September 2026 Threat Report: Unchecked Accumulation of Security Debt in Enterprise IT

Widespread, unchecked accumulation of security debt in enterprise IT is emerging at an accelerated pace. While the numbers are staggering, defenders need to realize that regular scanning, orderly prioritization, and timely patching are still the most fundamental way to prevent attackers from exploiting software flaws for impact. For prudent defenders applying well-orchestrated security programs, vulnerability management is still sustainable. On the other hand, some will need to improve their VM maturity to prevent an unmitigated exposure from turning catastrophic.
Here is a summary of high-risk issues for enterprise IT that emerged in September 2026.
Start Your Free Trial
Earlier in September, the Greenbone blog alerted to numerous emerging risks to IT systems. These include an actively exploited “MikroTrick” exploit chain targeting RouterOS [1], three actively exploited JFrog Artifactory vulnerabilities [2], an actively exploited flaw in GitLab [3], heightened risk for Cisco products from its September vulnerability disclosures [4], active exploitation of Roundcube Webmail CVE-2026-48842 [5], attacks targeting Zyxel GS1900 switches via CVE-2026-7273 [6], and active exploitation of the WSO2 API platform [7]. Greenbone’s OPENVAS SCAN allows IT defenders to tackle vulnerability management head-on, helping them detect and mitigate emerging threats before attackers can take advantage. A trial copy of OPENVAS SCAN includes a free two-week trial of the OPENVAS ENTERPRISE FEED, with over 250,000 vulnerability tests and counting.
CVE-2026-86218: Another Actively Exploited Unauthenticated RCE Flaw in N-able N-central
CVSS 9.8 · CriticalEPSS 12.9% (96th)Actively exploitedIn CISA KEVPublic PoC
CVE-2026-86218 (CVSS 9.8, EPSS ≥ 96th pctl) is a critical unauthenticated remote code execution (RCE) flaw in N-able N-central before version 2026.3.1.14. The root cause is improper neutralization of directives in statically saved code [CWE-96]. CVE-2026-86218 has been added to CISA’s KEV list. A detailed technical analysis [1], Metasploit module [2], and at least one additional proof-of-concept exploit [3] are available, further increasing the risk of ongoing attacks.
N-central vulnerabilities also appeared on CISA’s KEV list twice last month, and were alerted twice on the Greenbone blog in 2025 [4][5]. Risk is elevated because N-central is a remote administration platform used by internal IT teams and in Managed Service Provider (MSP) environments. Compromise of an N-central server creates a threat across managed customer environments.
The vendor has published fixes for CVE-2026-86218 via 2026.3 HF4 build 2026.3.1.14. Users should verify their installed patch level, since 2026.3 HF3 was issued only days before in response to CVE-2026-86206 and CVE-2026-86207. CVE-2026-86206 is considered to be exploited in the wild. Previdian reports exploitation of CVE-2026-86207 against its sensors, and a detailed technical analysis is available. The OPENVAS ENTERPRISE FEED includes a remote banner check for CVE-2026-86218, and a separate remote banner check and active check covering CVE-2026-86206 and CVE-2026-86207.
Living on the Edge: Emerging Risk to Perimeter Network Devices
According to the latest Verizon DBIR 2026 report, exploiting publicly exposed software vulnerabilities is now the most common vector for initial access globally. Greenbone’s OPENVAS SCAN excels at detecting perimeter vulnerabilities, via both network-based scans and host-based authenticated scans. Greenbone’s detection is industry-leading when paired with the OPENVAS ENTERPRISE FEED. Here are some of the most critical emerging threats to perimeter devices in September 2026.
Three Citrix NetScaler ADC and Gateway Flaws Actively Exploited
Three CVEs affecting Citrix NetScaler ADC and NetScaler Gateway were added to CISA’s KEV list in September [1][2][3]. CVE-2026-88771 (CVSS 9.8) and CVE-2026-88772 (CVSS 8.1) were published in late September; CVE-2026-19490 (CVSS 9.8) is from August 2026. Several detailed technical write-ups addressing one or more of the CVEs [4][5][6][7][8], as well as PoC exploits [9][10][11] are publicly available.
The three Citrix NetScaler ADC and Gateway CVEs added to CISA’s KEV list in September, each shown with its CVSS severity band and EPSS exploitation-probability score
An improper input validation flaw [CWE-20] allows unauthenticated, arbitrary RCE. All NetScaler ADC and NetScaler Gateway deployments are vulnerable in the default configuration.
