Critical Vulnerabilities and Active Exploitation, Sep 2026
September closed focused on actively exploited CVEs, especially SonicWall, GitLab, Fortinet, Adobe, and MikroTik, with heavy pressure in Brazil.
Key findings
- The dominant signal in September was active exploitation of vulnerabilities, with 130 of 177 verified incidents focused on that theme.
- Brazil concentrated the most intense institutional response, with alerts and guidance on SonicWall, Adobe, Fortinet, GitLab, and SEO poisoning in .gov.br.
- Ecuador issued a specific alert on MikroTik RouterOS being actively exploited, with potential impact on routers and edge networks.
- GitLab, SonicWall, ConnectWise, Adobe Commerce, Fortinet, and MikroTik were the month’s most sensitive names because of the combination of KEV, active exploitation, and regional use.
- The drop in volume from August did not mean a proportional reduction in risk, because the quality of the signal remained critical.
- Fraud and phishing decreased versus the previous month, but appeared mixed with intrusion and web manipulation in the Brazilian SEO poisoning campaign.
- The material did not allow a precise classification of a ransomware or extortion case, so that category remained an incomplete signal rather than a primary trend.
Monthly reference modules
These modules are automatically populated with verified dated facts from the period. Each one states its source base and counting criterion so the figures can be reconciled across modules. This is the recurring month-to-month readout; the later analysis develops the cases without repeating this summary.
Indicator window: 178 dated facts in September 2026 · 13 from prior months (comparative framework, not this month’s volume) · 2 without confirmed date (excluded from the indicators). Facts from prior months are used only as a comparative framework in the analysis, never as volume for this period.
Monthly executive summary
September 2026 left Latin America with a picture dominated by critical vulnerabilities with confirmed active exploitation, with 177 verified incidents in the material reviewed and 43 critical CVEs mentioned. The main burden fell on widely used software and infrastructure, with alerts and advisories from CTIR Gov, CISC, ECUCERT, and INCIBE-CERT setting the operational priority across the region, especially in Brazil and Ecuador.
The month was clearly technical and defensive in focus. The dominant threat was vulnerabilities, with 130 of the 177 incidents, and the corpus included notices on SonicWall SMA1000, GitLab, ConnectWise ScreenConnect, Fortinet, Adobe Commerce and Magento, MikroTik RouterOS, and Cisco Identity Services Engine, among others. The pattern repeated: patches were released, entries were added to the CISA KEV catalog, and in several cases active exploitation was confirmed by multiple independent sources.
The regional readout is one of high risk. Not because there was a single large outbreak, but because exploitation chains overlapped in products that are often exposed in hybrid perimeters, remote gateways, code repositories, access load balancers, and management platforms. That affects governments, service providers, cloud environments, and companies with broad attack surfaces, especially where updates are not immediate or there is dependence on legacy perimeter equipment.
Brazil accounted for the most visible part of the institutional response. CTIR Gov issued several alerts and recommendations on Adobe Commerce, Fortinet, SonicWall, Cisco Identity Services Engine, GitLab, and active SEO poisoning campaigns targeting .gov.br sites. CISC, meanwhile, brought together critical vulnerabilities from international vendors and explicitly identified cases of active exploitation, including Fortinet. That mix of official alerts and real-world campaigns shows a risk surface that did not remain in the lab or in abstract advisories.
Outside the Brazilian axis, Ecuador issued a specific alert on actively exploited MikroTik RouterOS, while international notices from CISA, Rapid7, Beazley, Censys, the Canadian Centre for Cyber Security, and others reinforced that the month was marked by urgent remediation and forensic triage. The material also points to a secondary signal of fraud and phishing, but the volume and severity were clearly below the vulnerability front.
Regional overview of the month
The region faced elevated risk, driven by a mix of technical severity, broad exposure, and confirmed active exploitation in products at the core of connectivity and administration. These were not isolated incidents, but a string of critical flaws in platforms that manage remote access, repositories, perimeter appliances, and cloud services, with potential cross-sector impact across government, industry, and digital services.
Brazil generated the most signal. CTIR Gov and CISC bulletins not only listed critical CVEs, they also turned them into operational decisions, from hotfixes and affected version ranges to active cloaking and SEO poisoning campaigns on government websites. That link between technical alert and mitigation procedure matters because it shortens the time between disclosure and containment, but it also shows how much regional defense depends on each agency's ability to patch quickly.
The month also confirmed that active exploitation was not limited to a single vendor. SonicWall, GitLab, Fortinet, ConnectWise, Adobe, and MikroTik appeared on different days and through different attack paths, but with the same effect, forcing teams to prioritize exposed assets and check for compromise after patching. In several sources, remediation went beyond applying the fix and included searching for intrusion indicators, reviewing credentials, and rebuilding forensic traces.
The severity picture also rises when you look at the maturity of the attack chains. In SonicWall SMA1000, exploitation was described as a chain of two flaws, one preauthentication and another command injection issue, which could lead to remote code execution. In GitLab, separate flaws allowed arbitrary file reading or code execution in self-managed instances. In MikroTik, the issue combined authentication bypass and privilege escalation, with exploitation already observed on the internet. That points to campaigns seeking persistence and control, not just noisy scanning.
