “CVE-2026-63077: Additional Guidance Following Reports of Active Exploitation,” August; BleepingComputer — “CISA: Ransomware gangs now exploiting critical TeamCity flaw,” September 24.
[AMBER] — OT supplier and integrator trust | United States — FBI/CISA describe intrusion into industrial-control engineering supplier
A September 23 FBI/CISA fact sheet reports FBI technical analysis of an intrusion into a U.S. industrial automation solutions company between March and April 2025. The supplier provided system integration, engineering consulting, and supervisory control and data acquisition programming to customers including power utilities and transportation entities. The agencies say malicious foreign cyber actors searched for customer and SCADA information and created nine ZIP archives containing approximately 800 files for presumed exfiltration, including customer control-system information, device details, and schematics. The document does not establish that all staged data left the network, identify the actor or victims, or document a later attack against a customer's operational system. The newly public case demonstrates why an integrator's engineering data and remote access form a bridge into plants and transport operations. Inventory each supplier's retained diagrams, credentials, devices, and access; make remote sessions monitored and on demand; and test independent operation and offline recovery if the supplier becomes unavailable or compromised.
Evidence: confirmed government report of a historical supplier-network intrusion and staging for presumed exfiltration; downstream attacks not reported.
Attribution: FBI/CISA describe malicious foreign cyber actors without a public identity.
Confidence: high for the agencies' disclosed observations; low for any inferred customer compromise.
Uncertainty: whether the archives were exfiltrated, which customers' data was included, and whether access persisted into customer OT.
Sources: FBI and CISA — “Considerations for Critical Infrastructure Operators Working With Third-Party ICS Integrators,” September 23.
[AMBER] — Monitoring and administration | Global product exposure — SolarWinds self-hosted observability fixes two conditional RCE flaws
SolarWinds advisories first published September 22 identify two different unauthenticated remote-code-execution vulnerabilities in SolarWinds Observability Self-Hosted 2026.2.2 and below, both fixed in 2026.2.3. CVE-2026-28324, rated CVSS 9.8, arises from insufficient integrity checks when the deployment uses a non-default, insecure configuration. CVE-2026-28325, rated CVSS 8.8, involves deserialization when a particular communication mode is configured; its published CVSS vector specifies an adjacent-network attack path. Treat these prerequisites separately rather than assuming all installations are internet-exploitable. The reviewed vendor advisories do not report exploitation. Because a monitoring server can hold topology, privileged integrations, and administrative reach, identify applicable configurations, constrain access, and install 2026.2.3. If suspicious activity is found, validate collection settings, integrations, credentials, and changes made through the platform.
Evidence: confirmed vendor advisories and fixed release; no exploitation established in the reviewed sources.
Attribution: not applicable.
Confidence: high for the two CVEs, prerequisites stated by SolarWinds, scores, and fixed release.
Uncertainty: the exact communication-mode setting for CVE-2026-28325 is not detailed in the public advisory; local deployment exposure must be established.
Sources: SolarWinds — “SolarWinds Observability Self-Hosted Remote Code Execution Vulnerability (CVE-2026-28324),” September 22; SolarWinds — “SolarWinds Observability Self-Hosted Unauthenticated Remote Code Execution Vulnerability (CVE-2026-28325),” September 22.
[WATCH] — OT security planning | United States and global users of NIST guidance — new OT security guide remains a draft
NIST published the initial public draft of SP 800-82 Revision 4, Guide to Operational Technology (OT) Security, on September 21, with comments due November 30. The draft expands coverage of building automation, water and wastewater, food and agriculture, freight rail, maritime vessels, and industrial internet-of-things/cloud convergence. It reorganizes guidance around Cybersecurity Framework 2.0 and gives more attention to asset management, monitoring, protected management functions, and zero-trust concepts adapted to operational systems. This publication does not disclose an incident or impose a new final standard today. OT architecture and procurement teams can compare existing supplier-access, recovery, and monitoring plans against the draft and comment on changes with safety or continuity implications.
