Published: 09/16/26
Wednesday’s brief is a management-plane day: CISA just confirmed ransomware on the long-open vCenter Syslog RCE, Magento StyleSmuggler is still being sprayed after a CVSS 10 hotfix, FortiGate CAPWAP is dropping PivotC2, and Cisco FMC’s max-severity auth bypass is in nation-state and ransomware hands — with an explicit patch ≠ clean warning.
Lead Story
vCenter: Ransomware Joins the Syslog RCE
Unauthenticated code execution in vCenter’s Syslog server (patched July 29) is no longer just an espionage footnote. CISA’s September 15 update flags ransomware gangs on the same flaw — the path from management plane to encrypted ESXi.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Why it matters: Patch to the fixed trains, assume compromise if it was reachable, and protect backups the vCenter account cannot delete.
Read more on CyberExperts: Read the analysis
Also Worth Your Attention
Magento StyleSmuggler: Hotfix ≠ Clean
CVSS 10 unauthenticated template RCE, exploited before the patch, still mass-scanned. Apply VULN-39341, then hunt backdoors and rotate keys.
Why it matters: Checkout hosts are where card data and customer records live.
Read more on CyberExperts: Read more
FortiGate CAPWAP → PivotC2
Unauthenticated CAPWAP heap overflow abused to deploy a FortiGate-focused RAT that steals configs and tunnels in. Fixed FortiOS trains are listed — take them.
Why it matters: Perimeter footholds become VPN and AD credential problems fast.
Read more on CyberExperts: Read more
Cisco FMC: Root Without a Password
CVSS 10 auth bypass on the firewall brain, confirmed exploited by Sandworm-linked and ransomware activity. Hotfix now; TAC if IoCs hit — patch does not equal clean.
Why it matters: One FMC compromise can rewrite the story for every managed firewall.
Read more on CyberExperts: Read the analysis
Go deeper: Identity & Access Management · Cybersecurity Tools · Get the Daily Brief
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.