Period indicators
The table below reproduces the month's measurement base as provided, without adding telemetry to incidents or reinterpreting categories. The comparison with the previous month is meant to show the direction of movement, not to recalculate September's volume.
| Indicator | September 2026 | Previous month | Change |
|---|---|---|---|
| Verified events in the period (base for all indicators) | 177 | 344 | -167 |
| Time window for the indicators | 178 events dated September 2026, 13 from prior months, 2 without confirmed dates excluded from the indicators | ||
| Unclassified incidents (breaches or disruptions) | 13 | 14 | -1 |
| Cases with ransomware or extortion as the primary focus | 1 | 0 | +1 |
| Breakdown of ransomware by impact type | Classification could not be determined from the material: 1 | ||
| Documented fraud or phishing cases | 9 | 30 | -21 |
| Documented regulatory moves | 0 | 0 | unchanged |
| Critical CVEs mentioned | 43 | 83 | -40 |
| Sectors with at least one documented event | 8 | 8 | unchanged |
| Main threat of the month | Vulnerabilities (130 of 177 events) | Vulnerabilities (281 of 344 events) | |
| Events directly confirmed by the source | 97% | ||
| Aggregated telemetry figures excluded from the volume | 1 (aggregated attempts or blocks, not incidents with confirmed impact) |
The period base shows a sharp drop in volume from the previous month, but not a uniform easing of risk. Verified events fell, critical CVEs mentioned fell, and documented fraud fell, although the leading threat remained the same. In other words, there were fewer items in the corpus, but technical pressure remained concentrated on exploited vulnerabilities or ones prioritized by official agencies.
Relevant Incidents
SonicWall SMA1000, chained zero-days and active exploitation
September delivered one of the clearest signals of the month in SonicWall SMA1000. The emergency advisory SNWLID-2026-0016, published on September 1, disclosed the zero-days CVE-2026-83548 and CVE-2026-83549, and several sources later described them as an actively exploited chain. The first was presented as an unauthenticated SSRF in the WorkPlace interface, while the second affected the Appliance Management Console and could be chained to achieve remote code execution.
The operational significance of this case lies in where it sits. SMA1000 devices are used as remote access and administration appliances, so a flaw there does not compromise a minor peripheral application, but an entry point into sensitive systems. The reporting also agrees that exploitation was active and that the response should not stop at patching. It also had to include credential review, remote access review, and checks for possible prior compromise.
Brazil moved quickly on this signal at the institutional level. CTIR Gov published Alert 79/2026 and later 80/2026 to detail affected versions and the availability of hotfixes. That reflects a typical decision by government teams in the region, where risk is measured not only by CVSS severity but by the ability to stop remote access before exploitation reaches internal components or administrative data.
GitLab self-managed, arbitrary file reading and code execution
GitLab took a central place in September’s remediation front. On September 11, CISA added CVE-2026-85706 to the KEV catalog, and in the second half of the month the picture hardened with notices from Beazley, Rapid7, Censys, the Canadian Centre for Cyber Security and INCIBE-CERT. The vulnerability affected self-managed GitLab CE and EE instances and allowed arbitrary reading of files accessible to the service account.
GitLab’s second round of patches, published on September 23, added other critical issues, including CVE-2026-89078 and CVE-2026-93577, both capable of arbitrary code execution under certain conditions. The main operational point for the region is that the GitLab stack is often integrated with CI/CD, code repositories and automated deployment, so a flaw of this kind does not just expose secrets. It can also open the door to pipeline and artifact tampering.
The case has special impact in Latin America because many medium and large organizations run GitLab in self-managed mode to avoid depending on external SaaS or because of operational sovereignty requirements. That raises the burden on local patching, service account control, secret backups and credential rotation. If a GitLab instance is reachable from internal networks or the internet, the exposure window becomes critical very quickly.
Fortinet, authentication bypass and cloud exposure
Fortinet appeared on several fronts, at different levels of detail. CTIR Gov published Alert 86/2026 on CVE-2025-25249 in FortiOS and FortiSwitchManager, and CISC included an active authentication bypass associated with CVE-2025-20265. At the same time, the Brazilian bulletin of September 22 added cloud products such as FortiSandbox Cloud and FortiSandbox PaaS, expanding the surface beyond the traditional on-prem appliance.
The reading here is twofold. On one side, there is continuing pressure on Fortinet devices and services, with active exploitation and KEV catalogs forcing prioritization. On the other, the risk is no longer confined to physical network boxes, because several of the listed vulnerabilities affect cloud or hybrid components. That matters in the region, where many deployments mix perimeter security, public cloud integration and centralized administration.
CISC’s bulletin on active exploitation of authentication bypass in Fortinet confirms that the mere presence of a patch is not enough if the device is already compromised or if the team does not review logs, accounts and sessions. For Latin American teams, especially in government and telecommunications, this kind of case requires treating the appliance as a possible persistence point, not just a maintenance task.
Adobe Commerce and Magento, KEV addition and signs of exploitation
CVE-2026-71362 in Adobe Commerce and Magento was another relevant piece of the month. Rescana indicated that Adobe had fixed the flaw through APSB26-92 on August 11, but CISA added it to the KEV catalog on September 24. BleepingComputer and The Hacker News agreed that Sansec observed exploitation, and CTIR Gov published two alerts, one for the vulnerability and another for its presence in KEV.
The sensitive point is not only the technical severity, with CVSS 9.1, but the exploitation profile. According to the material, it did not require an existing account, administrative privileges or user interaction. That makes it especially dangerous in e-commerce and service portals that expose Adobe Commerce or Magento to the internet, a common scenario in the region for retail, payments and marketplaces.
Brazil again responded quickly at the institutional level. CTIR Gov’s publication confirms that the case was considered relevant for government environments, but the risk goes beyond the public sector. Any organization that relies on e-commerce with exposed modules, third-party integrations or delayed deployments should read this case as a warning about direct exposure, not as a single-vendor incident.
