CiberLATAMbywhalemate
Intelligence report

Critical Vulnerabilities and Active Exploitation, Sep 2026

September closed focused on actively exploited CVEs, especially SonicWall, GitLab, Fortinet, Adobe, and MikroTik, with heavy pressure in Brazil.

Oct 1, 202627 min read
Critical Vulnerabilities and Active Exploitation, Sep 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are automatically populated with verified dated facts from the period. Each one states its source base and counting criterion so the figures can be reconciled across modules. This is the recurring month-to-month readout; the later analysis develops the cases without repeating this summary.

Indicator window: 178 dated facts in September 2026 · 13 from prior months (comparative framework, not this month’s volume) · 2 without confirmed date (excluded from the indicators). Facts from prior months are used only as a comparative framework in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Verified Signal Monthly Dashboard September 2026 · Latin America Main threat: Vulnerabilities (130 of 177 events). Coverage: 178 dated events in September 2026 · 13 d… VERIFIED EVENTS 177 period base: all counts measured from the bottom over this total RANSOMWARE / EXTORTION 1 1 undetermined classification with the material UNTYPED INCIDENTS 13 breaches or outages without declared threat type FRAUD / PHISHING 9 documented fraud campaigns documented REGULATION 0 standards, rulings, or sanctions UNIQUE CVEs 43 CVE-2025-20265 / CVE-2025-23266
Verified Signal Monthly Dashboard — Base: 177 verified dated events for Latin America.
FIXED MONTHLY MODULE Distribution by threat axis September 2026 · Latin America Each event is counted in only one axis, so the total is exactly 177. "Unclassified incidents" is the remainder. Vulnerabilities 130 Unclassified 24 Incidents 13 Fraud 9 Ransomware 1
Distribution by threat axis — Each event is assigned to a single axis based on its classification; the total reconciles to the 177 events in the period.
MONTHLY FIXED MODULE Sectoral Distribution of Signal September 2026 · Latin America Base: 177 incidents in the period · total 268 because 80 incidents are classified in more than one sector. Technology 144 Public sector / OIV 61 Telecom 30 Other / unidentified sector 15 Retail / consumer 7 Finance 6 Healthcare 3 Energy 2
Sectoral Distribution of Signal — Heuristic classification by victim sector. One incident may affect more than one sector, so the total may exceed the base.
MONTHLY FIXED MODULE Geographic Distribution of Coverage September 2026 · Latin America Each event is assigned to a single country or regional coverage, so the total is exactly 177 of 177 events … USA 50 Chile 43 Brazil 41 Regional 19 Paraguay 11 Mexico 8 Colombia 5
Geographic Distribution of Coverage — Verified period events grouped by country or regional coverage; each event is counted only once.

Monthly executive summary

September 2026 left Latin America with a picture dominated by critical vulnerabilities with confirmed active exploitation, with 177 verified incidents in the material reviewed and 43 critical CVEs mentioned. The main burden fell on widely used software and infrastructure, with alerts and advisories from CTIR Gov, CISC, ECUCERT, and INCIBE-CERT setting the operational priority across the region, especially in Brazil and Ecuador.

The month was clearly technical and defensive in focus. The dominant threat was vulnerabilities, with 130 of the 177 incidents, and the corpus included notices on SonicWall SMA1000, GitLab, ConnectWise ScreenConnect, Fortinet, Adobe Commerce and Magento, MikroTik RouterOS, and Cisco Identity Services Engine, among others. The pattern repeated: patches were released, entries were added to the CISA KEV catalog, and in several cases active exploitation was confirmed by multiple independent sources.

The regional readout is one of high risk. Not because there was a single large outbreak, but because exploitation chains overlapped in products that are often exposed in hybrid perimeters, remote gateways, code repositories, access load balancers, and management platforms. That affects governments, service providers, cloud environments, and companies with broad attack surfaces, especially where updates are not immediate or there is dependence on legacy perimeter equipment.