An authentication bypass using an alternate path [CWE-288] allows a remote, unauthenticated attacker to target appliances. Exploitability requires the appliance to be configured as a Gateway or AAA virtual server, and for certain later affected builds, a SAML action must also be configured. The practical impact depends on configuration: an attacker may be able to trigger DoS conditions or, on a vulnerable Gateway, potentially obtain an anonymous authenticated VPN session with access to an organization’s internal network.
A memory overflow flaw [CWE-119] that allows RCE or triggering denial of service (DoS) conditions. Exploitability depends on DTLS being enabled, which is enabled by default on VPN vServer deployments.
Affected versions are shown below:
No workarounds have been provided by the vendor. Affected users should update systems to the most relevant fixed build as described above. Immediately after the flaws were disclosed, the OPENVAS ENTERPRISE FEED added a remote banner version check for CVE-2026-88771 and CVE-2026-88772, and a separate remote banner check and active check for CVE-2026-19490.
Two New SonicWall SMA1000 Flaws Added to CISA’s KEV List
SonicWall has confirmed that two new SMA1000 vulnerabilities, described below, are being actively exploited in the wild [1][2].
The two SonicWall SMA1000 CVEs added to CISA’s KEV list, each shown with its CVSS severity band and EPSS exploitation-probability score
A pre-authentication SSRF flaw [CWE-918] in the Appliance Work Place interface caused by an unintended alternate access path. A remote, unauthenticated attacker could gain unauthorized access to sensitive functionality and perform unauthorized operations.
An OS command injection flaw [CWE-78] in the Appliance Management Console (AMC) allows a remote authenticated attacker with admin credentials to execute arbitrary OS commands on an affected device.
Exploitation of the two flaws can be chained to achieve unauthenticated RCE on affected appliances. A Metasploit module covering the exploit chain is available. SonicWall released a combined security update in SNWLID-2026-0016. Within hours of their disclosure, the OPENVAS ENTERPRISE FEED added a remote banner check that covers both CVEs.
CVE-2025-25249: Fortinet FortiOS Actively Exploited
CVSS 9.8 · CriticalEPSS 3.9% (90th)Actively exploitedIn CISA KEV
CVE-2025-25249 (CVSS 9.8, EPSS ≥ 90th pctl), published in January 2026, is a heap-based buffer overflow [CWE-122] in Fortinet’s cw_acd daemon. cw_acd is Fortinet’s CAPWAP (Control and Provisioning of Wireless Access Points) Access Controller daemon. The vulnerable path is reachable over the network, and exploitation allows unauthenticated arbitrary RCE on affected FortiOS, FortiSwitchManager, and FortiSASE devices. On FortiOS, the interface setting set allowaccess fabric enables the Security Fabric Connection service, which includes FortiTelemetry and the CAPWAP endpoint.
CVE-2025-25249 has been exploited in the wild since July 2026, and CISA added the flaw to its KEV catalog in September. The vulnerability has been used to deploy PivotC2, a novel Node.js malware strain against at least 178 confirmed victims.
Fortinet advises that the issue can be mitigated by removing fabric access for each interface or by disallowing access to the CAPWAP daemon. Users should verify their exposure and either apply the workaround or upgrade affected devices to the latest fixed versions. Devices using FortiOS version 6.4 must migrate to a fixed release train.
Immediately after disclosure, Greenbone’s OPENVAS ENTERPRISE FEED added package-level detection for CVE-2025-25249 in FortiOS. The ENTERPRISE FEED also includes regular detection for emerging vulnerabilities affecting Fortinet products.
CVE-2026-94127: Actively Exploited F5 BIG-IP APM OAuth Flaw Allows Unauthenticated RCE
CVSS 9.8 · CriticalEPSS 2.2% (82nd)Actively exploitedIn CISA KEV
CVE-2026-94127 (CVSS 9.8, EPSS ≥ 82nd pctl) is a critical heap-based buffer overflow [CWE-122] affecting F5 BIG-IP APM. The flaw allows unauthenticated RCE and full-system compromise on affected devices. Exploitability depends on APM access policy and an OAuth profile being configured on the same virtual server. Deployments using APM only as an OAuth Client or Resource Server are not affected.
The attack chain involves providing an oversized Authorization: Bearer header to an OAuth endpoint such as /f5-oauth2/v1/userinfo. F5 has confirmed active exploitation in the wild, and the flaw has been added to CISA’s KEV list. Also, watchTowr Labs has published a technical write-up with exploit details.