MikroTik RouterOS, MikroTrick and router takeover
Ecuador provided one of the region’s most concrete alerts on network infrastructure. ECUCERT published AL-2026-046 on critical vulnerabilities in MikroTik RouterOS that were actively exploited, identified as CVE-2026-67276, CVE-2026-86060 and CVE-2026-67277. The same line was reinforced by Kaspersky, DIVD, NICS-TW and other technical sources, which described an exploitation chain associated with MikroTrick.
The risk here is the classic one for routers exposed to the internet, but with a more worrying component, persistence and hiding. The material mentions hidden persistence accounts on compromised routers and a combination of SSH authentication bypass with parsing bugs or privilege escalation. That enables takeover, not just denial of service or scan noise.
For the region, the case matters because MikroTik has a wide presence among small operators, regional ISPs, SMEs and environments where network administration does not always include continuous monitoring. Active exploitation on those devices can lead to traffic redirection, access to internal networks or use of the router as a pivot. This is not an abstract lab problem, but a path to edge compromise.
ConnectWise ScreenConnect, KEV and post-patch response
CVE-2026-84869 in ConnectWise ScreenConnect added another alert for active exploitation. CISA confirmed the activity, ConnectWise recommended updating to version 26.6.5 or later and reviewing clients and agents after patching, and Rescana reported its addition to KEV. The detail matters because ScreenConnect is often part of legitimate remote support and administration tooling, exactly the kind of software an attacker would try to abuse for discreet movement.
The recommendation to review clients and agents after patching is a clear sign that remediation does not end with installing the new version. When a remote access tool appears in KEV, the priority shifts toward auditing sessions, authentications and managed devices. In Latin America, where this type of tool is widely used by providers, outsourced support and distributed operations, the potential reach is high.
Issabel, unauthenticated command execution
CEVIU reported real-world exploitation of an Issabel framework vulnerability observed by the Shadowserver Foundation since September 9. The available material does not provide the exact CVE, but it clearly shows unauthenticated command execution. Even without a concrete identifier, the case adds to the pattern of administration or communications products with immediate operational exposure.
Issabel has regional presence because it is used in IP telephony and enterprise communications environments. For that reason, even without the exact CVE, the alert deserves follow-up. If a platform of this kind allows unauthenticated command execution, the impact can include call manipulation, configuration theft or pivoting into internal segments. The absence of an identifier does not reduce the relevance of the finding, it only limits technical correlation.
Active threats and campaigns
Ransomware and extortion
September reporting identified only one case in which ransomware or extortion was the primary focus, but the source did not specify whether it involved asset encryption, data exfiltration without encryption, or only a mention on a leak site. That lack of detail prevents a more precise classification and means the case should be treated as an incomplete signal, not as a broader monthly pattern.
Operationally, that matters because a single ransomware label can mask very different impacts. Losing system availability is not the same as facing data extortion without encryption. Since the corpus does not separate those scenarios, this month’s analysis focuses on exploited vulnerabilities rather than on a true ransomware wave.
Fraud and phishing
The corpus recorded 9 documented fraud or phishing cases, down from 30 the previous month. The drop does not mean the problem disappeared, but it does confirm that in September the center of gravity shifted toward technical exploitation of vulnerabilities and campaigns against critical infrastructure. The most visible case was CTIR Gov Recommendation 17/2026 on SEO poisoning in .gov.br sites.
That campaign deserves attention because it went beyond classic phishing. The material describes cloaking against search engine bots, injected links to illegal gambling and casino sites, and the need to reset database, API, certificate, and administrative panel credentials. In other words, fraud overlapped with intrusion and manipulation of government websites.
APT, persistent intrusion, and infrastructure abuse
The material did not identify any case as a classic APT with solid attribution to a persistent group, but it did include campaigns with persistence, infrastructure abuse, and covert control. MikroTrick on MikroTik, SEO poisoning in .gov.br, and abuse of remote access tools such as ScreenConnect fit this broader category of campaigns that prioritize attacker continuity.
There is also an infrastructure vector that is difficult to neutralize, such as KREMLIN’s command-and-control infrastructure update through Ethereum smart contracts. The material itself makes clear that KREMLIN has no CVE and no KEV entry, so it should not be confused with an exploited vulnerability. Even so, it is a signal of campaigns designed for operational resilience and evasion of blocking.
Critical vulnerabilities
The table below consolidates the CVEs and the exploitation or prioritization status cited in the material reviewed. It excludes cases without an exact identifier, although those are mentioned in prose in earlier sections.