Brazil accounted for the most visible part of the institutional response. CTIR Gov issued several alerts and recommendations on Adobe Commerce, Fortinet, SonicWall, Cisco Identity Services Engine, GitLab, and active SEO poisoning campaigns targeting .gov.br sites. CISC, meanwhile, brought together critical vulnerabilities from international vendors and explicitly identified cases of active exploitation, including Fortinet. That mix of official alerts and real-world campaigns shows a risk surface that did not remain in the lab or in abstract advisories.

Outside the Brazilian axis, Ecuador issued a specific alert on actively exploited MikroTik RouterOS, while international notices from CISA, Rapid7, Beazley, Censys, the Canadian Centre for Cyber Security, and others reinforced that the month was marked by urgent remediation and forensic triage. The material also points to a secondary signal of fraud and phishing, but the volume and severity were clearly below the vulnerability front.

Regional overview of the month

The region faced elevated risk, driven by a mix of technical severity, broad exposure, and confirmed active exploitation in products at the core of connectivity and administration. These were not isolated incidents, but a string of critical flaws in platforms that manage remote access, repositories, perimeter appliances, and cloud services, with potential cross-sector impact across government, industry, and digital services.

Brazil generated the most signal. CTIR Gov and CISC bulletins not only listed critical CVEs, they also turned them into operational decisions, from hotfixes and affected version ranges to active cloaking and SEO poisoning campaigns on government websites. That link between technical alert and mitigation procedure matters because it shortens the time between disclosure and containment, but it also shows how much regional defense depends on each agency's ability to patch quickly.

The month also confirmed that active exploitation was not limited to a single vendor. SonicWall, GitLab, Fortinet, ConnectWise, Adobe, and MikroTik appeared on different days and through different attack paths, but with the same effect, forcing teams to prioritize exposed assets and check for compromise after patching. In several sources, remediation went beyond applying the fix and included searching for intrusion indicators, reviewing credentials, and rebuilding forensic traces.

The severity picture also rises when you look at the maturity of the attack chains. In SonicWall SMA1000, exploitation was described as a chain of two flaws, one preauthentication and another command injection issue, which could lead to remote code execution. In GitLab, separate flaws allowed arbitrary file reading or code execution in self-managed instances. In MikroTik, the issue combined authentication bypass and privilege escalation, with exploitation already observed on the internet. That points to campaigns seeking persistence and control, not just noisy scanning.

CHRONOLOGY Verified events in the period 1/9 Aindependentanalysisin 1/9 The Canadianadvisoryidentifies 1/9 The advisoryfrom SonicWall 1/9 SonicWall issuedthe advisory 1/9 CISA addedCVE-2026-82329to the 1/9 CiberPlanetreportsthatCISA
Chronology of verified events, September 2026 — Confirmed milestones within September 2026. Events from earlier months are outside the chronology and are used only as a comparative frame.

Period indicators

The table below reproduces the month's measurement base as provided, without adding telemetry to incidents or reinterpreting categories. The comparison with the previous month is meant to show the direction of movement, not to recalculate September's volume.

Indicator September 2026 Previous month Change
Verified events in the period (base for all indicators) 177 344 -167
Time window for the indicators 178 events dated September 2026, 13 from prior months, 2 without confirmed dates excluded from the indicators
Unclassified incidents (breaches or disruptions) 13 14 -1
Cases with ransomware or extortion as the primary focus 1 0 +1
Breakdown of ransomware by impact type Classification could not be determined from the material: 1
Documented fraud or phishing cases 9 30 -21
Documented regulatory moves 0 0 unchanged
Critical CVEs mentioned 43 83 -40
Sectors with at least one documented event 8 8 unchanged
Main threat of the month Vulnerabilities (130 of 177 events) Vulnerabilities (281 of 344 events)
Events directly confirmed by the source 97%
Aggregated telemetry figures excluded from the volume 1 (aggregated attempts or blocks, not incidents with confirmed impact)

The period base shows a sharp drop in volume from the previous month, but not a uniform easing of risk. Verified events fell, critical CVEs mentioned fell, and documented fraud fell, although the leading threat remained the same. In other words, there were fewer items in the corpus, but technical pressure remained concentrated on exploited vulnerabilities or ones prioritized by official agencies.