F5 provides an official iRule-based workaround for customers with a support agreement. Other temporary mitigation controls include restricting access to OAuth endpoints using IP allow-listing or web application firewall (WAF) rules and disabling the OAuth Authorization Server if it is not in use. The OPENVAS ENTERPRISE FEED includes package detection for CVE-2026-94127 in F5 BIG-IP APM and regular detection for vulnerabilities affecting F5 products. The affected versions and corresponding hotfix patches are shown below:
Critical Flaws Affecting Check Point Security Products Include Two Actively Exploited
Check Point reported active exploitation of two critical flaws: CVE-2026-85102 (CVSS 9.8, EPSS ≥ 94th pctl) affecting VPN certificate handling on Check Point Quantum Security Gateway and Spark Firewall, and CVE-2026-93616 (CVSS 9.8, EPSS ≥ 97th pctl) in the Check Point management web service. Both were added to CISA’s KEV catalog [1][2]. Two additional critical issues were disclosed in September: CVE-2026-85103 (CVSS 9.8, EPSS ≥ 89th pctl) and CVE-2026-91843 (CVSS 9.8, EPSS ≥ 42nd pctl), which affect VPN and management-plane components.
Attacks against Spark customers from anonymized IPs were observed globally. Check Point also said post-exploitation activity included internal port and service scans. Although Security Management and Log Server is not explicitly an edge networking service, Censys found 3,836 publicly accessible instances globally.
The four critical Check Point CVEs described in this section, each shown with its CVSS severity band and EPSS exploitation-probability score
Improper certificate trust [CWE-295] during VPN negotiation in Check Point Quantum Security Gateway allows an unauthenticated remote attacker to execute arbitrary code on the Gateway. A full list of affected products and versions is available from the vendor’s sk1000117 advisory.
A directory traversal flaw [CWE-22] allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server. A full list of affected products and versions is available from the vendor’s sk1000171 advisory.
A heap-based buffer overflow [CWE-122] in VPN certificate ASN.1 decoding allows an unauthenticated, remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems. A full list of affected products and versions is available from the vendor’s sk1000118 advisory.
A stack overflow [CWE-121] during the login process allows an unauthenticated, remote attacker to run arbitrary code with root privileges. A full list of affected products and versions is available from the vendor’s sk1000155 advisory.
The OPENVAS ENTERPRISE FEED includes a remote banner check that covers CVE-2026-85102 and CVE-2026-85103, and separate remote banner checks for CVE-2026-93616 [3] and CVE-2026-91843 [4]. Organizations using affected Check Point products should prioritize remediation for internet-exposed VPN and management systems, with the highest priority on the two actively exploited vulnerabilities.
Adobe Commerce/Magento: Two Actively Exploited CVEs Allow Remote PHP Code Execution and Customer Account Takeover
Adobe disclosed two critical-severity issues in Adobe Commerce and Magento Open Source. CVE-2026-75650 (CVSS 10, EPSS ≥ 90th pctl), dubbed “StyleSmuggler”, is a template-engine flaw [CWE-1336] that can enable unauthenticated arbitrary RCE. The second critical flaw, CVE-2026-71362 (CVSS 9.1, EPSS = 100th pctl), is an incorrect authorization flaw [CWE-863] that allows privilege escalation. Adobe reports that CVE-2026-75650 is being exploited in the wild. Both CVEs have been added to CISA’s KEV list [1][2] and are flagged for forensic triage.
Sansec reported that exploitation of StyleSmuggler starts with an unauthenticated request to Magento’s GraphQL endpoint. A specially crafted HTTP request allows an attacker to smuggle malicious PHP via HTTP headers and parameters into the template-processing chain. The malicious PHP is later executed during automated email rendering. Sansec also reported that CVE-2026-71362 lets attackers switch a customer session to another customer account, providing access to private customer data.
The OPENVAS ENTERPRISE FEED includes separate remote banner checks for CVE-2026-75650 [3] and CVE-2026-71362 [4] in Adobe Commerce and Magento Open Source. CVE-2026-71362 was addressed through Adobe’s APSB26-138 security update. For CVE-2026-75650 (StyleSmuggler), Adobe subsequently released the VULN-39341 hotfix. Both updates must be applied according to the affected release train. Adobe also recommends that users rotate exposed encryption keys, OAuth client secrets, tokens for integrated third-party extensions, payment credentials, and other privileged credentials.