| CVE | Software | Exploitation | Source |
|---|---|---|---|
| CVE-2026-83548 | SonicWall SMA1000 | Active exploitation, unauthenticated SSRF, can be chained for RCE | SonicWall, ProjectDiscovery, Quasa, CISA via cited sources |
| CVE-2026-83549 | SonicWall SMA1000 | Active exploitation, OS command injection, part of an RCE chain | SonicWall, Ayinedjimi Consultants, SecurityArsenal |
| CVE-2026-85706 | GitLab CE and EE self-managed | Exploited in the wild, arbitrary file read | Rapid7, Beazley Security Labs, Censys, Canadian Centre for Cyber Security |
| CVE-2026-84869 | ConnectWise ScreenConnect | Active exploitation confirmed by CISA | Aviatrix Threat Research Center, Rescana |
| CVE-2026-71362 | Adobe Commerce and Magento | Observed exploitation, added to CISA KEV | Rescana, BleepingComputer, The Hacker News, CTIR Gov |
| CVE-2025-25249 | Fortinet FortiOS and FortiSwitchManager | Listed in CISA KEV according to CTIR Gov | CTIR Gov |
| CVE-2025-20265 | Fortinet devices | Active exploitation of authentication bypass | CISC |
| CVE-2026-93616 | Multiple products, according to CTIR Gov | Listed in CISA KEV according to official alert | CTIR Gov |
| CVE-2026-67276 | MikroTik RouterOS | Active exploitation in the MikroTrick chain | ECUCERT, Kaspersky, DIVD, NICS-TW |
| CVE-2026-86060 | MikroTik RouterOS | Active exploitation, privilege escalation and takeover | ECUCERT, Kaspersky, NICS-TW, DIVD |
| CVE-2026-67277 | MikroTik RouterOS | Vulnerability included in an active exploitation alert | ECUCERT, Kaspersky |
| CVE-2026-89078 | GitLab CE and EE self-managed | Arbitrary code execution under certain conditions | CVE.org, GitLab, Forest Watch |
| CVE-2026-93577 | GitLab CE and EE self-managed | Arbitrary code execution under certain conditions | CVE.org, GitLab, Forest Watch |
| CVE-2026-92530 | GitLab Direct Transfer | Author spoofing in imports, no active exploitation described | CVE.org |
The universe of critical CVEs was not limited to these identifiers. The material also mentions flaws in Cisco Identity Services Engine, Cisco Secure Email Gateway, NGINX, 7-Zip and WSO2, but without a uniform list of active exploitation comparable to the main block above. For that reason, this table prioritizes only the cases where the link to exploitation, KEV or an official alert is explicitly supported.
Regulation and compliance
September did not show formal regulatory moves in the strict sense of the metric, but it did bring intense institutional response activity. CTIR Gov and CISC issued alerts and bulletins, ECUCERT published a specific alert, and INCIBE-CERT released notices on GitLab and other applications. In practice, the month looked more like an accelerated operational compliance cycle than a change in regulation.
In Brazil, the response included alerts, bulletins, and technical recommendations that drilled down into specific remediation steps. Recomendação 17/2026 called for deindexing routes, redefining credentials, and reporting anomalous activity. The alerts on Adobe Commerce, Fortinet, SonicWall, and Cisco Identity Services Engine point to the same logic: prioritize remediation, review exposure, and, in some cases, treat the incident as a potential compromise.
These kinds of documents do not create a new legal rule, but they do function as a de facto standard for state teams and vendors that work with government. In Latin America, where national response bodies often guide multiple sectors, these notices carry practical weight similar to a compliance circular, even if they remain technical in nature.
Most affected countries in Latin America
Brazil
Brazil accounted for the largest amount of verifiable signal this month. CTIR Gov issued alerts on SonicWall SMA1000, Adobe Commerce and Magento, Fortinet, Cisco Identity Services Engine, and GitLab, along with a recommendation on SEO poisoning in .gov.br sites. CISC also published bulletins on vulnerabilities in Microsoft, Fortinet, Commvault, Check Point, NGINX, and 7-Zip.
The Brazilian picture has two layers. The first is technical prioritization, because much of the material is focused on patching and KEV catalogs. The second is exposed surface, because several issues involve cloud services, automated repositories, remote administration, and public government sites. The result is a high-risk signal for public agencies, vendors, and companies with hybrid infrastructure.
Ecuador
Ecuador issued a specific and operationally valuable alert on MikroTik RouterOS being actively exploited. ECUCERT not only named the CVEs, it framed the issue as active exploitation, which means exposed routers must be treated as assets that may already be compromised, not simply as devices to update when possible.
This is especially relevant for connectivity providers, SMEs, and edge networks. In environments where MikroTik serves as a router, firewall, or access concentrator, active exploitation can enable persistence, traffic redirection, or movement into internal segments. The Ecuadorian alert aligns with the broader international technical ecosystem and reinforces the urgency of review.
Mexico
Mexico appears in the material mainly through web applications, cloud, and service exposure. Ciberseguridad LATAM coverage notes that in Brazil and Mexico, sectors such as digital payments and digital health operate applications integrated with AWS, Azure, and Google Cloud, with GitHub or GitLab repositories configured for automatic deployment without manual review. That is not a specific Mexican incident, but it is a useful frame for reading local risk.
For this report, Mexico also appears through references to companies and services in the regional market where attack surface depends on automated integrations and repositories connected to production. The available material does not allow for a claim of incident concentration in the country, but it does suggest exposure comparable to other regional markets that rely on DevOps and cloud.
Colombia
Colombia enters the corpus mainly through uncategorized items and incident cases in digital services, although the material analyzed does not provide a critical vulnerability case there with the same density as in Brazil or Ecuador. The lack of strong signal should not be read as absence of risk, but as a limit of the available corpus for the month.
The ICETEX case, although outside this thematic vertical because it was a provider security incident, reinforces the region's dependence on third parties and external services. In a critical vulnerability reading, that matters because many exploitations end up affecting organizations that do not directly control the compromised infrastructure.
Paraguay
Paraguay appears mainly through CERT.PY activity and the regional bulletin context. The material provided includes advisories on MISP and WordPress plugins, but without confirmed dates, so they are not included in the month’s indicators. Even so, they show institutional interest in common attack surfaces that are often relevant for mid-sized organizations.
In the regional comparison, Paraguay does not concentrate verifiable incidents at the same scale as Brazil or Ecuador. That does not reduce the value of its advisories, but it does limit the ability to build a narrative of active exploitation with enough volume for this report. The signal is one of monitoring, not prevalence.
Argentina
There were not enough verifiable facts in the material to build a specific reading for Argentina within this vertical. That does not imply absence of exposure to critical vulnerabilities, only that the September corpus did not provide a case with confirmed date and scope comparable to those in Brazil or Ecuador.