Relevant Incidents

SonicWall SMA1000, chained zero-days and active exploitation

September delivered one of the clearest signals of the month in SonicWall SMA1000. The emergency advisory SNWLID-2026-0016, published on September 1, disclosed the zero-days CVE-2026-83548 and CVE-2026-83549, and several sources later described them as an actively exploited chain. The first was presented as an unauthenticated SSRF in the WorkPlace interface, while the second affected the Appliance Management Console and could be chained to achieve remote code execution.

The operational significance of this case lies in where it sits. SMA1000 devices are used as remote access and administration appliances, so a flaw there does not compromise a minor peripheral application, but an entry point into sensitive systems. The reporting also agrees that exploitation was active and that the response should not stop at patching. It also had to include credential review, remote access review, and checks for possible prior compromise.

Brazil moved quickly on this signal at the institutional level. CTIR Gov published Alert 79/2026 and later 80/2026 to detail affected versions and the availability of hotfixes. That reflects a typical decision by government teams in the region, where risk is measured not only by CVSS severity but by the ability to stop remote access before exploitation reaches internal components or administrative data.

GitLab self-managed, arbitrary file reading and code execution

GitLab took a central place in September’s remediation front. On September 11, CISA added CVE-2026-85706 to the KEV catalog, and in the second half of the month the picture hardened with notices from Beazley, Rapid7, Censys, the Canadian Centre for Cyber Security and INCIBE-CERT. The vulnerability affected self-managed GitLab CE and EE instances and allowed arbitrary reading of files accessible to the service account.

GitLab’s second round of patches, published on September 23, added other critical issues, including CVE-2026-89078 and CVE-2026-93577, both capable of arbitrary code execution under certain conditions. The main operational point for the region is that the GitLab stack is often integrated with CI/CD, code repositories and automated deployment, so a flaw of this kind does not just expose secrets. It can also open the door to pipeline and artifact tampering.

The case has special impact in Latin America because many medium and large organizations run GitLab in self-managed mode to avoid depending on external SaaS or because of operational sovereignty requirements. That raises the burden on local patching, service account control, secret backups and credential rotation. If a GitLab instance is reachable from internal networks or the internet, the exposure window becomes critical very quickly.

Fortinet, authentication bypass and cloud exposure

Fortinet appeared on several fronts, at different levels of detail. CTIR Gov published Alert 86/2026 on CVE-2025-25249 in FortiOS and FortiSwitchManager, and CISC included an active authentication bypass associated with CVE-2025-20265. At the same time, the Brazilian bulletin of September 22 added cloud products such as FortiSandbox Cloud and FortiSandbox PaaS, expanding the surface beyond the traditional on-prem appliance.

The reading here is twofold. On one side, there is continuing pressure on Fortinet devices and services, with active exploitation and KEV catalogs forcing prioritization. On the other, the risk is no longer confined to physical network boxes, because several of the listed vulnerabilities affect cloud or hybrid components. That matters in the region, where many deployments mix perimeter security, public cloud integration and centralized administration.

CISC’s bulletin on active exploitation of authentication bypass in Fortinet confirms that the mere presence of a patch is not enough if the device is already compromised or if the team does not review logs, accounts and sessions. For Latin American teams, especially in government and telecommunications, this kind of case requires treating the appliance as a possible persistence point, not just a maintenance task.

Adobe Commerce and Magento, KEV addition and signs of exploitation

CVE-2026-71362 in Adobe Commerce and Magento was another relevant piece of the month. Rescana indicated that Adobe had fixed the flaw through APSB26-92 on August 11, but CISA added it to the KEV catalog on September 24. BleepingComputer and The Hacker News agreed that Sansec observed exploitation, and CTIR Gov published two alerts, one for the vulnerability and another for its presence in KEV.

