Threat Brief — 2026-09-29 — ICS advisories flood, Apple KEV addition
Executive summary. CISA released a batch of seven ICS advisories today spanning IP cameras, cellular gateways, dashcam apps, and industrial control systems—several enabling root-level remote code execution. Apple's CoreGraphics out-of-bounds write flaw (CVE-2026-86950KEV), disclosed yesterday as a targeted iOS zero-day, has now been added to the CISA Known Exploited Vulnerabilities catalog, confirming active in-the-wild exploitation. New IP-range-level blocking is disrupting OpenVPN and corporate tunnel services, representing a shift from port-based to range-based interference.
Top items
- Apple CVE-2026-86950KEV added to CISA KEV — confirmed exploited in the wild. An out-of-bounds write vulnerability in CoreGraphics affecting iOS, macOS, and iPadOS can lead to arbitrary code execution. This was first reported yesterday as a patched zero-day used in sophisticated targeted attacks; its addition to the KEV catalog today (remediation due 2026-10-02) is the new development. CISA requires affected organisations to apply vendor patches by the due date. (src: CISA KEV) — continues story first reported 2026-09-28 by The Hacker News
- CISA ICS advisory: VIVOTEK camera firmware — remote command execution with root privileges. Successful exploitation allows attackers to achieve RCE on affected camera devices, potentially with root privileges, leading to full compromise of the camera system. (src: CISA ICS Advisory)
- CISA ICS advisory: Lantronix G520 Series Cellular Gateway — root-level arbitrary code execution. Attackers can replace software and execute arbitrary code with root privileges on affected gateway versions. (src: CISA ICS Advisory)
- CISA ICS advisory: MikroTik RouterOS — remote code execution or denial of service. RouterOS versions prior to 7.24 are affected. This is a new CISA ICS advisory for an issue first reported on 2026-09-04 in the context of Russian regulatory pressure; the formal CISA advisory with exploitability confirmation is the new development. (src: CISA ICS Advisory) — continues story first reported 2026-09-04 by SecurityLab
- CISA ICS advisory: Anjvision YSSD-RTMP-H5 — full device takeover. Vulnerabilities allow access to sensitive information, account compromise, OS-level command execution, or full device control. (src: CISA ICS Advisory)
- CISA ICS advisory: Viidure Dashcam Android app — sensitive data and system file compromise. Attackers can access, modify, or delete sensitive user data and critical system files, potentially compromising the entire platform. (src: CISA ICS Advisory)
- CISA ICS advisory: Toptech TMS7 and TopHAT — critical data access or arbitrary code execution. Affected version TMS7 7.6.3 and related TopHAT deployments are vulnerable. (src: CISA ICS Advisory)
- CISA ICS advisory: Baicells Nova 430H — denial of service via malformed message injection. Attackers can inject malformed messages leading to DoS conditions on affected cellular infrastructure. (src: CISA ICS Advisory)
- IP-range-level blocking disrupts OpenVPN and corporate tunnels. New restrictions are knocking out VPN services by entire IP ranges rather than individual endpoints, making server-hopping mitigation ineffective. This represents a shift in interference methodology that affects both consumer and enterprise VPN users. (src: SecurityLab)
- DDoS attacks available for ~$30 on shadow markets. Kaspersky investigated current pricing and found higher-tier purchases enable simultaneous multi-attack campaigns, lowering the barrier to sustained DDoS operations. (src: SecurityLab)
Themes
ICS/OT exposure dominates today's advisory flow. Seven simultaneous CISA ICS advisories span network infrastructure (MikroTik, Lantronix, Baicells), surveillance (VIVOTEK, Anjvision), consumer IoT (Viidure), and industrial control (Toptech). Several grant root-level access, reinforcing that exposed embedded and edge devices remain a primary attack surface. The VIVOTEK and Lantronix advisories are particularly notable for enabling full remote compromise without authentication prerequisites.
Active exploitation continues to drive KEV additions. Apple's CoreGraphics flaw moved from disclosure to KEV listing in under 24 hours, underscoring how quickly targeted zero-days transition to broader exploitation pressure.