Chile
There were also not enough verifiable facts for Chile in the September corpus analyzed for this topic. The available material does not support a country trend, although that does not rule out exposure to the same products and exploitation chains seen in other regional markets.
Peru
There were not enough verifiable facts for Peru in the period analyzed. The report does not attribute that absence to lower real risk, only to the specific coverage in the material received.
Bolivia
There were no sufficient verifiable facts for Bolivia in the September material. The regional signal that does appear, especially in perimeter appliances and administration software, is equally relevant for Bolivian environments, but it cannot be documented here with a concrete local case.
United States
Although it is not part of Latin America, the United States appears as a background reference in nearly every prioritization process through CISA KEV. Remediation deadlines for U.S. federal agencies, such as September 14 or 27, helped define urgency for regional vendors and CERTs. In this report, it is used only as a comparative frame for active exploitation and remediation.
Trends and signals to watch
Compared with the previous month, the total volume fell sharply, from 344 to 177 verified incidents, and the number of critical CVEs mentioned dropped from 83 to 43. Even so, the operational signal did not ease by the same margin, because vulnerabilities remained the main threat and multiple cases were confirmed as actively exploited by several sources.
August brought a higher volume and multiple high-impact infrastructure cases. September had less noise, but the signal was more focused on urgent remediation and prioritizing exposed assets. That often happens when the ecosystem shifts from a cycle of broad disclosure to one of confirmed exploitation and institutional response.
The first signal to watch is the persistence of multi-CVE chains in perimeter devices. SonicWall SMA1000 and MikroTik RouterOS show that attackers are still looking for combinations of bypass, SSRF, command injection, and privilege escalation. When those flaws are combined, an attacker does not need a more sophisticated vector to move from initial access to device control.
The second signal is the pressure on development and deployment platforms. GitLab made clear that self-managed environments remain a high-value target because they bring together secrets, pipelines, service credentials, and automation. In the region, where many companies and public agencies use GitLab as a delivery backbone, that means reviewing not only versions but also exposure, permissions, and the traceability of imports or CI/CD.
The third signal is that regional advisories are no longer limited to on-prem software. Fortinet, Commvault Cloud, FortiSandbox Cloud, Microsoft, and other examples show a shift toward cloud and hybrid services. That requires Latin American teams to pair local remediation with control over identity, credentials, pipelines, and sessions. If only the appliance is reviewed, part of the risk is missed.
Security team recommendations
First, prioritize patches and compromise review for assets that appeared in KEV or in official alerts during the month. That includes SonicWall SMA1000, GitLab self-managed, ConnectWise ScreenScreenConnect, Adobe Commerce and Magento, MikroTik RouterOS, and the Fortinet products mentioned in official advisories. In these cases, applying the update is not enough, because several sources called for account, agent, session, and forensic trace review.
Second, review direct internet exposure for administration tools, repositories, and support portals. If GitLab, ScreenConnect, remote access appliances, or management interfaces are exposed, priority should rise immediately. The risk is not only the vulnerability itself, but also the combination of public accessibility, reused credentials, and automated deployment or support workflows.
Third, strengthen monitoring of credentials and secrets. The GitLab exploitation, SEO poisoning in .gov.br, and abuse of remote tools show that an intrusion can end in theft of tokens, API keys, certificates, and administrative panel passwords. Rotating credentials without reviewing the scope of exposure can leave active persistence in place.
Fourth, add post-patch compromise hunting. In SonicWall, ConnectWise, and Fortinet, the material stresses that patching does not automatically close the incident. Logs, configuration changes, active sessions, hidden accounts, access rules, and persistence artifacts need to be reviewed. That matters especially for edge devices and remote support platforms.
Fifth, treat network and security appliances as highly critical operational assets. MikroTik and SonicWall show that the network edge remains a primary target, and that a compromised router or gateway can have a broader impact than an isolated workstation. The response plan should include secure rebooting, restoration from a known-good configuration, and integrity validation.
Sixth, align regional prioritization with official CERT and CSIRT advisories. In Latin America, CTIR Gov, CISC, and ECUCERT acted as amplifiers of urgency and local context. When those organizations issue alerts about a CVE, the organization should translate that into an internal action with an owner, a deadline, and closure evidence. Otherwise, the alert remains informational reading rather than a control.
Frequently Asked Questions
Which countries had the strongest signal this month, and why?
Brazil and Ecuador had the clearest signal. Brazil concentrated official alerts on SonicWall, Adobe, Fortinet, GitLab, and active campaigns against .gov.br sites. Ecuador, meanwhile, issued a specific alert on MikroTik RouterOS that was actively exploited. Coverage for the rest of the countries was more scattered or lacked a confirmed date.
What was the difference between the Brazil and Ecuador material?
Brazil combined bulletins, recommendations, and active campaigns involving several vendors, along with alerts on SEO poisoning and cloud. Ecuador had a more focused but very clear case involving MikroTik RouterOS with confirmed active exploitation. The difference was breadth in Brazil and operational precision in Ecuador.
What changed between August and September in critical vulnerabilities?
The total volume of verified incidents fell, and so did the number of critical CVEs mentioned. Even so, the main threat remained vulnerabilities, and several cases were still confirmed as actively exploited. August had more noise, while September had less volume but a sharper focus on remediation and prioritization.
Which products should Latin American teams review first?
They should first review SonicWall SMA1000, GitLab self-managed, ConnectWise ScreenConnect, Adobe Commerce and Magento, Fortinet, MikroTik RouterOS, and, where applicable, Cisco Identity Services Engine. The priority comes from the combination of active exploitation, presence in KEV, and broad use across regional infrastructure.
Did the report record ransomware as the main trend?