The sensitive point is not only the technical severity, with CVSS 9.1, but the exploitation profile. According to the material, it did not require an existing account, administrative privileges or user interaction. That makes it especially dangerous in e-commerce and service portals that expose Adobe Commerce or Magento to the internet, a common scenario in the region for retail, payments and marketplaces.

Brazil again responded quickly at the institutional level. CTIR Gov’s publication confirms that the case was considered relevant for government environments, but the risk goes beyond the public sector. Any organization that relies on e-commerce with exposed modules, third-party integrations or delayed deployments should read this case as a warning about direct exposure, not as a single-vendor incident.

MikroTik RouterOS, MikroTrick and router takeover

Ecuador provided one of the region’s most concrete alerts on network infrastructure. ECUCERT published AL-2026-046 on critical vulnerabilities in MikroTik RouterOS that were actively exploited, identified as CVE-2026-67276, CVE-2026-86060 and CVE-2026-67277. The same line was reinforced by Kaspersky, DIVD, NICS-TW and other technical sources, which described an exploitation chain associated with MikroTrick.

The risk here is the classic one for routers exposed to the internet, but with a more worrying component, persistence and hiding. The material mentions hidden persistence accounts on compromised routers and a combination of SSH authentication bypass with parsing bugs or privilege escalation. That enables takeover, not just denial of service or scan noise.

For the region, the case matters because MikroTik has a wide presence among small operators, regional ISPs, SMEs and environments where network administration does not always include continuous monitoring. Active exploitation on those devices can lead to traffic redirection, access to internal networks or use of the router as a pivot. This is not an abstract lab problem, but a path to edge compromise.

ConnectWise ScreenConnect, KEV and post-patch response

CVE-2026-84869 in ConnectWise ScreenConnect added another alert for active exploitation. CISA confirmed the activity, ConnectWise recommended updating to version 26.6.5 or later and reviewing clients and agents after patching, and Rescana reported its addition to KEV. The detail matters because ScreenConnect is often part of legitimate remote support and administration tooling, exactly the kind of software an attacker would try to abuse for discreet movement.

The recommendation to review clients and agents after patching is a clear sign that remediation does not end with installing the new version. When a remote access tool appears in KEV, the priority shifts toward auditing sessions, authentications and managed devices. In Latin America, where this type of tool is widely used by providers, outsourced support and distributed operations, the potential reach is high.

Issabel, unauthenticated command execution

CEVIU reported real-world exploitation of an Issabel framework vulnerability observed by the Shadowserver Foundation since September 9. The available material does not provide the exact CVE, but it clearly shows unauthenticated command execution. Even without a concrete identifier, the case adds to the pattern of administration or communications products with immediate operational exposure.

Issabel has regional presence because it is used in IP telephony and enterprise communications environments. For that reason, even without the exact CVE, the alert deserves follow-up. If a platform of this kind allows unauthenticated command execution, the impact can include call manipulation, configuration theft or pivoting into internal segments. The absence of an identifier does not reduce the relevance of the finding, it only limits technical correlation.

Active threats and campaigns

Ransomware and extortion

September reporting identified only one case in which ransomware or extortion was the primary focus, but the source did not specify whether it involved asset encryption, data exfiltration without encryption, or only a mention on a leak site. That lack of detail prevents a more precise classification and means the case should be treated as an incomplete signal, not as a broader monthly pattern.

Operationally, that matters because a single ransomware label can mask very different impacts. Losing system availability is not the same as facing data extortion without encryption. Since the corpus does not separate those scenarios, this month’s analysis focuses on exploited vulnerabilities rather than on a true ransomware wave.

Fraud and phishing

The corpus recorded 9 documented fraud or phishing cases, down from 30 the previous month. The drop does not mean the problem disappeared, but it does confirm that in September the center of gravity shifted toward technical exploitation of vulnerabilities and campaigns against critical infrastructure. The most visible case was CTIR Gov Recommendation 17/2026 on SEO poisoning in .gov.br sites.

