important2 findings, 11 signals, 9 noted6 min read

Today's changes are a disclosed low-privilege Linux path to kernel execution and confirmed operational use of pre-authentication flaws in FortiGate and Cisco FMC.

The Linux route still lacks a public reproduction, while the appliance chains already end in reverse-shell or root control.

Priority findings2
01
High
Edge — FortiGate
Confirmed
CVE-2025-25249

PivotC2 operators are taking over FortiGate appliances through CAPWAP.

Network reachability to the CAPWAP control service on UDP/5246 is the prerequisite.

Affects

FortiOS firewall appliances and FortiSwitchManager network-management appliances.

What it enables

Unauthenticated code execution and interactive appliance control

Discover the exposed CAPWAP service and derive firmware-specific image and data addresses from its response.Heap-groom cw_acd with Add Station messages.Send a crafted Image Data message that overwrites allocator pointers.Convert the resulting write into an execvp control-flow pivot.Start a Node.js reverse shell and install the PivotC2 implant for shell, tunneling, scanning and configuration theft.
Why this matters

This leads ahead of the higher-ranked Bluetooth disclosure because operators have already converted the FortiGate flaw into reverse-shell control, while the Bluetooth paths have no public reproduction.

Detail, proof-of-concept code and 3 sources
Required access

Network reachability to the CAPWAP control service on UDP/5246

Affected versions

FortiOS 7.6.0–7.6.3, FortiOS 7.4.0–7.4.8, FortiOS 7.2.0–7.2.11, FortiOS 7.0.0–7.0.17, FortiOS 6.4 releases, FortiSwitchManager 7.2.0–7.2.6, FortiSwitchManager 7.0.0–7.0.5

A crafted Image Data message turns the cw_acd heap overflow into an arbitrary eight-byte write, which the observed exploit converts into an execvp pivot and Node.js reverse shell.

The installed PivotC2 implant supports shell access, tunneling, scanning, and configuration theft.

Evidence
SOCRadar campaign telemetry and reverse engineering of the in-the-wild exploit and PivotC2 implantCISA Known Exploited Vulnerabilities catalog entry added 2026-09-09GitHub Advisory Database affected-version record
Share this finding
02
High
Edge — Cisco FMC
Confirmed
CVE-2026-20079

Cisco's exploited FMC bypass gives an unauthenticated caller root command execution.

HTTP reachability to the management interface is enough to reach the vulnerable path.

Affects

Cisco Secure Firewall Management Center, the on-premises management appliance for Cisco firewalls, and the affected Cisco Security Cloud Control firewall-management service.

What it enables

Unauthenticated command execution as root on firewall-management infrastructure

Send crafted HTTP requests to the FMC web interface without credentials.Bypass the normal management-interface authentication boundary through the boot-created process.Invoke scripts or commands with root access to the appliance operating system.Use the management-plane foothold to harvest credentials, deploy tunnels or web shells, and reach managed networks.
Why this matters

Although ranked below the Bluetooth disclosure, it leads because exploitation is active, reaches root on the firewall-management plane, and has already produced several post-compromise toolsets; the Bluetooth elevation paths remain unreproduced.

Detail and 4 sources
Required access

HTTP reachability to an affected Secure FMC management interface

Affected versions

6.4.0.13 through 6.4.0.18, 7.0.0 through 7.0.8.1, 7.1.0 through 7.1.0.3, 7.2.0 through 7.2.10.2, 7.3.0 through 7.3.1.2, 7.4.0 through 7.4.5, 7.6.0 through 7.6.4, 7.7.0, 7.7.10, 7.7.10.1, and 7.7.11, 10.0.0, FMC 7.0 without hotfix GB-7.0.9.1-3, FMC 7.2 without hotfix HL-7.2.11.1-4, FMC 7.4 without hotfix HG-7.4.7.1-3, FMC 7.6 without hotfix CY-7.6.5.1-2, FMC 7.7 without hotfix AM-7.7.12.1-2, FMC 10.0 without hotfix P-10.0.1.1-2, Secure FMC 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0 installations lacking the applicable hot fix

A boot-created system process exposes an alternate route from crafted unauthenticated web requests to root-capable script execution.

Cisco observed web shells, Cyclops Blink, credential harvesting, tunnels, and ransomware staging across three intrusion clusters.

Cisco has published fixes, and CISA added the flaw to its exploited-vulnerability catalog on September 9.

Evidence
Cisco's advisory confirms unauthenticated HTTP-to-root execution and active exploitationCisco Talos documents three intrusion clusters, including web shells, Cyclops Blink deployment, credential harvesting, tunneling, and ransomware stagingCISA added CVE-2026-20079 to KEV on 2026-09-09
Share this finding
Signals11
important · Bluetooth — Windows

Five Windows Bluetooth lifetime flaws allow local privilege elevation.

