Threat Brief — 2026-09-10 — KEV additions and multi-actor exploitation
Active exploitation intensified across several fronts. Google Chrome's seventh zero-day of the year (CVE-2026-87491KEV) landed in CISA's Known Exploited Vulnerabilities catalogue, and Cisco confirmed its Secure FMC flaws are now being leveraged by three distinct threat clusters including ransomware operators and state-sponsored actors. On the medical-ICS front, CISA published advisories for AVEVA Pipeline Integrity Monitor, NextGen Healthcare Mirth Connect, and Orthanc DICOM Server — all capable of enabling data exfiltration or code execution under the right conditions. The Nightmare-Eclipse researcher's vendetta against Microsoft continued with a ShieldCrash patch bypass.
Top items
- Chrome V8 zero-day CVE-2026-87491KEV added to CISA KEV. Google patched 230 vulnerabilities including this actively exploited V8 engine flaw allowing remote code execution. Its addition to CISA's Known Exploited Vulnerabilities catalogue means federal agencies face a binding remediation deadline and confirms in-the-wild exploitation. This is Chrome's seventh zero-day patched this year. First reported 2026-09-09 by BleepingComputer. (src: xakep)
- Cisco Secure FMC vulnerabilities now exploited by three separate threat clusters. Cisco Talos reports that two recently patched Secure Firewall Management Center flaws are being leveraged by ransomware operators and state-sponsored hackers, expanding well beyond the initial CISA KEV listing. The involvement of multiple distinct actor groups elevates urgency for any unpatched FMC deployments. First reported 2026-09-09 by BleepingComputer. (src: bleepingcomputer-main)
- Nightmare-Eclipse publishes ShieldCrash Windows Defender zero-day with patch bypass. The disgruntled researcher continued their campaign against Microsoft by releasing another zero-day exploit targeting Windows Defender, this time including a bypass for the patch — meaning existing fixes may not fully remediate the privilege escalation path. First reported 2026-09-09 by BleepingComputer. (src: darkreading-all)
- CISA advisory: AVEVA Pipeline Integrity Monitor vulnerabilities. Successful exploitation could allow an attacker to disclose information, brute-force hashes, or execute arbitrary code in a browser session. Affects specific versions of AVEVA Pipeline Integrity Monitor. (src: CISA)
- CISA medical advisory: NextGen Healthcare Mirth Connect. Vulnerabilities could allow an attacker to exfiltrate data or cause denial-of-service conditions. Mirth Connect is widely deployed in healthcare interoperability environments, making exposure potentially significant. (src: CISA)
- CISA medical advisory: Orthanc DICOM Server heap overflow. An authenticated remote attacker can trigger a heap overflow when Orthanc decodes a attacker-supplied PNG or JPEG image, resulting in a crash or potential code execution. Orthanc is a popular open-source DICOM server used in medical imaging. (src: CISA)
- Office documents remain dominant malware delivery vector. Analysis indicates one in four malicious files detected in corporate networks is a Word or Excel document, reinforcing that macro-enabled and embedded-object attacks remain a primary initial-access method despite defensive controls. (src: securitylab-ru)
- Identity-centric attacks dominate confirmed malicious activity. A quarterly investigation of every alert across customer environments found identity was the target in roughly half of all confirmed malicious activity, with four main attack patterns identified. This aligns with the broader trend of attackers pivoting from network perimeter to credential and session-token theft. (src: bleepingcomputer-main)
Themes
Exploitation maturation: Multiple stories today show actors moving from initial discovery to multi-group exploitation. Chrome's CVE-2026-87491KEV went from patch to KEV in under 24 hours, and Cisco FMC flaws are now used by three separate clusters — ransomware and state-sponsored simultaneously. The window between disclosure and broad exploitation continues to compress.
Healthcare and ICS exposure: Three CISA advisories targeting medical imaging and industrial pipeline systems highlight that specialised operational technology remains a persistent weak point, with attack surfaces spanning data exfiltration, denial-of-service, and memory corruption.
Identity as the perimeter: The quarterly alert analysis confirming identity as the target in ~50% of confirmed attacks corroborates the ongoing shift in adversary tradecraft — credentials and session tokens, not network exploits, are the primary commodity.