That campaign deserves attention because it went beyond classic phishing. The material describes cloaking against search engine bots, injected links to illegal gambling and casino sites, and the need to reset database, API, certificate, and administrative panel credentials. In other words, fraud overlapped with intrusion and manipulation of government websites.

APT, persistent intrusion, and infrastructure abuse

The material did not identify any case as a classic APT with solid attribution to a persistent group, but it did include campaigns with persistence, infrastructure abuse, and covert control. MikroTrick on MikroTik, SEO poisoning in .gov.br, and abuse of remote access tools such as ScreenConnect fit this broader category of campaigns that prioritize attacker continuity.

There is also an infrastructure vector that is difficult to neutralize, such as KREMLIN’s command-and-control infrastructure update through Ethereum smart contracts. The material itself makes clear that KREMLIN has no CVE and no KEV entry, so it should not be confused with an exploited vulnerability. Even so, it is a signal of campaigns designed for operational resilience and evasion of blocking.

Critical vulnerabilities

The table below consolidates the CVEs and the exploitation or prioritization status cited in the material reviewed. It excludes cases without an exact identifier, although those are mentioned in prose in earlier sections.

CVE Software Exploitation Source
CVE-2026-83548 SonicWall SMA1000 Active exploitation, unauthenticated SSRF, can be chained for RCE SonicWall, ProjectDiscovery, Quasa, CISA via cited sources
CVE-2026-83549 SonicWall SMA1000 Active exploitation, OS command injection, part of an RCE chain SonicWall, Ayinedjimi Consultants, SecurityArsenal
CVE-2026-85706 GitLab CE and EE self-managed Exploited in the wild, arbitrary file read Rapid7, Beazley Security Labs, Censys, Canadian Centre for Cyber Security
CVE-2026-84869 ConnectWise ScreenConnect Active exploitation confirmed by CISA Aviatrix Threat Research Center, Rescana
CVE-2026-71362 Adobe Commerce and Magento Observed exploitation, added to CISA KEV Rescana, BleepingComputer, The Hacker News, CTIR Gov
CVE-2025-25249 Fortinet FortiOS and FortiSwitchManager Listed in CISA KEV according to CTIR Gov CTIR Gov
CVE-2025-20265 Fortinet devices Active exploitation of authentication bypass CISC
CVE-2026-93616 Multiple products, according to CTIR Gov Listed in CISA KEV according to official alert CTIR Gov
CVE-2026-67276 MikroTik RouterOS Active exploitation in the MikroTrick chain ECUCERT, Kaspersky, DIVD, NICS-TW
CVE-2026-86060 MikroTik RouterOS Active exploitation, privilege escalation and takeover ECUCERT, Kaspersky, NICS-TW, DIVD
CVE-2026-67277 MikroTik RouterOS Vulnerability included in an active exploitation alert ECUCERT, Kaspersky
CVE-2026-89078 GitLab CE and EE self-managed Arbitrary code execution under certain conditions CVE.org, GitLab, Forest Watch
CVE-2026-93577 GitLab CE and EE self-managed Arbitrary code execution under certain conditions CVE.org, GitLab, Forest Watch
CVE-2026-92530 GitLab Direct Transfer Author spoofing in imports, no active exploitation described CVE.org

The universe of critical CVEs was not limited to these identifiers. The material also mentions flaws in Cisco Identity Services Engine, Cisco Secure Email Gateway, NGINX, 7-Zip and WSO2, but without a uniform list of active exploitation comparable to the main block above. For that reason, this table prioritizes only the cases where the link to exploitation, KEV or an official alert is explicitly supported.

Regulation and compliance

September did not show formal regulatory moves in the strict sense of the metric, but it did bring intense institutional response activity. CTIR Gov and CISC issued alerts and bulletins, ECUCERT published a specific alert, and INCIBE-CERT released notices on GitLab and other applications. In practice, the month looked more like an accelerated operational compliance cycle than a change in regulation.