No. Only one case appeared with ransomware or extortion as the primary focus, but the material did not specify whether there was encryption, exfiltration without encryption, or only a mention on a leak site. The month’s main trend was clearly vulnerabilities, not extortion. The threats and active campaigns section covers it in more detail.
Which official alerts should government teams read first?
In Brazil, the CTIR Gov alerts on SonicWall, Adobe Commerce, Fortinet, GitLab, and Recomendação 17/2026 on SEO poisoning. In Ecuador, the ECUCERT alert on MikroTik RouterOS. Those documents combine active exploitation, operational impact, and concrete mitigation steps.
Material limitations
This report was built exclusively from the material provided for September 2026 and from the comparative framework for prior months included in the file. There was no access to the internet or to sources outside the authorized list. As a result, several technical references are limited to what each source described, rather than to any additional independent verification.
The time window for the indicators was based on 178 dated facts from September 2026, 13 facts from prior months used only as comparative context, and 2 undated facts excluded from the indicators. The undated facts, such as CERT.gov.py notices about MISP and WordPress plugins, may be used as qualitative context, but they are not part of the monthly volume.
A zero indicator means it did not appear in the September material analyzed, not that the phenomenon did not occur in the region. This applies in particular to regulatory developments and the breakdown of some categories. It also applies to CVEs, if the material does not record a given case, that does not rule out the possibility that it existed outside the available corpus.
Aggregated telemetry was handled separately and was not added to incidents. In this report, it is mentioned only as a point of reference when the source makes clear that they are attempted or automated blocks, not confirmed intrusions. Sponsored content, consumer social media, and posts outside the list of available sources were also not used as evidence of trend.
Countries without enough verifiable facts, or with insufficient material to support a local reading, were left out of volume statements. That does not mean there was no risk, only a documentation coverage limitation for the period.
Sources
- Active Exploitation Alert: Adobe Commerce / Magento CVE-2026-71362Rescana
- ALERTA 89/2026Centro de Tratamento e Resposta a Incidentes Cibernéticos de Governo (CTIR Gov)
- ALERTA 90/2026Centro de Tratamento e Resposta a Incidentes Cibernéticos de Governo (CTIR Gov)
- CISA warns of SharePoint, WSO2, Adobe Commerce flaws exploited in attacksBleepingComputer
- ALERTA 86/2026Centro de Tratamento e Resposta a Incidentes Cibernéticos de Governo (CTIR Gov)
- WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV CatalogThe Hacker News
- Boletim do CISC de Vulnerabilidades — 22 de setembro de 2026Centro de Prevenção, Tratamento e Resposta a Incidentes Cibernéticos de Governo (CISC)
- Cibersegurança e inteligência artificial: os destaquesIT Show
- Boletín Semanal de Ciberseguridad, 12-18 de septiembreTelefonica Tech
- Atacantes exploram falha no framework Issabel permitindo execução de comandos no sistema sem autenticaçãoCEVIU
- ConnectWise ScreenConnect CVE-2026-84869 Actively ...Aviatrix Threat Research Center
- KREMLIN malware uses Ethereum to update attack serversCrypto.news
- KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session TokensF4N6
- Sept. 15 Advisory: GitLab Critical Path Traversal VulnerabilityCensys
- Critical Path Traversal in GitLab CE and EE Under Active ExploitationBeazley Security Labs
- CVE-2026-85706: Critical GitLab Path Traversal Exploited in the WildRapid7
- KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens in BrazilWorld Cyber News
- Microsoft mapea vectores de ataque en aplicaciones web cloud: primera matriz unificada para entornos serverlessCiberseguridad LATAM
- GitLab security advisory (AV26-917)Canadian Centre for Cyber Security
- Active Exploitation Alert: ConnectWise ScreenConnect Improper Privilege Management / Missing Authorization (CVE-2026-84869) Added to CISA KEVRescana
- ALERTA 79/2026GSI/CTIR Gov
- Rede chinesa invade sites '.gov.br' em fraude de apostas onlineTecMundo
- ALERTA 80/2026GSI/CTIR Gov
- CISA Adds 5 Actively Exploited Artifactory, ScreenConnect ...The Hacker News
- CVE-2026-83548 & 83549 : SonicWall SMA 1000 zero-days chainés en RCEAyinedjimi Consultants
- Redbelt Security aponta ataques contra Microsoft e VMwareItsection
- RECOMENDAÇÃO 17/2026GSI/CTIR Gov
- RECOMENDAÇÃO 17/2026GSI/CTIR Gov
- CVE-2026-83548 – SonicWall SMA1000 WorkPlace Unauthenticated SSRFProjectDiscovery
- Exploited SonicWall SMA1000 Flaws Need More Than PatchingQuasa
