Skip to main content
All Threat Briefings
Weekly Threat AwarenessSeptember 10, 2026|Vol. 1 · Issue 12

Weekly Threat Awareness ReportExchange Auth Bypass Exploited · Defender "ShieldBreak" · PivotC2 FortiGate RAT

Three high-severity Microsoft flaws lead this week: an Exchange Server authentication bypass that UNC3886 is actively exploiting to gain administrative privileges, the "ShieldBreak" privilege escalation in Defender's Malware Protection Engine, and an Outlook integer overflow that enables remote code execution and is already noted as exploited. On the campaign side, a Russian-speaking cybercrime operator is exploiting a FortiOS heap overflow to plant PivotC2, a post-exploitation RAT built for FortiGate appliances, and SAP has patched a CVSS 10.0 unauthenticated remote code execution flaw in SAP Commerce Cloud. The through-line, echoed by this week's mindmap: edge exploitation and AI-assisted operations are converging - and the email platform and security tooling organizations trust most are squarely in scope.

VT

Vaughn Thomas

Compliance Engineer & Threat Researcher · SOClogix Cyber Group

Technical review: William Johnson, VP of Security Operations

About the Analyst

Vaughn Thomas is SOClogix's Compliance Engineer and principal threat researcher, operating at the intersection of regulatory compliance and active adversary tradecraft. Each week, Vaughn synthesizes intelligence from dark web forums, vendor security advisories, CISA KEV updates, Shodan/Censys exposure data, and real-time telemetry from SOClogix's managed client network - spanning healthcare, financial services, defense industrial base, manufacturing, and local government - to produce actionable threat awareness briefings written for security teams and executive stakeholders at every level. Vaughn actively tracks over 200 threat actor groups and contributes threat sharing intelligence to multiple ISAC communities. His analysis deliberately bridges raw technical findings and business risk so compliance teams and CISOs can act, not just read.

Full bio and published research LinkedIn

200+

Threat groups tracked

50+

Intel feeds monitored

3 yrs

Threat research tenure

This Week's Threat Landscape Mindmap

Threat landscape for August 31 - September 6, 2026: top threats, active actors, attack trends, sector exposure, and what to do now.

Threat landscape mindmap, August 31 - September 6, 2026. Weekly assessment: AI-driven attacks and edge exploitation converge. Top threats: MikroTrick vulnerability chain (CVE-2026-67276), StyleSmuggler zero-day RCE in Magento/Adobe Commerce, Langflow CVE-2026-9198, BREEZE COMET AI-driven financial attacks.
Weekly assessment: AI-driven attacks and edge exploitation converge. Priority: patch MikroTik RouterOS, block StyleSmuggler on Magento, harden AI infrastructure against agent intrusions, and enforce behavioral detection for AiTM phishing in the financial sector. View full size

Vulnerabilities at a Glance

Exploitation status and required action for each CVE covered this week, including the SAP Commerce Cloud flaw covered under campaigns below.

CVEProductSeverityExploitation StatusFixPriority
CVE-2026-58231SAP Commerce Cloud (COM_CLOUD 2211)Critical · CVSS 10.0Patched; exploitation not reportedSAP August Security Patch DayURGENT
CVE-2026-62911Microsoft Exchange ServerHighActive - UNC3886; public exploitMicrosoft patches + mitigationsURGENT
CVE-2026-70329Microsoft OutlookHighNoted as exploited; no public exploitApply update when releasedURGENT
CVE-2026-64914Microsoft Defender (Malware Protection Engine)HighPublicly discussed; no active exploitsStandard Defender updatesThis cycle

CVEs Affecting Client Assets

Vulnerabilities identified this week with direct relevance to common enterprise environments. All three sit in the Microsoft stack, and two are noted as exploited.

HighCVE-2026-62911 New this week Actively exploited Public exploit APT-linked

Microsoft Exchange Server - Authentication Bypass to Admin Privileges

Authentication Bypass by Capture-replay (CWE-294)  ·  Remote  ·  Actively exploited by UNC3886

Series context: UNC3886 also appears on this week's mindmap as Fire Ant (China-nexus / UNC3886), running router implants, the Medusa rootkit, and TACACS credential interception - an actor that targets infrastructure defenders assume is trustworthy.