In Brazil, the response included alerts, bulletins, and technical recommendations that drilled down into specific remediation steps. Recomendação 17/2026 called for deindexing routes, redefining credentials, and reporting anomalous activity. The alerts on Adobe Commerce, Fortinet, SonicWall, and Cisco Identity Services Engine point to the same logic: prioritize remediation, review exposure, and, in some cases, treat the incident as a potential compromise.

These kinds of documents do not create a new legal rule, but they do function as a de facto standard for state teams and vendors that work with government. In Latin America, where national response bodies often guide multiple sectors, these notices carry practical weight similar to a compliance circular, even if they remain technical in nature.

Most affected countries in Latin America

Brazil

Brazil accounted for the largest amount of verifiable signal this month. CTIR Gov issued alerts on SonicWall SMA1000, Adobe Commerce and Magento, Fortinet, Cisco Identity Services Engine, and GitLab, along with a recommendation on SEO poisoning in .gov.br sites. CISC also published bulletins on vulnerabilities in Microsoft, Fortinet, Commvault, Check Point, NGINX, and 7-Zip.

The Brazilian picture has two layers. The first is technical prioritization, because much of the material is focused on patching and KEV catalogs. The second is exposed surface, because several issues involve cloud services, automated repositories, remote administration, and public government sites. The result is a high-risk signal for public agencies, vendors, and companies with hybrid infrastructure.

Ecuador

Ecuador issued a specific and operationally valuable alert on MikroTik RouterOS being actively exploited. ECUCERT not only named the CVEs, it framed the issue as active exploitation, which means exposed routers must be treated as assets that may already be compromised, not simply as devices to update when possible.

This is especially relevant for connectivity providers, SMEs, and edge networks. In environments where MikroTik serves as a router, firewall, or access concentrator, active exploitation can enable persistence, traffic redirection, or movement into internal segments. The Ecuadorian alert aligns with the broader international technical ecosystem and reinforces the urgency of review.

Mexico

Mexico appears in the material mainly through web applications, cloud, and service exposure. Ciberseguridad LATAM coverage notes that in Brazil and Mexico, sectors such as digital payments and digital health operate applications integrated with AWS, Azure, and Google Cloud, with GitHub or GitLab repositories configured for automatic deployment without manual review. That is not a specific Mexican incident, but it is a useful frame for reading local risk.

For this report, Mexico also appears through references to companies and services in the regional market where attack surface depends on automated integrations and repositories connected to production. The available material does not allow for a claim of incident concentration in the country, but it does suggest exposure comparable to other regional markets that rely on DevOps and cloud.

Colombia

Colombia enters the corpus mainly through uncategorized items and incident cases in digital services, although the material analyzed does not provide a critical vulnerability case there with the same density as in Brazil or Ecuador. The lack of strong signal should not be read as absence of risk, but as a limit of the available corpus for the month.

The ICETEX case, although outside this thematic vertical because it was a provider security incident, reinforces the region's dependence on third parties and external services. In a critical vulnerability reading, that matters because many exploitations end up affecting organizations that do not directly control the compromised infrastructure.

Paraguay

Paraguay appears mainly through CERT.PY activity and the regional bulletin context. The material provided includes advisories on MISP and WordPress plugins, but without confirmed dates, so they are not included in the month’s indicators. Even so, they show institutional interest in common attack surfaces that are often relevant for mid-sized organizations.

In the regional comparison, Paraguay does not concentrate verifiable incidents at the same scale as Brazil or Ecuador. That does not reduce the value of its advisories, but it does limit the ability to build a narrative of active exploitation with enough volume for this report. The signal is one of monitoring, not prevalence.

Argentina

There were not enough verifiable facts in the material to build a specific reading for Argentina within this vertical. That does not imply absence of exposure to critical vulnerabilities, only that the September corpus did not provide a case with confirmed date and scope comparable to those in Brazil or Ecuador.

