top of page

Cybersecurity Weekly Roundup: 7–14 September 2026

Writer: SOC Team
SOC Team
46 minutes ago
3 min read

1. JFrog Artifactory Vulnerabilities Exploited to Gain Admin Control


Attackers have chained multiple vulnerabilities in JFrog Artifactory to gain administrator privileges on self-hosted servers and deploy backdoors. Security researchers observed attacks between 15 August and 8 September, including activity involving administrator account creation, malicious plugins and remote command execution.

A separate critical vulnerability, CVE-2026-82329, was also exploited between 1 and 8 September, allowing unauthenticated attackers to obtain administrator privileges without requiring an additional vulnerability.

CVE ID: CVE-2026-42018, CVE-2026-42016 and CVE-2026-82329 (CVSS 9.8 for CVE-2026-82329)

Why It Matters: JFrog Artifactory is used to store and distribute software packages and build artefacts. Successful exploitation could provide attackers with administrative access to repositories, credentials and software supply-chain infrastructure.

Actions: Upgrade self-hosted Artifactory to the appropriate fixed version for the affected release branch. Review administrator accounts, tokens, plugins, repositories and configuration changes for unexpected activity. Rotate affected credentials, tokens and Artifactory join keys where compromise is suspected.


2. Cisco Firewall Management Center Vulnerabilities Exploited in Ransomware Attacks


Attackers are actively exploiting two vulnerabilities affecting Cisco Secure Firewall Management Center (FMC). Cisco Talos identified three separate threat clusters linked to ransomware and state-sponsored activity targeting vulnerable FMC systems.

The attacks have included credential theft, web-shell deployment, reverse shells and the deployment of ransomware, demonstrating the potential impact of compromising a centrally managed security platform.


CVE ID: CVE-2026-20079 (CVSS 10.0) and CVE-2026-20316 (CVSS 5.3)

Why It Matters: Cisco FMC provides centralised management for firewall infrastructure. Successful exploitation could give attackers root-level access to the management platform, expose sensitive network information and provide a foothold for further attacks against the environment.

Actions: Apply Cisco's available security updates immediately. Restrict FMC management interfaces from unnecessary internet exposure and review logs for unexpected administrator activity, web shells, reverse shells, credential theft and unusual outbound connections.


3. Chrome Zero-Day Actively Exploited in the Wild


Google has released security updates for Chrome after confirming that a vulnerability in the browser's V8 JavaScript and WebAssembly engine is being actively exploited in the wild.

The flaw is an out-of-bounds write that can allow a remote attacker to execute arbitrary code inside Chrome's sandbox through a specially crafted HTML page. CISA subsequently added the vulnerability to its Known Exploited Vulnerabilities catalogue.


CVE ID: CVE-2026-87491

Why It Matters: Chrome is widely deployed across enterprise environments, making browser vulnerabilities an attractive route for attackers. Successful exploitation could allow a malicious webpage to execute code on a victim's system and potentially lead to further compromise.

Actions: Update Chrome to version 153.0.8010.36/.37 for Windows and macOS, or 153.0.8010.36 for Linux. Ensure other Chromium-based browsers receive their corresponding security updates and monitor endpoints for suspicious browser-child processes.


4. AI-Powered Attack Uses PaperCut Vulnerabilities to Compromise 395 Organisations


Security researchers identified a large-scale campaign in which hundreds of AI agents were used to develop, test and launch exploits against vulnerable PaperCut NG/MF servers. The campaign compromised at least 440 PaperCut instances belonging to 395 organisations across 48 countries.The attackers used AI models alongside conventional offensive security tools to automate reconnaissance and exploitation. Researchers observed attackers obtaining credentials from 280 victims and administrator privileges at 12 organisations, with the education sector accounting for roughly half of the victims.


CVE ID: CVE-2026-81578 and CVE-2026-82078

Why It Matters: PaperCut is widely used by schools, universities and organisations to manage printing infrastructure. Compromised PaperCut servers can provide attackers with access to credentials and domain environments, potentially enabling privilege escalation, data theft or ransomware deployment.Actions: Apply PaperCut's latest security updates immediately. Restrict unnecessary internet access to PaperCut servers and review authentication, administrative and process activity for signs of compromise. Pay particular attention to credential theft, unexpected administrator accounts and suspicious domain activity.


Key Recommendations


  • Prioritise actively exploited vulnerabilities: Review exposure to CVE-2026-82329, CVE-2026-20079, CVE-2026-87491, CVE-2026-81578 and CVE-2026-82078 and apply available security updates as a priority.

  • Secure privileged infrastructure: Give urgent attention to JFrog Artifactory, Cisco FMC, PaperCut and other systems with administrative access to critical environments.

  • Patch enterprise endpoints: Ensure Chrome and other Chromium-based browsers are fully updated across managed devices.

  • Monitor for exploitation: Review logs for unexpected administrator accounts, authentication anomalies, web shells, reverse shells, malicious plugins, privilege escalation and unusual outbound connections.

  • Protect credentials: Rotate credentials, tokens and other secrets where vulnerable systems may have been compromised.

  • Review education-sector exposure: Organisations using PaperCut should specifically review their exposure because education organisations represented a significant proportion of the observed campaign.

  • Prepare for AI-assisted attacks: Security teams should expect attackers to increasingly use AI to accelerate reconnaissance, exploit development and large-scale attacks, reducing the time available for defenders to respond.

 
 
bottom of page