- CISA KEV Flash: 12 CVEs Added — Microsoft, SonicWall, N-able and Adobe Commerce Under Active AttackSecurityArsenal
- Boletim do CISC de Vulnerabilidadesgov.br / CISC
- Bulletin de sécurité Fortinet (AV26-898)Centre canadien pour la cybersécurité
- Bulletin de sécurité Commvault (AV26-899)Centre canadien pour la cybersécurité
- Microsoft Patch Tuesday: 974 Bugs, 2 Zero-Days [2026]Shattered.io
- Microsoft's Two-Track Patch Tuesday: Cloud Identity Flaws Fixed Before Disclosure, Windows Still Catching UpYahoo Tech
- SonicWall SMA 1000 : zero-days chainés CVSS 10, KEV CISAAyinedjimi Consultants
- ALERTA 87/2026Governo Federal do Brasil / CTIR Gov
- ALERTA 86/2026Governo Federal do Brasil / CTIR Gov
- ALERTA 85/2026Governo Federal do Brasil / CTIR Gov
- INCIBE-CERT alerta de siete vulnerabilidades de severidad mediaMoncloa
- INCIBE-CERT alerta de 11 vulnerabilidades en GitLab, dos de severidad críticaMoncloa
- 「GitLab」に再び緊急パッチ、CVSS基本値「9.9」の脆弱性2件に対処Forest Watch / Impress Watch
- CVE-2026-89078 - CVE RecordCVE.org
- CVE-2026-92530 - CVE RecordCVE.org
- CVE-2026-93577 - CVE RecordCVE.org
- Cybersecurity Weekly Report: Sept 14-20, 2026CyberExperts / Cyberinfos
- Security Week 2638: опасные уязвимости в роутерах MikroTikKaspersky / Securitylab.ru
- AL-2026-046: Vulnerabilidades críticas en MikroTik RouterOS explotadas activamenteCentro de Respuesta a Incidentes Informáticos del Ecuador (ECUCERT)
- MikroTik RouterOS存在高風險安全漏洞(CVE-2026-67276與CVE-2026-86060)National Information and Communication Security (NICS-TW) – Taiwán
- DIVD-2026-00012 - MikroTik RouterOS MikroTrickDIVD CSIRT (Holanda)
- Weekly Threat Landscape Digest - Week 38HawkEye
- MikroTik cerraba ese puerto de fábrica: la vulnerabilidad es suya, la excepción es tuyaEveryWAN
- 122,500 MikroTik routers exposed: what MikroTrick tells us about unauthenticated RCE at scaleInfosec.ge
- MikroTrick Chain Enables Unauthenticated Takeover of MikroTik RouterOS DevicesMallory Threat Research
- Hackers exploit zero-day flaw in Cisco email gatewayCybersecurity Dive
- Cisco Secure Email Gatewayに深刻な脆弱性 - JPCERT/CC emergency informationINTERNET Watch (vía JPCERT/CC)
- INCIBE-CERT alerta de seis vulnerabilidades críticas en CiscoMoncloa
- Multiple Vulnerabilities in Ivanti Products Could Allow for Arbitrary Code ExecutionCenter for Internet Security
- Multiple Vulnerabilities in Cisco Secure Email Products Could Allow for Remote Code Execution (MS-ISAC 2026-096)Center for Internet Security (CIS)
- Cisco Security Advisory / Hardening Guidance for Cisco Secure Email GatewayCisco
- Criminosos exploram falha crítica no Cisco Secure Email GatewayIT Forum
- INCIBE-CERT alerta de una vulnerabilidad crítica en GitLab que permite leer archivos arbitrarios del servidorMoncloa
- MoncloaPolítica EspañolaMoncloa
- Cisco Secure Email Gateway SQL Injection Vulnerability AdvisoryCisco
- Unauthenticated Arbitrary File Read in GitLab Repository Commits API (CVE-2026-85706)Mallory Security Labs
- INCIBE-CERT alerta de diez vulnerabilidades en Ivanti: seis son críticas y permiten ejecución remota de códigoMoncloa
- GitLab Patches Critical Flaws Enabling Arbitrary File Read, Credential Theft and Remote Code ExecutionCybersecurity News
- Análisis técnico de CVE-2026-85706: unauthenticated arbitrary local file read in GitLabInvestigador independiente en GitHub
- GitLab CE/EE arbitrary file read vulnerability advisory (CVE-2026-85706)GitHub Security Advisories (GitLab)
- Icetex sufrió un incidente de seguridad de la información que afectó sus serviciosZona Cero
- Comunicado institucional sobre incidente de seguridad de ...ICETEX
- Preocupación en los estudiantes: Icetex enfrenta fallas tras incidente de seguridad digitalPulzo
- Icetex reporta incidente de seguridad: varios de sus servicios fueron afectadosBlu Radio
- Descarta Aeroméxico riesgo financiero tras filtración digitalEl Mañana
- Aeroméxico reconoce sustracción de datos de clientes; descarta información bancariaAristegui Noticias
- Aeroméxico admite filtración: Revela qué datos de clientes fueron vulnerados en ciberataqueEl Financiero
- Buen Gobierno investiga posible filtración de datos de Aeroméxico con más de 15 millones de registrosInfobae México
- Detectan posible exposición de datos de Aeroméxico: esto halló la Secretaría AnticorrupciónRadio Fórmula
- VECERT Analyzer on X: "⚠️ TARGETED PREVENTIVE ALERT ...VECERT Analyzer on X
- CERT-PY – CERT-PYCERT-PY
- CVE-2026-87730 – Rejected reasonUK Cyber Defence
- Vulnerabilidades en complementos de WordPressCERT.gov.py
- CVE-2026-86452 - Vulnerability Details - OpenCVEOpenCVE
- NVD-CVE-2026-86418 - NISTNIST NVD
- CVE-2026-86440 - Vulnerability Details - OpenCVEOpenCVE
- CVE-2026-86441 - Vulnerability Details - OpenCVEOpenCVE
- Eclypsium flags 1,051 CVEs in infrastructure advisoriesSecurityBrief.news
- Cisco patched five Cisco SD-WAN vulnerability issues in Catalyst SD-WAN SoftwareSecurityOnline.info