Chile

There were also not enough verifiable facts for Chile in the September corpus analyzed for this topic. The available material does not support a country trend, although that does not rule out exposure to the same products and exploitation chains seen in other regional markets.

Peru

There were not enough verifiable facts for Peru in the period analyzed. The report does not attribute that absence to lower real risk, only to the specific coverage in the material received.

Bolivia

There were no sufficient verifiable facts for Bolivia in the September material. The regional signal that does appear, especially in perimeter appliances and administration software, is equally relevant for Bolivian environments, but it cannot be documented here with a concrete local case.

United States

Although it is not part of Latin America, the United States appears as a background reference in nearly every prioritization process through CISA KEV. Remediation deadlines for U.S. federal agencies, such as September 14 or 27, helped define urgency for regional vendors and CERTs. In this report, it is used only as a comparative frame for active exploitation and remediation.

Compared with the previous month, the total volume fell sharply, from 344 to 177 verified incidents, and the number of critical CVEs mentioned dropped from 83 to 43. Even so, the operational signal did not ease by the same margin, because vulnerabilities remained the main threat and multiple cases were confirmed as actively exploited by several sources.

August brought a higher volume and multiple high-impact infrastructure cases. September had less noise, but the signal was more focused on urgent remediation and prioritizing exposed assets. That often happens when the ecosystem shifts from a cycle of broad disclosure to one of confirmed exploitation and institutional response.

The first signal to watch is the persistence of multi-CVE chains in perimeter devices. SonicWall SMA1000 and MikroTik RouterOS show that attackers are still looking for combinations of bypass, SSRF, command injection, and privilege escalation. When those flaws are combined, an attacker does not need a more sophisticated vector to move from initial access to device control.

The second signal is the pressure on development and deployment platforms. GitLab made clear that self-managed environments remain a high-value target because they bring together secrets, pipelines, service credentials, and automation. In the region, where many companies and public agencies use GitLab as a delivery backbone, that means reviewing not only versions but also exposure, permissions, and the traceability of imports or CI/CD.

The third signal is that regional advisories are no longer limited to on-prem software. Fortinet, Commvault Cloud, FortiSandbox Cloud, Microsoft, and other examples show a shift toward cloud and hybrid services. That requires Latin American teams to pair local remediation with control over identity, credentials, pipelines, and sessions. If only the appliance is reviewed, part of the risk is missed.

ComparisonIncidentsPrevious month incidentsCVEsPrevious month CVEsFraudPrevious month fraud1773444383930Visual scale, no telemetry
Monthly comparison of verified signal — Volume of verified incidents, critical CVEs, and fraud/phishing, comparing September with the previous month according to the provided dataset.

Security team recommendations

First, prioritize patches and compromise review for assets that appeared in KEV or in official alerts during the month. That includes SonicWall SMA1000, GitLab self-managed, ConnectWise ScreenScreenConnect, Adobe Commerce and Magento, MikroTik RouterOS, and the Fortinet products mentioned in official advisories. In these cases, applying the update is not enough, because several sources called for account, agent, session, and forensic trace review.

Second, review direct internet exposure for administration tools, repositories, and support portals. If GitLab, ScreenConnect, remote access appliances, or management interfaces are exposed, priority should rise immediately. The risk is not only the vulnerability itself, but also the combination of public accessibility, reused credentials, and automated deployment or support workflows.

Third, strengthen monitoring of credentials and secrets. The GitLab exploitation, SEO poisoning in .gov.br, and abuse of remote tools show that an intrusion can end in theft of tokens, API keys, certificates, and administrative panel passwords. Rotating credentials without reviewing the scope of exposure can leave active persistence in place.

Fourth, add post-patch compromise hunting. In SonicWall, ConnectWise, and Fortinet, the material stresses that patching does not automatically close the incident. Logs, configuration changes, active sessions, hidden accounts, access rules, and persistence artifacts need to be reviewed. That matters especially for edge devices and remote support platforms.