A high-severity flaw in the core authentication process of Microsoft Exchange Server lets attackers bypass security checks and gain unauthorized administrative privileges. It is an authentication bypass by capture-replay: an attacker intercepts valid communication data and reuses it to trick the server into granting access as if they were a legitimate user. Successful exploitation hands the attacker the keys to the email environment, exposing organizations to data theft, unauthorized access to sensitive email, and lateral movement deeper into the corporate network. The flaw is being exploited in the wild, intelligence reporting links the activity to the advanced threat group UNC3886, and publicly available exploit code has been identified, significantly lowering the barrier to entry.

Recommended Actions

  • Apply all available Microsoft security patches and mitigation guidance for Exchange Server immediately
  • Monitor the Exchange environment for anomalous activity - unexpected administrative actions, new mailbox permissions, and new transport or inbox rules
  • Prioritize internet-facing Exchange servers, and treat any server exposed before patching as potentially compromised until reviewed
HighCVE-2026-70329 New this week Actively exploited

Microsoft Outlook - Remote Code Execution

Integer Overflow or Wraparound (CWE-190)  ·  Unauthorized · Network  ·  Noted as exploited

A high-severity flaw in the core processing logic of Microsoft Outlook could let an unauthorized attacker execute malicious code remotely. It is an integer overflow: a calculation produces a number too large for the software to handle, which an attacker can use to manipulate the program's behavior and potentially take control of the application. Exploited over a network, it enables arbitrary code execution on a victim's machine, leading to data theft, malware installation, or complete system compromise - a critical threat for anyone who interacts with untrusted email or network-based Outlook resources. The vulnerability is noted as being exploited, though no specific exploit code or APT groups have been identified and there are no known indicators of compromise yet, so vigilance is essential until further technical details emerge.

Recommended Actions

  • Monitor official Microsoft channels and apply the Outlook security update as soon as it is available
  • Apply any interim mitigation guidance Microsoft publishes before the update ships
  • Remind users to treat unexpected email and attachments with extra caution while no indicators of compromise exist to detect attacks
HighCVE-2026-64914 New this week

Microsoft Defender "ShieldBreak" - Elevation of Privilege

Improper Access Control (CWE-284)  ·  Malware Protection Engine  ·  No active exploits identified

Series context: The second elevation-of-privilege flaw in Defender's Malware Protection Engine this summer, after "RoguePlanet" (CVE-2026-50656) on June 18 - and Defender's second appearance in two weeks, after last week's CVE-2026-50657.

A high-severity flaw nicknamed "ShieldBreak" in the Microsoft Malware Protection Engine - the core scanning engine inside Microsoft Defender - lets an attacker escalate their permissions to a level that would normally require administrative authorization, potentially taking full control of a system. It is an improper access control issue: the software fails to properly restrict who can perform certain high-level actions, effectively creating a bypass. The result is unauthorized access to sensitive files, data tampering, or malware installation, with the security tool meant to protect the system turned against it. The flaw is being discussed publicly, but there are currently no identified active exploits, APT activity, or known indicators of compromise - it is not yet being widely weaponized, though the public attention calls for proactive defense.

Recommended Actions

  • Ensure all Microsoft Defender software is fully up to date - Microsoft delivers the fix through its standard update channels
  • Confirm the Malware Protection Engine version on endpoints rather than assuming automatic updates applied
  • Alert on attempts to tamper with or disable Defender, a common precursor to privilege abuse

Active Threats & Campaigns

Threat actor activity and disclosed tradecraft with immediate defensive relevance.

Edge Device RATSOCRadar Threat Research Unit · Russian-speaking operator New this week Actively exploited

PivotC2 - FortiGate Post-Exploitation RAT Delivered via CVE-2025-25249

SOCRadar's Threat Research Unit identified ongoing exploitation, since July 2026, of CVE-2025-25249, a heap-based buffer overflow in the wireless controller daemon of FortiOS and FortiSwitchManager. The exploit binary fortirun.bin opens a Node.js reverse shell that stages PivotC2, a post-exploitation RAT for FortiGate appliances. Over a single TLS socket it tunnels shells, proxies, port forwarding, scanning, and configuration harvesting with credential decryption. Of 30,000 targeted addresses, 178 devices were infected, mostly in the United States, with data exfiltration confirmed at two US organizations. The attack lifecycle runs from exploitation and PivotC2 deployment through internal tunneling, host discovery, browser credential theft, lateral movement, and exfiltration. Recovered tool outputs show heavy reliance on AI tools across multiple stages, including automatically generated command-output reports. Russian-language comments, exfiltration tactics, and active discovery of storage and backup infrastructure support a high-confidence assessment of a Russian-speaking, financially motivated cybercrime operator, which also appears to target CVE-2024-47575 (FortiManager), CVE-2026-35273 (PeopleSoft Enterprise PeopleTools), and CVE-2024-26304 (ArubaOS).