- Cisco patched five Cisco SD-WAN vulnerability issues in Catalyst SD-WAN SoftwareSecurityOnline.info
- NoticiasCERT.PY
- Vulnerabilidad en productos MISPCERT.gov.py
- Vulnerabilidades en complementos de WordPressCERT.gov.py
- 28th September – Threat Intelligence ReportCheck Point Research
- Check Point security advisory (AV26-902) – Update 2Canadian Centre for Cyber Security
- Check Point warns of hackers exploiting Security Gateway VPN RCE flawBleepingComputer
- Active Exploitation of CVE-2026-85102 and a Management Pre-Authentication Vulnerability CVE-2026-93616Check Point
- Weekly CISA KEV Updates: 14 September 2026HackerStorm
- CISA KEV Catalog: Four Critical Vulnerabilities Added in September 2026Aviatrix
- Threat matrix: Mapping threats across cloud web applicationsMicrosoft Security Blog
- Critical CVEs & Hacking Techniques Weekly: 7 Sep-13 Sep 2026FireCompass
- Weekly Security Roundup: Secure AI Agents and Provenance-First CI/CDMicrosoft Tech Community
- Critical CVEs & Hacking Techniques Weekly: 31 Aug-6 Sep 2026FireCompass
- Rafay and Stealthium Partner to Bring Verifiable Security to Shared ...Stealthium
- Ilya Sutskever Warns Neoclouds Lack Security to Stop a Rogue ...Startup Fortune
- The Signal — August 31, 2026Buttondown - The Signal newsletter
- Actively Exploited NetScaler VulnerabilitiesSygnia
- Citrix NetScaler exploitation began days before public notificationCybersecurity Dive
- Custom malware used in Citrix 0-day attacks targeting govt, banks, professional servicesThe Register
- Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772Unit 42, Palo Alto Networks
- Citrix Products Multiple VulnerabilitiesHong Kong Computer Emergency Response Team Coordination Centre
- Zero-Day Exploitation of Citrix NetScaler ADC and GatewayRapid7
- Sept 28 Advisory: Citrix NetScaler ADC and Gateway VulnerabilitiesCensys
- CVE-2026-88772 Impact, Exploitability, and Mitigation StepsWiz
- Alerta de Seguridad: Citrix NetScaler - RCE y denegación de ...CiberPlaneta
- Alerta de Seguridad: WSO2 - Path Traversal y RCE | Boletín de Seguridad CiberPlanetaCiberPlaneta
- Breach Watch Weekly: When the Attacker Is an AI Agent — Sep 20–24CISO Platform
- CISA Flags Three Linux Kernel Vulnerabilities Exploited in the WildThe Hacker News
- Weekly Threat Bulletin – September 16th, 2026F5 Labs
- WordPress plugin fires, SonicWall zero-days, and a KEV avalanche · Perimeter · 09-11-2026Fruition
- CVE-2026-67277: fuga de memoria del kernel y DoS no autenticado en MikroTik RouterOSCiberPlaneta
- CISO Application Risk Intel Briefing for Week of September 9Veracode
- Active Exploitation of Vulnerability in Adobe ProductsCyber Security Agency of Singapore
- Weekly Threat Bulletin – September 9th, 2026F5 Labs
- SonicWall customers face actively exploited zero-days (X post)CyberScoop
- Unauthentifizierte SSRF im SMA1000 Work-Place-InterfaceArgos Security
- SonicWall SMA1000 2nd Zero-Day: CVSS 10.0 Flaw [2026]Tech Insider
- Exploit chain for SonicWall SMA1000 zero-days (X post)Stephen Fewer
- SonicWall SMA1000: Patch and Check for CompromiseQuasa
- Two SonicWall SMA 1000 zero-days are being exploited right nowSecure in Seconds
- SonicWall SMA1000 RCE Vulnerability: Patch NowDIESEC
- SonicWall's CVE-2026-83549 Was Exploited in 1 Days — Well Under Its 197-Day MedianCVEDaily
- Google security advisory (AV26-883) – Update 1Canadian Centre for Cyber Security
- SonicWall's CVE-2026-83548 Was Exploited in 1 Days — Well Under Its 197-Day MedianCVEDaily
- Critical SonicWall SMA 1000 Zero-Day Vulnerabilities ...Triskele Labs
- Cyber Threat Brief — September 3 2026AJ King
- CISA Warns of SonicWall SMA1000 Vulnerabilities Active ExploitationQualys Threat Research
- SonicWall PSAIRT vulnerability details for SonicWall SMA1000SonicWall
- [NEW] [high] JFrog Artifactory: Vulnerability allows obtaining administrator privilegesCSIRTs.com
- CISA Incorpora 7 Fallos Críticos Al Catálogo KEV 2026CybersecureFox
- Known Exploited Vulnerabilities CatalogCISA
- Bulletin de sécurité JFrog (AV26-867)Canadian Centre for Cyber Security
- SonicWall SMA 1000 zero-days demand compromise ...Security.io
- CVE-2026-82329: Bypass de Autenticación Crítico en JFrog Artifactory Explotado ActivamenteCiberPlaneta
- CVE-2026-81578 y CVE-2026-82078: cadena crítica de ataque en PaperCut NG/MF explotada activamenteCiberPlaneta
- Explotación Activa de Omisión de Autenticación en JFrog Artifactory (CVE-2026-82329)Devel.group
- CISA Adds Two Known Exploited Vulnerabilities to CatalogCyber Experts
- JFrog security advisory (AV26-867)Canadian Centre for Cyber Security
- PaperCut RCE Chain Requires Emergency Patch Release 2WindowsForum
- CVE-2026-81578 & CVE-2026-82078: PaperCut NG/MF Added to CISA KEV Detection and Remediation GuideSecurity Arsenal
- PaperCut NG/MF CVE-2026-81578: Patch Now, Exploited in Wildforsmile.jp
- Huntress detecta explotación activa de la vulnerabilidad de PaperCutMoncloa
