Threat Brief — 2026-09-23 — Router SSH Chain, GitLab Email-as-Credential
Executive summary: A chained pair of MikroTik RouterOS SSH vulnerabilities — one now in CISA's Known Exploited Vulnerabilities catalog — lets attackers take full control of internet-exposed routers with no password or key. Separately, a design weakness in GitLab means the private email address used for issue-by-email submissions is effectively a credential: anyone who obtains it can push code and trigger CI/CD jobs under your identity. CISA also added four actively exploited CVEs to its KEV catalog today, spanning Check Point, F5 BIG-IP APM, and Arista VeloCloud products. A new InfraTrust report warns that network management systems are increasingly being targeted with vulnerabilities exploited before or shortly after vendor disclosure.
Top items
- MikroTik RouterOS "MikroTrick" SSH chain — CVE-2026-86060KEV, actively exploited. Two SSH vulnerabilities in RouterOS, chained together, allow unauthenticated administrative takeover of internet-exposed MikroTik routers. CERT Polska dubbed the chain "MikroTrick." CVE-2026-86060KEV is listed in CISA's Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. No password, SSH key, or completed authentication is required. (src: The Hacker News)
- GitLab issue-by-email address acts as a reusable code-push credential. GitLab assigns each project a private email address for filing issues by email. If that address leaks, anyone can email a patch that GitLab commits in the victim's name to any branch they can push to — including
main— and can trigger CI/CD jobs that execute attacker-controlled code. The address is not treated as a secret by default. Treat issue-email addresses as credentials: rotate them, restrict branch permissions, and audit CI/CD pipeline access. (src: The Hacker News)
- CISA adds four actively exploited CVEs to KEV catalog. The additions are: CVE-2026-85102KEV (Check Point multiple products, improper certificate validation), CVE-2026-93616KEV (product not specified in source), CVE-2026-93952KEV (Arista VeloCloud Orchestrator — CVSS 10.0, first reported 2026-09-22), and CVE-2026-94127KEV (F5 BIG-IP APM remote code execution, first reported 2026-09-23). All four carry evidence of active exploitation. This is a developing KEV story first reported 2026-08-17 by CISA. (src: CISA)
- InfraTrust report: network management systems under active attack. Attackers are increasingly targeting the management platforms used to control enterprise infrastructure. Several critical vulnerabilities in NMS products were exploited before or shortly after vendors disclosed them, indicating threat actors are moving quickly on network-management attack surface. (src: BleepingComputer)
- AI coding tools silently upload developer projects to cloud. An AI programming assistant uploaded users' local project repositories to a cloud service without explicit consent. A large archive exceeded upload limits, but a small test repository was accepted by the server — confirming the upload path works. This highlights data-exfiltration risk in AI-assisted development workflows where source code may leave the local environment through tooling behaviour alone. (src: SecurityLab.ru)
Themes
AI-as-attack-surface continues to expand. Beyond the CLOSEDQUORUM malware (which lets up to four AI models vote on attack actions, first reported 2026-09-22) and the malicious AI-agent skimming operation (600K cards stolen, first reported 2026-09-23), today adds a third AI-adjacent risk: AI coding tools exfiltrating source code to cloud endpoints. The common thread is that AI tooling is creating new, under-appreciated pathways for data loss and autonomous malicious action.
Edge device exploitation remains the dominant attack vector. MikroTik routers join D-Link DIR-822A, Arista VeloCloud, F5 BIG-IP, and Check Point as network-edge products with actively exploited or unpatched critical flaws. Internet-exposed management interfaces on routers, firewalls, and orchestrators continue to be the highest-priority patching surface.