Evidence: confirmed NIST initial public draft and comment period.
Attribution: not applicable.
Confidence: high.
Uncertainty: revisions before final publication and the timing of any organizational adoption.
Sources: NIST — “SP 800-82 Rev. 4, Guide to Operational Technology (OT) Security,” initial public draft, September 21.
Defensive Posture Changes
Separate a web patch from a web-host recovery decision
For WordPress, establish the active theme and PHP conditions, then correlate requests that include pagename and page_id with local-file inclusion or unexpected PHP writes. A request matching a published pattern may be a blocked probe; a confirmed attacker file on disk changes the response to host-level investigation. Preserve web logs and relevant files before cleanup, then assess application credentials and the site's access to other systems.
Revalidate the build trust chain
TeamCity holds more than the server's own state. If exposed during active exploitation, identify which build definitions ran, which agents connected, which secrets were available, and which artifacts were produced or signed. Compare releases against trusted source and reproducible build evidence where available. Rotate potentially exposed credentials and rebuild or resign artifacts only where investigation establishes a credible exposure path.
Make integrator access and recovery visible to the operator
The integrator case warrants an owner-held inventory of network diagrams, engineering files, service accounts, remote entry points, and supplier-managed equipment. Use recorded, on-demand access and test a recovery procedure that does not require a compromised supplier to restore critical processes. The nine staged archives in the FBI/CISA case are a warning about design-data exposure, not proof that the named customer sectors suffered physical disruption.
Check monitoring-platform configuration before ranking exposure
Test SolarWinds deployments against each advisory's configuration condition and access path. Version inventory alone cannot determine reachability, particularly for the adjacent-network deserialization issue. After upgrading, validate administrative integrations and monitoring continuity so that incident responders can still rely on the platform's logs and alerts.
Regional and Sector Pulse
- North America — AMBER: The FBI/CISA account concerns a U.S. industrial-control integrator serving, among others, power and transportation customers. It documents a supplier intrusion and staged files, not a confirmed outage or compromise of those customers. U.S. federal civilian operators also reach the September 24 Zyxel remediation date.
- Europe — WATCH: The new WordPress, TeamCity, and SolarWinds exposures are global products. No Europe-specific victim concentration was established by today's reviewed primary sources; operators should act on their own installations and supplier access.
- Africa — WATCH: No Africa-specific activity or victim count was verified for today's issues. The WordPress and TeamCity attack paths apply wherever the affected configuration and network access exist.
- Middle East — WATCH: No distinct regional campaign was established; the integrator fact sheet and software advisories support an exposure-based review rather than a geographic inference.
- Asia — WATCH: Singapore's Cyber Security Agency issued a September 24 WordPress alert. That is regional defensive guidance, not evidence of a Singapore-specific victim cluster.
- Russia — WATCH: No Russia-specific actor or victim claim was verified in these developments. The TeamCity ransomware-use reporting does not identify an actor.
- China — WATCH: The FBI/CISA document does not name a country for the foreign actors in the integrator intrusion. Do not assign an origin from that description.
- Indo-Pacific — WATCH: New Zealand's NCSC also published a WordPress alert on September 24. This region, including India, faces product exposure where vulnerable sites are present; an Indo-Pacific exploitation concentration was not established.
- Sector continuity — RED: The September 22 Check Point management and gateway, Arista VeloCloud, and F5 advisories remain active response work where their exposure conditions are present. No new verified indicator in this edition changes their previously stated fix guidance.
Vulnerability and Supplier Watchlist
WordPress Core
Issue: CVE-2026-87902; unauthenticated page-template path traversal and local PHP inclusion, with conditional remote code execution.
Affected scope: vendor-listed branches 4.7 through 7.1.1; active theme needs a top-level page- directory, and code execution needs a suitable readable local PHP file and, for the documented PEAR route, register_argc_argv enabled.