Recommended Actions

  • Patch FortiOS and FortiSwitchManager for CVE-2025-25249 and review exposure of the wireless controller service
  • Hunt FortiGate appliances for a fortirun.bin binary, unexpected Node.js processes, and long-lived outbound TLS sessions
  • On any suspect appliance, rotate credentials stored in the device configuration - PivotC2 harvests and decrypts them
  • Close the actor's other doors: CVE-2024-47575 (FortiManager), CVE-2026-35273 (PeopleTools), CVE-2024-26304 (ArubaOS)

Campaign Profile

Source: SOCRadar Threat Research Unit

CVE: CVE-2025-25249 (heap overflow)

Loader: fortirun.bin → Node.js reverse shell

Implant: PivotC2 over a single TLS socket

Scope: 30,000 targeted, 178 infected, mostly US

Actor: Russian-speaking, financially motivated

CriticalCVE-2026-58231SAP August Security Patch Day New this week
10.0CVSS

SAP Commerce Cloud - Unauthenticated Remote Code Execution

SAP patched a maximum-severity remote code execution flaw in SAP Commerce Cloud as part of its August Security Patch Day. It carries a CVSS score of 10.0 and stems from an improper authorization weakness in the core Data Hub Adapter extension, combined with insufficient input validation. An unauthenticated attacker with network access can abuse a default authentication client and submit specially crafted input to functions lacking sufficient validation - a low-complexity attack that could achieve arbitrary code execution and compromise internal components, with high impact on the confidentiality, integrity, and availability of the application. Affected releases are COM_CLOUD 2211 and COM_CLOUD 2211-JDK21. Actual impact depends on deployment architecture, service permissions, network segmentation, and downstream connections.

Recommended Actions

  • Apply the SAP August Security Patch Day fix to COM_CLOUD 2211 and 2211-JDK21 deployments
  • Restrict network access to the Data Hub Adapter and review use of the default authentication client
  • Map what the Commerce Cloud service account can reach downstream - segmentation and service permissions set the blast radius

Vulnerability Profile

Vendor: SAP

CVSS: 10.0

Component: Data Hub Adapter extension

Affected: COM_CLOUD 2211, 2211-JDK21

Access: Unauthenticated, low complexity

Fix: August Security Patch Day

Sources

Primary reporting behind this week's briefing.

  • · Microsoft Security Update Guide - CVE-2026-62911, CVE-2026-64914, CVE-2026-70329
  • · SOCRadar Threat Research Unit - PivotC2 and CVE-2025-25249 exploitation research
  • · Fortinet PSIRT - CVE-2025-25249
  • · SAP August Security Patch Day - CVE-2026-58231
VT

Vaughn Thomas

Compliance Engineer & Threat Researcher, SOClogix

Technical review: William Johnson, VP of Security Operations

Full bio →
VT

Vaughn Thomas

Compliance Engineer

SOClogix Cyber Group

200+

Threat groups tracked

50+

Intel feeds monitored

52×

Reports per year

Global dark web & forum monitoring
Live CISA KEV & NVD tracking
Adversary TTP analysis
Compliance-threat intersection

Get Weekly Briefings Free

Confirmed via email. No spam. Unsubscribe anytime.

This Week at a Glance

CVEs covered5
Actively exploited3
CVSS 10.01
APT-linked1
Active campaigns2
FortiGate devices infected178

Get Vaughn's Briefing Every Week

Free weekly threat awareness reports delivered to your inbox. CVEs, active campaigns, and actionable guidance - written for security teams, compliance managers, and executive stakeholders.

Confirmed via email. No spam. Unsubscribe anytime.

Questions about your exposure to anything in this report? SOClogix Shield MDR clients receive proactive detection coverage and patch-priority guidance for the threats above. Talk to our team to schedule a consultation.