TABLE OF CONTENT
This week’s intelligence highlights an intense wave of structural zero-day exploitation and advanced endpoint evasion techniques. Threat actors are weaponizing legitimate endpoint detection tools to bypass OS protections, exploiting zero-click memory corruption in ubiquitous video conferencing software, and compromising critical edge network appliances to dismantle multi-factor authentication.
SISA Weekly Threat Watch – our weekly feature brings to you a quick snapshot of all the major security vulnerabilities that posed a threat to organizations worldwide. These recurring actionable threat advisories will also provide information and recommendations that will help security teams take appropriate actions to defend against the latest and critical threats.
1. Defense Evasion & Zero-Day Endpoint Exploitation
Adversaries are actively bypassing and inverting endpoint security controls, using trusted EDR signatures and components as Trojan horses to bypass Windows Protected Process Light (PPL).
- ShieldBreak Zero-Day (Defender Patch Bypass) — A functional zero-day PoC named ShieldBreak completely bypasses Microsoft's incomplete August 2026 patch for CVE-2026-50656 (RoguePlanet). By exploiting unpatched thread-lock synchronization and memory pointer leaks in
mpengine.dll, local low-privileged users can instantly elevate to SYSTEM privileges and completely blind Microsoft Defender. - "Bring Your Own EDR" (BYOEDR) — Local administrators are abusing legitimate, signed SentinelOne Agents via an unvalidated COM interface (
SentinelHelper.1). Attackers can dump protected antimalware memory, extract COM secrets, and inject unsigned code into PPL-protected processes. Furthermore, they can use the EDR's own file tamper protection features to shield malicious payloads from manual termination. - Cisco ClamAV & Secure Endpoint DoS — Multiple high-severity vulnerabilities (such as CVE-2026-20337 and CVE-2026-20338) in ClamAV's file format parsers allow unauthenticated, remote attackers to trigger out-of-bounds writes or double-free memory corruption. By submitting specially crafted ZIP or PDF files for scanning, attackers can crash the scanning engine, creating a Denial of Service state that disables Cisco Secure Endpoint protection.
2. Edge Perimeter Collapse & Ransomware
The enterprise perimeter is under severe strain from automated credential harvesting and high-severity vulnerabilities targeting edge routing, secure gateways, and virtualization platforms.
- Gunra Ransomware Exploiting Fortinet VPNs — Gunra threat actors are actively exploiting critical authentication bypass vulnerabilities in internet-facing Fortinet VPNs (CVE-2024-55591 and CVE-2025-24472). Upon gaining super-admin privileges, attackers tamper with virtual desktop infrastructure (VDI) authentication portals to hardcode OTP values (bypassing MFA), extract NTDS hashes, and deploy cross-platform encryption payloads.
- Systemic Fortinet Ecosystem Vulnerabilities — Fortinet addressed multiple severe vulnerabilities across its suite. Most critically, CVE-2026-26035 allows an unauthenticated remote attacker to bypass administrative authentication on FortiWeb appliances configured with wildcard Remote RADIUS authentication. Additionally, a kernel driver heap overflow in FortiClient (CVE-2026-70465) poses severe operational risks.
- Zoom "Zoomsday" RCE & VMware vCenter Flaws — A critical zero-click memory corruption flaw (CVE-2026-53413/4/5) in Zoom's proprietary annotation protocol (
libannotate.so) allows attackers to execute arbitrary code on all meeting participants without user interaction. Concurrently, a directory traversal flaw in VMware vCenter Server (CVE-2026-59310) is undergoing active mass exploitation globally, allowing attackers to drop malicious cron jobs for persistence.
3. Enterprise Application & Infrastructure Privilege Escalation
Vulnerabilities deep within enterprise collaboration servers, Kubernetes orchestration, and legacy network peripherals are providing attackers with silent pathways to full domain control.
- Microsoft Exchange Server Critical RCE — Microsoft's Patch Tuesday addressed six key vulnerabilities in on-premises Exchange Servers. Most notably, CVE-2026-62913 (CVSS 8.8) is a network-accessible heap-based buffer overflow allowing unauthenticated RCE. Additionally, an authentication bypass via capture-replay (CVE-2026-62911) was publicly demonstrated at Pwn2Own, enabling unauthorized mailbox exfiltration.
- Red Hat ACM Privilege Escalation (CVE-2026-10090) — A critical flaw in Red Hat Advanced Cluster Management (ACM) allows an authenticated attacker with basic namespace-scoped edit permissions to bypass intent-based authorization controls. By deploying a custom Helm chart via the Application Subscription controller, attackers can force the creation of cluster-scoped resources (like
ClusterRoleBinding) to escalate to fullcluster-admin. - IoT Printers as Active Directory Pivots — Threat actors are actively exploiting unpatched IoT printers using default credentials. Once compromised, the printers' cleartext "Scan-to-Email" LDAP configurations are harvested, or the MS-RPRN Print Spooler interface is abused to coerce domain controller authentication, enabling Pass-the-Hash and DCSync attacks against Tier-0 AD infrastructure.
- Linux Kernel Network Scheduler LPE (CVE-2026-68138) — A race condition in the Linux kernel’s
net/schedtraffic control scheduler allows unprivileged local users to trigger a Use-After-Free condition via concurrent flower filter network requests, leading to kernel memory corruption or local Denial of Service.
Proactive Steps for the Week
- Harden Endpoint Detection and Response (EDR): Implement strict Least Privilege Access (LPA) to ensure standard users cannot weaponize
mpengine.dllusing the ShieldBreak zero-day exploit. Upgrade all SentinelOne Windows Agents to version 26.1.1+ to patch the unvalidated COM interface vulnerability. - Apply Edge & Virtualization Patches: Upgrade exposed FortiOS and FortiProxy units to fixed releases (e.g., FortiOS 7.0.17+, 7.2.7+) to resolve the active Gunra ransomware vectors. Deploy Zoom Workplace clients version 7.1.5 (or VDI version 7.0.11) to eliminate the zero-click "Zoomsday" RCE vector, and patch VMware vCenter (CVE-2026-59310) immediately.
- Secure Microsoft Exchange & Red Hat ACM: Deploy the August Microsoft Exchange Security Updates across all on-premises instances and verify the installation using the Exchange Health Checker. For Red Hat ACM hubs, strictly restrict namespace edit privileges to trusted administrators until CVE-2026-10090 errata are applied.
- Isolate Network Peripherals & Disable Print Spooler: Place all IoT printers on a dedicated, restricted VLAN. Disable the Print Spooler service (
spoolsv.exe) on all Domain Controllers to prevent authentication coercion attacks (MS-RPRN), and mandate LDAPS for all directory integrations. - Restrict Traffic Control & Network Namespaces: To mitigate the Linux Kernel
net/schedflaw (CVE-2026-68138), restrict raw netlink capabilities to trusted administrators and disable unprivileged user namespace cloning (sysctl -w kernel.unprivileged_userns_clone=0) until vendor kernel patches are applied.
Explore our DFIR Solutions to discover how our advanced incident response support, compromise assessments, and threat hunting frameworks can insulate your enterprise infrastructure against these campaigns.
.png)