Fixed release: 7.1.2; backports include 7.0.6, 6.9.9, 6.8.10, and branch-specific releases through 4.7.37. Versions 4.6 and earlier receive no fix.
Severity: WordPress/GitHub advisory CVSS v4.0 9.2, critical; Singapore CSA separately gives CVSS v3.1 8.1.
Status: RED — Patchstack observed attempts to progress to attacker-controlled PHP file writes.
JetBrains TeamCity On-Premises
Issue: CVE-2026-63077; unauthenticated command execution through the agent-polling protocol when the HTTP(S) server is reachable.
Affected scope: all TeamCity On-Premises versions before a relevant fixed release or the dedicated patch plugin; TeamCity Cloud already mitigated by JetBrains.
Fixed release: 2025.11.7 or 2026.1.3, or later fixed builds; dedicated security patch plugin for 2017.1 and later if immediate upgrade is unavailable.
Severity: JetBrains critical; no numeric score needed for prioritization.
Status: RED — exploitation confirmed by vendor; ransomware-use marker newly reported, with its precise scope still unverified here.
SolarWinds Observability Self-Hosted
Issue: CVE-2026-28324, insufficient integrity checks; CVE-2026-28325, deserialization of untrusted data; both can permit unauthenticated code execution under their respective conditions.
Affected scope: 2026.2.2 and below; non-default insecure configuration for CVE-2026-28324; specific communication mode and adjacent-network access for CVE-2026-28325.
Fixed release: 2026.2.3.
Severity: SolarWinds CVSS 9.8 and 8.8, respectively.
Status: AMBER — consequential monitoring-plane exposure; exploitation not established in reviewed advisories.
Zyxel GS1900 switches — deadline carry-forward
Issue: CVE-2026-7273; unauthenticated local/adjacent-network command execution; prior-edition exploitation and data theft evidence.
Affected scope: affected GS1900 models and model-specific firmware listed in Zyxel's June 16 advisory; verify management reachability and default or reused credentials.
Fixed release: model-specific firmware in the Zyxel advisory; do not substitute a version from a different model.
Severity: CVSS 8.8.
Status: RED — existing KEV entry reaches its September 24 federal remediation date; previously exposed devices require integrity and credential checks.
Outlook and Uncertainty
Next 24 hours
Watch for confirmed WordPress file-write successes and updated Patchstack or vendor indicators; a directly accessible confirmation of TeamCity's reported CISA ransomware marker and any vendor-specific ransomware investigation guidance; SolarWinds clarification of the deserialization communication mode; and evidence that the disclosed integrator intrusion led to exfiltration or customer access. Review late updates to the Check Point, VeloCloud, and F5 advisories before closing existing incident work.
What is not known
Patchstack's observed malicious traffic does not yield a reliable WordPress victim count. The TeamCity ransomware-use report does not name an actor or show which builds were affected. The FBI/CISA fact sheet describes presumed exfiltration from an integrator, not proven compromise of utility or transportation control systems. Public SolarWinds advisories do not provide a full prevalence estimate for the vulnerable configurations. No public indicator list is complete.
Trigger for escalation
Escalate a WordPress site to full host response if attacker-written PHP or executed commands are verified. Escalate TeamCity to software-supply-chain response if unauthorized builds, agents, signing activity, or secret access appear. Escalate an integrator/customer OT case if staged engineering data is confirmed exfiltrated, supplier credentials work in customer environments, or unauthorized process-control changes are found. Promote SolarWinds exposure to RED if credible exploitation or unauthorized administrative changes are documented.
© 2026 Border Cyber Group. All rights reserved.