Affects

Microsoft Windows 10, Windows 11, and Windows Server systems containing the built-in Bluetooth service or port driver.

Microsoft identified three use-after-free conditions and two race or double-free conditions in the Bluetooth Service and Port Driver.

Detail and 5 sources

The paths start from low-privileged local code and do not have an identified radio-proximity or interaction requirement.

Microsoft published affected and fixed builds, but no public proof of concept or independent reproduction was found.

important · Research — Agent boundaries

A shared ChatGPT conversation could use a victim's connected Gmail authority across accounts.

Affects

ChatGPT, OpenAI’s hosted conversational agent and connected-app platform.

A shared Artifactory property channel carried a hidden task into the victim's account and returned results after one ordinary message caused ChatGPT to invoke the victim's connected tools.

Detail and 1 source

The demonstrated task retrieved data from the victim's connected Gmail account.

OpenAI decommissioned the implicated internal Artifactory instance.

important · Privilege — GlobalProtect

A normal GlobalProtect user can execute commands as SYSTEM or root across three desktop platforms.

Affects

Palo Alto Networks GlobalProtect, the enterprise VPN and endpoint-access client for Windows, macOS, and Linux.

A non-administrative user influences a search path consumed by a privileged component, which resolves attacker-controlled content as SYSTEM on Windows or root on macOS and Linux.

Detail and 1 source

Only the 6.2 Windows and macOS fixes were already available on September 10; several other platform or release fixes still had future dates.

Chain to watch
A non-administrative user influences a GlobalProtect search path.A privileged component resolves attacker-controlled content.Commands run as SYSTEM or root.Coverage remains incomplete across the affected platform and release matrix.
Unverified chainInventory GlobalProtect versions by platform and verify each platform-specific fixed release rather than treating the 6.2 Windows and macOS release as universal coverage.
important · Edge — Commerce

StyleSmuggler requests are giving unauthenticated callers code execution on Adobe Commerce and Magento stores.

Affects

Adobe Commerce, Adobe Commerce B2B, and Magento Open Source, PHP e-commerce storefronts commonly hosted on Linux servers.

An anonymous /graphql request injects styles data that poisons template output, and a failed-payment email path executes the injected PHP.

Detail and 3 sources
important · Edge — Check Point

Two certificate-processing flaws allow unauthenticated code execution on Check Point gateways and managers.

Affects

Check Point Quantum Security Gateway, Quantum Security Management Server, and Spark Firewall network-security appliances.

The primitives are a certificate trust-validation failure and a heap overflow in VPN-certificate ASN.1 decoding.

Detail and 3 sources

Affected VPN or certificate-processing services are sufficient access, including negotiation exposed on UDP/500 or UDP/4500.

Check Point reports internal discovery and no active exploitation.

important · Edge — RMM

An unauthenticated caller can execute code on an N-central RMM server before login.

Affects

N-able N-central, remote monitoring and management servers used by MSPs to administer customer endpoints.

Network reachability to an affected on-premises N-central server is the only established prerequisite.

Detail and 2 sources

Compromise lands beside N-central's script, deployment, and remote-session functions, but public evidence does not show whether attackers used them against managed endpoints.

Chain to watch
Reach an affected N-central server before authentication.Execute code on the RMM server.Potentially reach managed endpoints through N-central control functions.We do not know the execution identity, root cause, or whether observed exploitation reached downstream endpoints.
Unverified chainObtain a root-cause advisory or incident trace connecting server compromise to a process identity and managed-endpoint actions.
important · Physical — Windows

Crafted NTFS storage can trigger kernel code execution when attached to a Windows machine.

Affects

Microsoft Windows 10, Windows 11, and Windows Server systems whose NTFS driver processes attacker-supplied storage

Physical attachment through an accepted storage interface can reach three NTFS heap overflows without credentials or user interaction.

Detail and 2 sources

We do not know the malformed structures or final instruction-control mechanics.

Chain to watch
Prepare crafted NTFS storage.Attach it to an affected Windows machine.NTFS parsing reaches a kernel heap overflow.The malformed NTFS structures and final instruction-control steps are not public.
Unverified chainDiff the fixed ntfs.sys builds and reproduce representative media under kernel tracing.
important · Research — SAP

One Message Server packet can make an unauthenticated host trusted across an SAP cluster.

Affects

SAP NetWeaver Kernel infrastructure underlying ABAP-based SAP systems, including S/4HANA and ABAP Platform deployments.

