Wednesday, September 16, 2026
Daily digest
No single dominant story today, but a cluster of actively-exploited critical vulnerabilities (ScreenConnect, WSO2, Cisco ESA) demands prompt patch review, alongside continued signal that CMMC enforcement is not slowing down despite DoD process changes.
CISA Warns of Active Exploitation of Critical ScreenConnect Flaw
CISA confirmed that attackers are actively exploiting a critical-severity vulnerability in ConnectWise ScreenConnect. The agency issued a warning urging organizations running the remote access/support tool to apply available patches immediately.
Why it matters: ScreenConnect and similar RMM tools are common vectors for lateral movement into managed environments; if it's used anywhere in your admin toolchain, patch now and check CISA's KEV catalog for CMMC/FedRAMP remediation deadlines.
Critical WSO2 API Manager Flaw Under Active Exploitation
A critical vulnerability in WSO2 API Manager (CVE-2026-5430, CVSS 9.8) is being actively exploited to forge admin JWT tokens and take over accounts, according to watchTowr. The flaw stems from improper verification of a cryptographic signature during JWT authentication.
Cisco Email Security Appliance Can Be Rooted by a Single Email
Cisco disclosed a critical vulnerability in its email security appliances that can be triggered by a specially crafted email to achieve remote root access. Cisco confirmed active exploitation and warned attackers may be able to erase evidence of compromise once inside.
Why it matters: If Cisco ESA/SEG sits on your mail gateway, this is a pre-auth RCE with active exploitation — prioritize patching over routine change-control cycles given the anti-forensics risk.
Iranian Telegram-Controlled Malware Spies on Dissidents and Journalists
US, UK, and Dutch cybersecurity agencies published a joint advisory on a Windows malware family used by Iran's intelligence service, controlled via Telegram. The malware can exfiltrate emails and chats, take screenshots, and activate microphones on infected devices.
Mass-Scanning Campaign Exploits Vite Flaw to Steal Cloud Credentials
F5 Labs identified an automated campaign scanning for internet-exposed Vite development servers to extract AWS and Azure cloud credentials, configuration data, and infrastructure state files. The activity targets misconfigured dev environments left accessible online.
Why it matters: If any dev/test workloads run Vite servers in AWS GovCloud, ensure they're not internet-exposed and rotate any IAM keys or state files that may have been reachable — this is a direct path to GovCloud credential theft.
As the Pentagon Rethinks CMMC, Cybersecurity Requirements Aren't Pausing
Federal News Network reports that a DoD class deviation affecting CMMC implementation does not signal the program's end, according to industry association leadership. Contractors are advised that NIST 800-171 compliance obligations continue regardless of procedural changes to CMMC rollout.
Why it matters: Don't deprioritize SSP/POA&M work or self-assessment prep based on rumors of CMMC delay — the underlying 800-171 requirements and contractual obligations remain in force.
Windows Server 2022 Reaches End of Mainstream Support Next Month
Microsoft reminded customers that Windows Server 2022 will exit mainstream support next month, moving into extended support that runs until October 2031. Extended support continues security updates but drops free non-security hotfixes and feature requests.
Why it matters: Security patching continues through 2031 so there's no immediate compliance gap, but budget for eventual OS upgrades on any Server 2022 hosts underpinning Nutanix AHV management or domain services.
September Windows 11 Patch Needs Its Own Emergency Fix
Microsoft issued an out-of-band emergency patch after the September Patch Tuesday update broke RDP and Hyper-V functionality for some users. Certain USB audio devices reportedly remain affected even after the follow-up fix.
Why it matters: Test the out-of-band fix in a pilot ring before broad Intune deployment — RDP and Hyper-V regressions could disrupt remote admin access or any nested virtualization workflows on managed endpoints.
AWS STS Simplifies Session Token Size Limits
AWS Security Token Service replaced its separate packed policy size and overall session token size limits with a single unified 4,096-byte token size limit. STS now also reports session token size in API responses to support monitoring.
Why it matters: If you use complex session policies or tags for role assumption in AWS GovCloud, review the new unified limit and use the added monitoring to catch tokens approaching the cap before it breaks automation.
AWS Confirms Permanent Loss of Some Middle East Cloud Resources After Wartime Damage
AWS disclosed that Iranian strikes caused damage that overwhelmed regional redundancy in its Bahrain region and left one UAE Availability Zone permanently inaccessible. Some customer cloud resources in the affected areas are gone for good.
Why it matters: A reminder that even hyperscaler regional redundancy has physical limits — validate that GovCloud DR/backup architecture doesn't assume any single region or AZ is invulnerable to catastrophic loss.
Commentary: Federal Acquisition Can't Keep Pace With Cyberattack Speed
A Federal News Network commentary argues that AI has drastically shortened the window between vulnerability discovery and exploitation, while federal procurement processes for cybersecurity tools have not adapted to match that pace.