18 Sep 2026

Week in review

Greetings,

September is MFA Month, making it the perfect time to review one of the simplest and most effective cyber security measures available: multi-factor authentication (MFA).

As part of the Australian Signals Directorate’s (ASD) MFA: Switch It On campaign, organisations across Australia are being encouraged to enable MFA on all accounts and systems. The initiative aims to increase MFA adoption across businesses, government agencies, and critical infrastructure organisations, helping make Australia a safer place to connect online.

The need for MFA has never been clearer. According to the ASD, 42% of cyber security incidents reported by industry, government, and critical infrastructure organisations in 2024-25 involved compromised accounts or credentials. This serves as a timely reminder that passwords alone are no longer enough to protect against modern cyber threats.

MFA adds an extra layer of protection by requiring users to verify their identity using more than just a password. As one of the most effective defences against unauthorised access, phishing-resistant forms of MFA can significantly reduce the risk of cybercriminals gaining access to accounts, applications, corporate systems, and networks.

By encouraging employees, customers, suppliers, and stakeholders to enable MFA, organisations can strengthen their cyber resilience, better protect sensitive information and assets, and reduce the risk of account compromise.
For practical guidance, including step-by-step instructions for enabling MFA on popular accounts and applications, visit the Australian Cyber Security Centre's guide


ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks
Date: 2026-09-14
Author: Security Week

ConnectWise has released urgent patches for a critical-severity vulnerability in the ScreenConnect remote access and support software that has been exploited in worm-like attacks.
Tracked as CVE-2026-84869 (CVSS score of 9.9/10), the security defect is described as a missing authorization and improper privilege management issue.
The bug creates “a condition in the ScreenConnect client that may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances,” ConnectWise explains in its advisory.

Cisco patches Secure Email Gateway zero-day exploited in attacks
Date: 2026-09-15
Author: Bleeping Computer

[Please see AUSCERT bulletin https://portal.auscert.org.au/bulletins/ESB-2026.10980.2/]
Cisco warned customers to patch a critical Secure Email Gateway zero-day security flaw that threat actors have been exploiting in attacks.
"In September 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability," the company warned in a Monday security advisory.
The security flaw (tracked as CVE-2026-76461) was found in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway and affects virtual and physical appliances, regardless of the device configuration.

GitLab Vulnerability Exploited One Day After Disclosure
Date: 2026-09-11
Author: Security Week

[Please see AUSCERT bulletin https://portal.auscert.org.au/bulletins/ESB-2026.10914/]
Threat actors have started exploiting a newly patched vulnerability in GitLab one day after public disclosure, attack surface management firm WatchTowr warns.
Tracked as CVE-2026-85706 (CVSS score of 10/10), the security defect is described as a path traversal issue that can allow unauthenticated users to read arbitrary files from the GitLab server.
All Community Edition (CE) and Enterprise Edition (EE) versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 are affected.

Check Point Patches Critical VPN Vulnerabilities
Date: 2026-09-11
Author: Security Week

Cybersecurity firm Check Point this week announced patches for two critical-severity vulnerabilities in its gateway and firewall products using VPN functionality.
Tracked as CVE-2026-85102 and CVE-2026-85103 (CVSS score of 9.8), both security defects could be exploited without authentication for remote code execution (RCE), Check Point warns.
The former is described as an improper validation of certificate data during VPN negotiation, while the latter is a heap overflow in the VPN certificate ASN.1 decoding flow.

Passkey-themed phishing attacks lead to Microsoft 365 data theft
Date: 2026-09-11
Author: Bleeping Computer

Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts and steal data from Microsoft 365 services.
The activity has been observed since May 2026 and begins with the attackers researching targeted organizations and employees before calling or messaging victims while impersonating corporate IT help desks.
The attackers tell employees that they must urgently update a passkey, multi-factor authentication (MFA), or single sign-on (SSO) configuration to avoid losing access to corporate systems.


ASB-2026.0222 – Check Point Products: CVSS (Max): 9.8

Check Point have provided fixes for two critical CVSS 9.8 flaws that affect Check Point Security Gateway, Security Management Server and Spark Firewall (Centrally Managed and Locally Managed) products.

ASB-2026.0236 – Oracle Communications: CVSS (Max): 9.8

Oracle have provided a Critical Security Patch Update that contains 31 new security patches for Oracle Communications – 23 of these vulnerabilities may be remotely exploitable without authentication.

ESB-2026.11217 – Cisco Secure Firewall Management Center (FMC): CVSS (Max): 10.0

Cisco has released software updates that address a vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.

ESB-2026.10914 – GitLab Community & Enterprise Edition: CVSS (Max): 10.0

GitLab have provided updated versions of GitLab Community & Enterprise Edition that contain important bug and security fixes, and they strongly recommend that all self-managed GitLab installations be upgraded to one of these versions immediately.

ESB-2026.10980.2 – Cisco Secure Email Gateway: CVSS (Max): 9.8

Cisco has released software updates that address a vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.


Stay safe, stay patched and have a good weekend!

The AUSCERT team