CVE-2026-28326: Hard-Coded Key Allows Unauthenticated RCE in SolarWinds Access Rights Manager
CVSS 8.8 · HighEPSS 0.7% (51st)
CVE-2026-28326 (CVSS 8.8) is an unauthenticated RCE flaw in SolarWinds Access Rights Manager prior to version 2026.2.1. The root cause is a hard-coded static key [CWE-321], and exploitation allows total device compromise. Some technical details are available, which could support exploit development. ARM’s gRPC service on TCP port 55555 does not properly handle a missing client certificate during TLS authentication, but instead redirects to a fallback authentication mechanism. The fallback path accepts an HMAC token generated with a hard-coded secret, allowing an attacker to authenticate without a client certificate.
Access Rights Manager (ARM) is used to provision, deprovision, manage, and audit user access rights to systems, data, and files in corporate networks, including Microsoft Active Directory, Exchange, and SharePoint. The product’s central role in access-rights administration makes patching CVE-2026-28326 critical, especially where ARM is reachable via untrusted IP addresses.
The OPENVAS ENTERPRISE FEED includes a remote banner check for CVE-2026-28326 in SolarWinds ARM. CVE-2026-28326 affects Access Rights Manager 2026.2 and all previous versions. For deployments that cannot be updated immediately, SolarWinds strongly recommends not exposing ARM on the public internet and restricting access to trusted IPs. For full mitigation, users should upgrade to the fixed version 2026.2.1 as soon as possible.
Ivanti Patches Six Critical Flaws in Neurons ITSM
Ivanti disclosed eight new CVEs in Neurons for ITSM prior to version 2026.2; all allow RCE on the server. Six are rated critical severity. Two can be exploited without authentication, while the remaining require authenticated access. The CVEs include improper deserialization [CWE-502] and missing authorization [CWE-862] flaws. While there is no evidence of exploitation in the wild yet, Ivanti products are a popular target in cyberattacks, including ransomware attacks.
Ivanti Neurons for ITSM is used by administrators and IT staff to manage service requests, incidents, problems, and changes. Exploitation allows attackers to manipulate service-desk data, credentials, and integrations, and potentially pivot further into an organization’s IT network.
The affected versions and fixes are shown below:
Ivanti’s security advisories [1][2] indicate that cloud customers are already protected, but on-premises administrators must apply the relevant patch for mitigation. Immediately after the disclosure, the OPENVAS ENTERPRISE FEED added a remote banner check covering all aforementioned CVEs in Ivanti Neurons for ITSM.
Summary
In September, critical flaws in enterprise IT products emerged at an accelerated pace. Critical flaws in N-able N-central, Citrix NetScaler, SonicWall, Fortinet, F5, Check Point, Adobe Commerce, and Ivanti Neurons ITSM illustrate persistent high-risk exposure to internet-facing systems. While the numbers are staggering, defenders need to remain vigilant. Regular scanning, orderly prioritization, and timely patching are still the most fundamental way to prevent attackers from exploiting software flaws for impact.
Start Your Free Trial
Earlier in September, the Greenbone blog alerted to numerous emerging risks to IT systems. These include an actively exploited “MikroTrick” exploit chain targeting RouterOS [1], three actively exploited JFrog Artifactory vulnerabilities [2], an actively exploited flaw in GitLab [3], heightened risk for Cisco products from its September vulnerability disclosures [4], active exploitation of Roundcube Webmail CVE-2026-48842 [5], attacks targeting Zyxel GS1900 switches via CVE-2026-7273 [6], and active exploitation of the WSO2 API platform [7]. Greenbone’s OPENVAS SCAN allows IT defenders to tackle vulnerability management head-on, helping them detect and mitigate emerging threats before attackers can take advantage. A trial copy of OPENVAS SCAN includes a free two-week trial of the OPENVAS ENTERPRISE FEED, with over 250,000 vulnerability tests and counting.
Joseph has had a varied and passionate background in IT and cyber security since the late 1980s. His early technical experience included working on an IBM PS/2, assembling PCs and programming in C++.
He also pursued academic studies in computer and systems engineering, anthropology and an MBA in technology forecasting.
Joseph has worked in data analytics, software development and, in particular, enterprise IT security. He specialises in vulnerability management, encryption and penetration testing.



