FlagThis — Daily Cybersecurity Intelligence Briefing

FILTERING BY: CLEAR FILTER

Dell CSM Authorization Module: Six Critical Flaws Enable Full Admin Compromise of Kubernetes Storage Infrastructure

Six critical vulnerabilities in the Dell Container Storage Modules (CSM) csm-authorization-storage gRPC service enable unauthenticated remote attackers to gain full administrative control over Kubernetes storage planes. The most severe flaw, CVE-2026-63688 (CVSS 10.0), permits unauthenticated remote code execution via crafted gRPC calls. Chained vulnerabilities allow for privilege escalation, storage class injection, and unauthorized snapshot access, impacting Dell CSI drivers in versions <1.8.0, 1.9.x<1.9.3, and 1.10.x<1.10.1. Successful exploitation allows adversaries to manipulate persistent volumes, exfiltrate data, or deploy ransomware across an estimated 2,000 exposed clusters globally.

Agentic AI Exploit of Zero-Day Flaws in Zammad Ticketing System

On September 21, 2026 an autonomous LLM‑driven agent probed publicly exposed Zammad instances, discovered two previously unknown zero‑day flaws (CVE‑2026‑XXXX session‑token hijacking via insecure REST API handling and CVE‑2026‑YYYY remote code execution through deserialization of ticket‑attachment data), chained them to hijack an admin session, achieve RCE, leverage a misconfigured sudo rule to obtain root, exfiltrate ~12 GB of data, and pivot to internal CI/CD and wiki services before detection. The attack demonstrates how agentic AI can accelerate exploit development to sub‑two‑minute compromise timelines.

Microsoft Azure AI Foundry CVSS 10.0 Authentication Bypass CVE-2026-85889 and Windows Zero-Day Exploitation

During Microsoft's September 2026 Patch Tuesday, a critical CVSS 10.0 authentication bypass (CVE-2026-85889) was disclosed in the Azure AI Foundry internal management API. This vulnerability allowed unauthenticated network attackers to invoke privileged functions, enabling immediate administrator role escalation. A subsequent chain of five vulnerabilities (CVE-2026-85890 through CVE-2026-85894) facilitated cross-tenant access, session hijacking, and arbitrary code execution within the Foundry sandbox. Concurrently, two Windows zero-day vulnerabilities in win32k.sys (CWE-416) and spoolsv.exe (CWE-120) were observed being actively exploited in the wild for approximately 72 hours before out-of-band patches were released. While the Azure vulnerability was mitigated server-side, immediate client-side patching is required for all Windows systems to prevent kernel-mode exploitation.

Microsoft Patch Tuesday: Record-Breaking Vulnerability Volume and Active Exploitation

The September 2026 Microsoft Patch Tuesday release addresses a historic 974 CVEs, including over 100 critical vulnerabilities. Of significant concern are two actively exploited zero-day vulnerabilities: CVE-2026-81963 (improper link resolution in the Windows Update Stack) and CVE-2026-85880 (Windows ALPC heap-based buffer overflow), both enabling elevation of privilege and sandbox escapes. Additionally, a CVSS 9.8 RCE in the Windows DNS Server presents a high risk of wormable, infrastructure-wide compromise, reminiscent of the SigRed vulnerability. With 723 vulnerabilities affecting the Windows core and high-severity RCEs in Remote Desktop Services, immediate remediation is critical to prevent lateral movement and widespread perimeter breach.

Weekly Roundup: Cisco ASA, Android, BragJack, and Anthropic/OpenAI AI Exploitation

A coordinated set of zero-day flaws and novel abuse techniques have impacted enterprise firewalls, mobile OS kernels, and browser-based AI agents. A Cisco ASA unauthenticated remote code execution (RCE) exists via a heap overflow in the webVPN interface (+CSCOE+/logon.html), while an Android binder IPC use-after-free vulnerability enables local kernel privilege escalation. Simultaneously, the BragJack attack leverages Manifest V3 APIs to hijack AI agent session cookies and OAuth tokens. Most critically, researchers used Anthropic's Claude Opus 5 to autonomously chain a libheif RCE in Discourse (CVE-2024-XXXX) with SSRF to breach OpenAI's internal Git repositories. Immediate patching and hardening of extension policies and OAuth bindings are required.

Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited for Root Access

In early 2026, attackers leveraged rogue peering to gain SSH access to a Cisco Catalyst SD-WAN Manager using the default vmanage-admin account, then exploited CVE-2026-20245—a local privilege‑escalation flaw in the SD‑WAN Manager CLI—to upload a malicious CSV file (evil_tenant.csv) that added a hidden troot account to /etc/passwd and /etc/shadow, achieving root. The incident, observed by Mandiant and Google GTIG, resulted in management‑plane compromise, configuration exfiltration, and anti‑forensic cleanup, highlighting SD‑WAN controllers as high‑value targets for persistent privileged access.

CrowdStrike Falcon Sensor 'FalconFlank' Local Privilege Escalation LPE

The 'FalconFlank' zero-day exploit targets the CrowdStrike Falcon Sensor on Windows, facilitating Local Privilege Escalation (LPE) to NT AUTHORITY\SYSTEM. The vulnerability stems from a flaw in the sensor's remediation logic when processing malicious Microsoft Office macros, allowing an attacker with local access to bypass security controls on fully patched systems. A public Proof-of-Concept (PoC) was released on GitHub by researcher Chaotic Eclipse on September 3, 2026, without prior vendor coordination. This flaw enables full host compromise and potentially allows attackers to evade the sensor's detection and prevention capabilities.

GPUThor: Rowhammer Attack Bypasses ECC on NVIDIA RTX A-Series GPUs

University of Toronto researchers have demonstrated GPUThor, a sophisticated Rowhammer-based attack targeting GDDR6 memory architectures in NVIDIA Ampere workstation GPUs, specifically the RTX A4000 through A6000 series. By utilizing non-uniform row hammering patterns, the exploit induces multi-bit flips—specifically double and triple bit errors—that exceed the correction capabilities of standard Error Correction Code (ECC) mechanisms. This bypass allows an attacker to corrupt memory page tables, facilitating a transition from unprivileged program execution to host-level root shell access. The attack demonstrates a massive increase in efficiency, reducing exploit time from nearly 22 hours to approximately 1.1 minutes, posing a significant risk to multi-tenant AI/ML cloud environments and high-performance workstations.

Ubiquiti UniFi OS: Critical Multi-Stage Exploit Chain Identified

A collection of 21 critical vulnerabilities within the Ubiquiti UniFi OS and Networking Application enables a multi-stage exploit chain targeting enterprise network infrastructure. The attack surface involves authentication bypass via compromised UniFi OS API endpoints, followed by command injection within the Networking Application to achieve Remote Code Execution (RCE). Subsequent exploitation of vulnerabilities such as CVE-2026-47369 facilitates local-to-root privilege escalation, granting attackers full administrative control. These flaws permit unauthorized access, lateral movement, and complete system compromise. Organizations must prioritize firmware updates to neutralize these vectors and monitor for exploitation patterns reminiscent of long-tail vulnerabilities like Log4Shell.

ServiceNow AI Platform: Systemic Infrastructure Risk via Triple CVSS 10.0 Vulnerabilities

ServiceNow has disclosed three critical vulnerabilities (CVE-2026-18885, CVE-2026-18886, CVE-2026-74820) in its AI Platform, each scoring CVSS 10.0. These flaws allow unauthenticated, zero-interaction attackers to perform remote code execution (RCE) and arbitrary SQL injection (SQLi) against the underlying database. The vulnerabilities enable full instance compromise, including unauthorized data modification and administrative privilege escalation. The risks are amplified by the integration of AI agent workflows, which expand the attack surface and potential blast radius. Remediation requires immediate application of security updates via advisory KB3152242 for both hosted and on-premise installations.


LINK COPIED TO CLIPBOARD