Fifth, treat network and security appliances as highly critical operational assets. MikroTik and SonicWall show that the network edge remains a primary target, and that a compromised router or gateway can have a broader impact than an isolated workstation. The response plan should include secure rebooting, restoration from a known-good configuration, and integrity validation.

Sixth, align regional prioritization with official CERT and CSIRT advisories. In Latin America, CTIR Gov, CISC, and ECUCERT acted as amplifiers of urgency and local context. When those organizations issue alerts about a CVE, the organization should translate that into an internal action with an owner, a deadline, and closure evidence. Otherwise, the alert remains informational reading rather than a control.

Frequently Asked Questions

Which countries had the strongest signal this month, and why?

Brazil and Ecuador had the clearest signal. Brazil concentrated official alerts on SonicWall, Adobe, Fortinet, GitLab, and active campaigns against .gov.br sites. Ecuador, meanwhile, issued a specific alert on MikroTik RouterOS that was actively exploited. Coverage for the rest of the countries was more scattered or lacked a confirmed date.

What was the difference between the Brazil and Ecuador material?

Brazil combined bulletins, recommendations, and active campaigns involving several vendors, along with alerts on SEO poisoning and cloud. Ecuador had a more focused but very clear case involving MikroTik RouterOS with confirmed active exploitation. The difference was breadth in Brazil and operational precision in Ecuador.

What changed between August and September in critical vulnerabilities?

The total volume of verified incidents fell, and so did the number of critical CVEs mentioned. Even so, the main threat remained vulnerabilities, and several cases were still confirmed as actively exploited. August had more noise, while September had less volume but a sharper focus on remediation and prioritization.

Which products should Latin American teams review first?

They should first review SonicWall SMA1000, GitLab self-managed, ConnectWise ScreenConnect, Adobe Commerce and Magento, Fortinet, MikroTik RouterOS, and, where applicable, Cisco Identity Services Engine. The priority comes from the combination of active exploitation, presence in KEV, and broad use across regional infrastructure.

Did the report record ransomware as the main trend?

No. Only one case appeared with ransomware or extortion as the primary focus, but the material did not specify whether there was encryption, exfiltration without encryption, or only a mention on a leak site. The month’s main trend was clearly vulnerabilities, not extortion. The threats and active campaigns section covers it in more detail.

Which official alerts should government teams read first?

In Brazil, the CTIR Gov alerts on SonicWall, Adobe Commerce, Fortinet, GitLab, and Recomendação 17/2026 on SEO poisoning. In Ecuador, the ECUCERT alert on MikroTik RouterOS. Those documents combine active exploitation, operational impact, and concrete mitigation steps.

Material limitations

This report was built exclusively from the material provided for September 2026 and from the comparative framework for prior months included in the file. There was no access to the internet or to sources outside the authorized list. As a result, several technical references are limited to what each source described, rather than to any additional independent verification.

The time window for the indicators was based on 178 dated facts from September 2026, 13 facts from prior months used only as comparative context, and 2 undated facts excluded from the indicators. The undated facts, such as CERT.gov.py notices about MISP and WordPress plugins, may be used as qualitative context, but they are not part of the monthly volume.

A zero indicator means it did not appear in the September material analyzed, not that the phenomenon did not occur in the region. This applies in particular to regulatory developments and the breakdown of some categories. It also applies to CVEs, if the material does not record a given case, that does not rule out the possibility that it existed outside the available corpus.

Aggregated telemetry was handled separately and was not added to incidents. In this report, it is mentioned only as a point of reference when the source makes clear that they are attempted or automated blocks, not confirmed intrusions. Sponsored content, consumer social media, and posts outside the list of available sources were also not used as evidence of trend.

Countries without enough verifiable facts, or with insufficient material to support a local reading, were left out of volume statements. That does not mean there was no risk, only a documentation coverage limitation for the period.

Sources