// Zero-day
Zero-Days, KEV Additions, and a $351M Crypto Heist: September 26 Threat Briefing
By NeoShield AI Threat Desk · Published 2026-09-26 · 5 min read
#zero-day#CISA KEV#Kiteworks#SharePoint#MikroTik#WordPress#Roundcube#WSO2
A wave of actively exploited vulnerabilities across file-sharing, email, CMS, and API platforms converged today with a massive state-sponsored crypto theft, demanding immediate defensive action from security teams worldwide.
The most operationally disruptive item is the Kiteworks advisory urging customers to take their secure file-sharing servers offline for a six-hour window. Kiteworks is used by organizations that handle sensitive regulated data, including legal, financial, and government sectors. The company's decision to recommend a proactive shutdown signals that threat intelligence is specific and credible enough to justify business disruption over risk acceptance. If your organization runs Kiteworks, treat this as a P1 incident response action: coordinate the maintenance window immediately, notify stakeholders, and monitor vendor channels for indicators of compromise or patch releases. Do not wait for a confirmed breach before acting.
CISA's KEV catalog received six additions today, which is an unusually high single-day volume and reflects the breadth of the current threat landscape. CVE-2026-65660, a code injection vulnerability in Microsoft SharePoint, is particularly dangerous given SharePoint's prevalence as a collaboration backbone in enterprise environments. Code injection flaws at this level can allow attackers to execute arbitrary code in the context of the application, potentially pivoting to broader network access. CVE-2026-67279 affects MikroTik RouterOS and involves improper enforcement of behavioral workflow controls. MikroTik devices are ubiquitous in SMB and ISP environments and have historically been weaponized into botnets and used as covert relay infrastructure by advanced threat actors. CVE-2026-87902 is a Remote File Inclusion vulnerability in WordPress Core, a class of flaw that allows attackers to load and execute malicious remote scripts, often leading to full site compromise and lateral movement into hosting infrastructure.
WSO2 API Control Plane carries a CVSS score of 9.8 for CVE-2026-5430, a path traversal vulnerability that in API gateway contexts can expose backend service configurations, credentials, and internal routing logic. Adobe Commerce, the e-commerce platform formerly known as Magento, also appears in today's KEV additions. Adobe Commerce has been a persistent target for payment card skimming operations, and any unpatched instance should be treated as a high-priority remediation item, especially for organizations in retail or financial services.
Roundcube Webmail's CVE-2026-48842 deserves special attention because it is a pre-authentication SQL injection, meaning attackers do not need valid credentials to begin exploitation. With a CVSS score of 8.1 and active exploitation confirmed by the Canadian Centre for Cyber Security, any internet-facing Roundcube instance running the virtuser_query plugin is at immediate risk. SQL injection at the authentication layer can expose the entire user database, enable account takeover, and in some configurations allow further server-side exploitation.
Finally, the $351.6 million theft from Bitget's hot and warm wallets attributed to North Korean threat actors is a stark reminder that cryptocurrency holdings represent a high-value target for sophisticated, well-resourced adversaries. The Lazarus Group and affiliated clusters have refined their techniques for targeting exchange infrastructure, insider social engineering, and supply chain compromise. Any organization holding or transacting in cryptocurrency should review wallet architecture, enforce cold storage for reserves, and audit privileged access to exchange accounts and API keys.
Defensive priorities for today:
- Kiteworks: Execute the recommended six-hour shutdown window immediately and monitor vendor advisories for patch or IOC releases.
- SharePoint (CVE-2026-65660): Apply Microsoft patches on an emergency basis; review SharePoint server logs for anomalous code execution or unusual service account activity.
- MikroTik RouterOS (CVE-2026-67279): Audit all RouterOS devices in your environment, apply available firmware updates, restrict management interfaces to trusted IP ranges, and disable unnecessary services.
- WordPress Core (CVE-2026-87902): Update WordPress installations to the latest patched version immediately; audit allow_url_include PHP settings and web server logs for remote file inclusion attempts.
- WSO2 API Control Plane (CVE-2026-5430): Apply vendor patches; review API gateway logs for path traversal patterns such as directory traversal sequences in request URIs.
- Adobe Commerce: Patch immediately; deploy file integrity monitoring and review payment processing logs for signs of skimmer injection.
- Roundcube (CVE-2026-48842): Patch or temporarily disable the virtuser_query plugin; review database query logs for anomalous authentication-phase SQL patterns.
- Cryptocurrency assets: Migrate reserves to cold storage, rotate API keys, enforce hardware MFA on all exchange accounts, and brief staff on social engineering tactics used by North Korean actors.
Across all of these items, ensure your SIEM is ingesting logs from the affected platforms and that detection rules are tuned for the specific exploitation patterns described. Threat intelligence sharing with sector peers is strongly encouraged given the breadth of today's activity.
This briefing is informational and does not substitute for official vendor advisories, CISA guidance, or your organization's own risk assessment processes.
Related articles
Critical Zero-Days Across Network Infrastructure Demand Immediate Action — October 2026
A wave of critical, actively exploited vulnerabilities is hitting core enterprise infrastructure today, spanning SD-WAN…
Zero-dayZero-Days Everywhere: FBI, Check Point, WordPress, and Network Gear All Hit on Same Day
A wave of critical zero-day exploits struck enterprise and government infrastructure on September 23, 2026, spanning Oracle…
Zero-dayZero-Days, Auth Bypasses, and Invisible Phishing: September 7 Threat Briefing
A wave of critical unpatched and actively exploited vulnerabilities is hitting e-commerce platforms, print management systems…
NeoShield Security publishes defensive cybersecurity guides for developers, small teams, SOC learners, and MSPs. AI-assisted content is reviewed for safety, defensive purpose, and practical security value.