A crafted packet to public port 36NN asserts trusted-node status, propagates that decision to application servers, and enables RFC-callable external programs to run as the SAP operating-system account.

Detail and 1 source
important · Zero-click — Image parsing

A crafted HEIF reference chain can crash automatic libheif consumers before decoding.

Affects

libheif, the HEIF/AVIF library used by Linux desktop image loaders and server-side image-processing pipelines.

About 45,000 distinct dimg references evade the cycle and finished-item checks until the pre-decode recursive walk exhausts the process stack.

Detail and 2 sources
important · Bluetooth — Earbuds

A nearby stranger can silently bond to Skullcandy Dime 3 earbuds and capture microphone audio.

Affects

Skullcandy Dime 3, consumer true-wireless earbuds running embedded Airoha Bluetooth firmware.

Within Bluetooth Classic range, an attacker can create a stored NoInputNoOutput bond while the earbuds are not in pairing mode, then reconnect for audio takeover and microphone access.

Detail and 6 sources

A fixed build exists, but no owner-accessible upgrade path for deployed units was established.

Chain to watch
Discover or obtain the earbuds' BR/EDR address.Create a stored bond without pairing mode or owner confirmation.Reconnect and open the microphone path.Owners do not have an established route to the fixed firmware.
Unverified chainSkullcandy needs to identify how deployed retail units receive the fixed build.
important · Privilege — Linux

An unprivileged Linux process can turn stale IPv6 multicast-routing state into kernel execution.

Affects

The Linux kernel IPv6 multicast-routing subsystem on Linux hosts.

An unresolved multicast packet can retain a route destination beyond RCU protection; after the route is deleted, a wrong-parent resolution makes ip6mr_cache_report clone the freed destination.

Detail and 2 sources

The upstream fix addresses that sequence, but we do not have a public exploit, a reliability demonstration, or a complete affected stable-version matrix.

Also noted9
Physical — Boot Manager
Physical possession can cross an undisclosed Windows Boot Manager privilege boundary.
The trigger and gained authority are unknown; do not infer a Secure Boot or BitLocker defeat.
ResearchCVE-2026-77892 - Vulnerability Details - OpenCVE
Wi-Fi — Qualcomm
Malformed nearby WLAN frames can transiently disable firmware across broad Qualcomm chipset families.
Broad hardware reach, but only a transient availability loss is established.
ResearchSamsung Mobile Security
Physical — dm-integrity
Raw disk writes can forge legacy discard markers and silently wipe selected keyed dm-integrity blocks.
The bypass is limited to legacy allow_discards and destroys data rather than disclosing it.
Code / PoCTags · cryptsetup / cryptsetup · GitLab
Mobile — Samsung Cloud
A permissionless local app can disable Samsung enhanced data protection without interaction.
It switches off a deliberate protection but does not itself disclose protected data.
ResearchCVE-2026-21106 - Vulnerability Details - OpenCVE
Mobile — Photoshop
A malicious webpage can fixate a Photoshop Mobile session and expose authenticated resources.
Victim interaction, high complexity, and one mobile application keep it below the main brief.
ResearchCVE-2026-76196 - Vulnerability Details - OpenCVE
Wi-Fi — D-Link
Public DHCP code can overwrite the DIR-822A udhcpcd stack through TR-111 option 125.
Unpatched stack corruption is established; reliable control-flow hijacking is not.
Researchhttps://tenable.com/cve/CVE-2026-86296
Wi-Fi — D-Link
An unauthenticated LAN DHCP request can overwrite the DIR-895L udhcpcd stack.
Public code exists, but the original report and a reliable execution chain are missing.
ResearchCVE-2026-86509 - Vulnerability Details - OpenCVE
Mobile — Samsung
An ordinary app can make Samsung Visual Voicemail initiate a call without call permission.
It defeats an explicit permission, but the unauthorized action is limited to placing a call.
SecondarySamsung Mobile Security
Bluetooth — Windows
A low-privilege Windows process can trigger a Bluetooth port-driver out-of-bounds read.
The disclosed object and security utility of the returned data remain unknown.
Researchhttps://secalerts.co/vulnerability/CVE-2026-68849
What was checked · 2 quiet
Boot chain & TPMQuiet

HP-specific InsydeH2O code exposed a privileged-local-to-SMM path; the broader OpenSSL mapping still lacks preboot reachability.

FirmwareQuiet

FortiGate exploitation and persistent Skullcandy Dime 3 microphone access supplied the material firmware changes.

Get it by email

The same brief, every morning. One email a day, nothing else.

fullchain.sh follows the day’s disclosures from bug to shell — what each one enables, what it links to, and where the fix left the primitive in place.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Thursday, September 10, 2026