Cybersecurity Radar — 2026-09-23
CISA has ordered federal agencies to patch an actively exploited Zyxel switch flaw within days, as a suspected Chinese-speaking actor has been weaponizing it since mid-August. Microsoft confirmed that a SharePoint vulnerability it previously rated as low-severity spoofing is in fact a high-severity remote code execution flaw with no clear exploitation ceiling. Meanwhile, ransomware has reportedly hit a record 997 global incidents this quarter, with utilities and healthcare surging.
Cybersecurity Radar — 2026-09-23
🔴 Critical Alerts
Microsoft SharePoint RCE reclassification. Microsoft has confirmed that a SharePoint Server vulnerability originally logged as a low-severity spoofing issue is actually a high-severity remote code execution (RCE) flaw that low-privileged, authenticated attackers can exploit to run arbitrary code on affected servers. Organizations running on-premises SharePoint should treat this as urgent and apply Microsoft's fix immediately.

CISA orders federal patching of exploited Zyxel flaw. CISA added CVE-2026-7273, affecting Zyxel switches, to its Known Exploited Vulnerabilities (KEV) Catalog and ordered Federal Civilian Executive Branch agencies to secure their switches by Thursday under Binding Operational Directive (BOD) 26-04. CISA noted this vulnerability type "is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise."

Threat Landscape
Zyxel and Veeam flaws under active exploitation. CISA's KEV additions also cover Veeam flaws enabling command and SYSTEM access. GreyNoise reported a suspected Chinese-speaking malicious actor has weaponized the Zyxel flaw since August 17, 2026, with successful exploitation confirmed; affected devices include GS1900-48HPv2 firmware 2.90(ABTQ.1)C0 and earlier, fixed in 2.90(ABTQ.2)C0.

macOS backdoor activity resurfaces. SentinelOne disclosed attack activity involving Apple macOS backdoors tracked as FLATROOF (aka Gaslight) and ROOFDECK, both previously observed in the March–April 2026 campaign, indicating renewed use of these implants.
Ransomware at record levels. A weekly intelligence briefing for the week of September 21 reports ransomware reached a record 997 incidents globally, with utility and healthcare sectors surging, alongside confirmed critical infrastructure intrusions and actors using AI-assisted exploitation tools.

Vulnerabilities & Patches
ZcopyReaper Linux kernel bug (CVE-2026-43502). A CVSS 7.8 local privilege escalation issue affecting the RDS zero-copy path, present in kernels since 4.17, has been detailed with patch status and fixes; Linux kernel environments should verify patch availability.
Cisco ISE zero-day CVE-2026-76460 (CVSS 10.0). Cisco patched an actively exploited ISE zero-day enabling root command execution via auth bypass, with no workaround available; CISA gave federal agencies only a 3-day KEV deadline.
CVE-2026-96257 (CVSS 10.0) in Fast FAC1203R Gigabit Edition 2.0.4. A critical flaw in the copy_msg_element function has been disclosed at the maximum severity rating.
CISA flags three Linux kernel exploits in the wild. CISA added three actively exploited Linux kernel flaws to its KEV catalog, including bugs enabling local privilege escalation and DoS.
Breaches & Incidents
Japan's Digital Agency breach. Check Point's September 21 threat intelligence report confirms a data breach at Japan's Digital Agency, which operates the Government Solution Service used by multiple ministries.

Industry & Policy
Cybersecurity Awareness Month 2026 focuses on critical infrastructure. October's theme, "Securing the Next 250," urges critical infrastructure operators to adopt the cybersecurity "3Rs" framework.

Industry shift toward algorithmic resilience. Analyst commentary on the 2026 landscape describes a widening "preparedness gap" and a shift toward algorithmic resilience as attack tempo outpaces human response.
What to Watch
- The weekend deadline under CISA's BOD 26-04 for federal agencies to remediate the exploited Zyxel switch flaw — expect expanded scanning against network device fleets.
- Continued scrutiny of the reclassified SharePoint RCE, including whether exploitation guidance or proofs of concept emerge in the coming days.
- Whether the record 997-incident ransomware quarter translates into further KEV-driven emergency patching, particularly in utilities and healthcare.
Reader Action Items
- Update Zyxel switch firmware to 2.90(ABTQ.2)C0 or later, and check both Zyxel and Veeam products against the latest KEV additions.
- If you run on-premises SharePoint Server, review Microsoft's latest advisory and patch immediately given the RCE reclassification.
- Audit Linux deployments for CVE-2026-43502 exposure and verify kernel versions are patched, especially where untrusted local users can execute code.
This content was collected, curated, and summarized entirely by AI — including how and what to gather. It may contain inaccuracies. Crew does not guarantee the accuracy of any information presented here. Always verify facts on your own before acting on them. Crew assumes no legal liability for any consequences arising from reliance on this content.