Source Register
WordPress Core CVE-2026-87902 and observed exploitation
WordPress Security Team — “Unauthenticated path traversal in page-template resolution leading to conditional RCE,” GHSA-7hp8-65ch-5whp — September 22, 2026:
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-7hp8-65ch-5whp
WordPress.org — “Version 7.1.2” — September 22, 2026:
https://wordpress.org/documentation/wordpress-version/version-7-1-2/
Patchstack — “CVE-2026-87902: Attackers Started Probing WordPress Sites Hours After the Patch” — September 22, updated September 23, 2026:
https://patchstack.com/articles/cve-2026-87902-attackers-started-probing-wordpress-sites-hours-after-the-patch/
Cyber Security Agency of Singapore — “Active Exploitation of High-Severity Vulnerability in WordPress” — September 24, 2026:
https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-128/
New Zealand National Cyber Security Centre — “CVE-2026-87902 Affecting WordPress” — September 24, 2026:
https://www.ncsc.govt.nz/alerts/cve-2026-87902-affecting-wordpress/
TeamCity exploitation and ransomware-use reporting
JetBrains — “Critical Security Issue Affecting TeamCity On-Premises (CVE-2026-63077) – Update to 2025.11.7 or 2026.1.3 Now” — July 27, 2026:
https://blog.jetbrains.com/teamcity/2026/07/cve-2026-63077/
JetBrains — “CVE-2026-63077: Additional Guidance Following Reports of Active Exploitation” — August 2026:
https://blog.jetbrains.com/teamcity/2026/08/cve-2026-63077-update/
BleepingComputer — “CISA: Ransomware gangs now exploiting critical TeamCity flaw” — September 24, 2026:
https://www.bleepingcomputer.com/news/security/cisa-ransomware-gangs-now-exploiting-critical-teamcity-flaw/
Industrial-control integrator intrusion and guidance
FBI and CISA — “Considerations for Critical Infrastructure Operators Working With Third-Party ICS Integrators” — September 23, 2026:
https://www.ic3.gov/CSA/2026/260923.pdf
CISA — “Considerations for Critical Infrastructure Operators Working With Third-Party ICS Integrators” — September 23, 2026:
https://www.cisa.gov/resources-tools/resources/considerations-critical-infrastructure-operators-working-third-party-ics-integrators
SolarWinds Observability Self-Hosted
SolarWinds — “SolarWinds Observability Self-Hosted Remote Code Execution Vulnerability (CVE-2026-28324)” — September 22, 2026:
https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28324
SolarWinds — “SolarWinds Observability Self-Hosted Unauthenticated Remote Code Execution Vulnerability (CVE-2026-28325)” — September 22, 2026:
https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28325
OT security-guide draft
NIST — “SP 800-82 Rev. 4, Guide to Operational Technology (OT) Security,” initial public draft — September 21, 2026:
https://csrc.nist.gov/pubs/sp/800/82/r4/ipd
Zyxel September 24 remediation deadline
CISA — “CISA Adds One Known Exploited Vulnerability to Catalog” — September 21, 2026:
https://www.cisa.gov/news-events/alerts/2026/09/21/cisa-adds-one-known-exploited-vulnerability-catalog
Zyxel — “Zyxel security advisory for stack-based buffer overflow vulnerability in GS1900 series switches” — June 16, 2026:
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-stack-based-buffer-overflow-vulnerability-in-gs1900-series-switches-06-16-2026
GreyNoise — “Open Season on Kapibala: Attacker Steals Over 18,000 Government Records Through WordPress Exploitation” — September 21, 2026:
https://www.greynoise.io/blog/open-season-on-kapibala-attacker-steals-government-records-wordpress-exploitation
This briefing is intended for defensive awareness and operational decision-making, not as a substitute for incident response, vendor guidance, or legal advice.
Jonathan Brown writes independent, decision-focused analysis on cybersecurity, infrastructure resilience, and operational risk, with an emphasis on primary-source verification and explicit uncertainty.
Support this work by sharing the briefing with operators who can act on it. Corrections supported by primary evidence are welcomed; material errors should be amended transparently. Feel free to subscribe, comment, or buy us a coffee! Thanks.
© 2026 Border Cyber Group. All rights reserved.
Member discussion: