Welcome to the September 2026 edition of the MEDITECH Customer Security Newsletter. This month, we provide critical updates on vulnerabilities added to federal catalogs and strategic intelligence on threat actors targeting essential infrastructure. Our goal is to provide you with actionable information and resources to strengthen your organization's security posture. This data has been gleaned from the review of public records on file with CISA, H-ISAC and Health Sector Cybersecurity Coordination Center (HC3) alerts. Please note the Talk To Us section, as we would like to tailor future editions of the newsletter to address specific concerns.
Known Exploited Vulnerabilities
Between August 5, 2026 and September 9, 2026, CISA added 38 items to its "Known Exploited Vulnerabilities" catalog based on definitive evidence of active exploitation in the wild.
| CVE Record | Targeted Product | Attack Type |
|---|---|---|
| CVE-2026-85880 | Microsoft Windows | Heap-Based Buffer Overflow |
| CVE-2026-86218 | N-able N-central | Static Code Injection |
| CVE-2026-81963 | Microsoft Windows | Improper Link Resolution Before File Access ('Link Following') |
| CVE-2026-75650 | Adobe Commerce and Magento | Improper Neutralization of Special Elements Used in a Template Engine |
| CVE-2026-85046 | Google Chromium V8 | Type Confusion |
| CVE-2026-83549 | SonicWall SMA1000 Appliances | OS Command Injection |
| CVE-2026-83548 | SonicWall SMA1000 Appliances | Server-Side Request Forgery |
| CVE-2026-9586 | Sangoma Switchvox | SQL Injection |
| CVE-2026-82329 | JFrog Artifactory | Improper Authentication |
| CVE-2026-49869 | Kestra OSS | OS Command Injection |
| CVE-2026-48710 | Kludex Starlette | HTTP Request/Response Smuggling |
| CVE-2026-59822 | BerriAI LiteLLM | Improper Authentication |
| CVE-2026-81578 | PaperCut NG/MF | Missing Authentication for Critical Function |
| CVE-2026-82078 | PaperCut NG/MF | Unsafe Reflection |
| CVE-2026-66384 | JFrog Artifactory | Improper Limitation of a Pathname to a Restricted Directory |
| CVE-2026-53362 | Linux Kernel | Unspecified |
| CVE-2023-49105 | ownCloud | Improper Authentication |
| CVE-2019-1068 | Microsoft SQL Server | Remote Code Execution |
| CVE-2026-8452 | Citrix NetScaler ADC and NetScaler Gateway | Improper Restriction of Operations within the Bounds of a Memory Buffer |
| CVE-2022-0995 | Linux Kernel | Out-of-Bounds Write |
| CVE-2015-5287 | Red Hat Automatic Bug Reporting Tool | Privilege Escalation |
| CVE-2015-3246 | Red Hat Libuser | Race Condition |
| CVE-2021-23758 | Ajax.NET Professional | Deserialization of Untrusted Data |
| CVE-2026-60004 | Gitea | Code Injection |
| CVE-2026-21962 | Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in | Improper Access Control |
| CVE-2026-73570 | Zimbra Collaboration Suite (ZCS) | OS Command Injection |
| CVE-2026-72529 | TrueConf Server | Missing Authentication for Critical Function |
| CVE-2026-72530 | TrueConf Server | Code Injection |
| CVE-2026-64849 | MLflow | Server-Side Request Forgery |
| CVE-2026-65400 | Apple macOS | Improper Authentication |
| CVE-2026-55040 | Microsoft SharePoint | Weak Authentication |
| CVE-2026-59310 | Broadcom VMware vCenter | Path Traversal |
| CVE-2026-33824 | Microsoft Internet Key Exchange (IKE) Service Extensions | Double Free |
| CVE-2025-62593 | Ray-Project Ray | Code Injection |
| CVE-2026-72898 | Metabase | SQL Injection |
| CVE-2026-68820 | Microsoft Windows Ancillary Function Driver for WinSock | Use-After-Free |
| CVE-2026-20349 | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) | Heap Inspection |
| CVE-2026-8037 | Progress LoadMaster | Command Injection |
Threat Actor Spotlight: INC Ransom
First emerging in July 2023, INC Ransom (also tracked as GOLD IONIC) is a prominent double extortion cybercrime group that aggressively targets critical infrastructure, with a heavy emphasis on the healthcare, education, and industrial sectors across North America and Europe. The group operates by exfiltrating sensitive clinical data before deploying encryption, utilizing the threat of public exposure to coerce healthcare facilities into paying ransoms.
- Targeting Strategy: Healthcare facilities are primary targets due to the strict operational uptime requirements and the high value of protected health information (PHI). Compromising patient records and clinical networks creates immediate leverage to force financial compliance.
- Initial Access: Attackers gain entry by exploiting known vulnerabilities in internet-facing applications—specifically platforms like Citrix NetScaler—or by using compromised corporate credentials to log in directly via Remote Desktop Protocol (RDP).
- Operational Behavior: INC Ransom heavily leverages "Living off the Land" (LotL) tactics, utilizing native system tools and dual-use network scanners such as NETSCAN and adfind to discover network resources without triggering alerts. To bypass security software, they tamper with local antivirus configurations using legitimate Windows binaries like SystemSettingsAdminFlows.exe. Before initiating their encryption routine, they exfiltrate sensitive files and frequently attempt to print ransom notes directly on connected office printers and fax machines.
- Proactive Defense: Healthcare IT administrators should enforce phishing-resistant multi-factor authentication (MFA) across all remote access entry points, apply immediate security patches to edge appliances, isolate network printer subnets, and monitor for unauthorized administrative script executions.
News
FBI Warns of OAuth Consent Phishing Targeting Prominent Individuals
On September 1, 2026, the FBI's IC3 published an alert regarding a rise in "OAuth consent phishing," a sophisticated tactic where malicious actors impersonate trusted figures on messaging apps to trick victims into granting persistent, high-level account access without needing passwords or multi-factor authentication.
Healthcare Cyberattacks Surge 14% as Attackers Target Third-Party Vendors
On Aug 10, 2026, H-ISAC linked an article detailing a 14% rise in healthcare cyberattacks during the first half of the year, emphasizing how hackers are increasingly targeting centralized third-party vendors to compromise multiple hospital networks simultaneously and jeopardize patient safety.
Additional Resources
- HHS 405(d) Aligning Health Care Industry Security Approaches - The 405(d) Program and Task Group is a collaborative effort between industry and the federal government, which aims to raise awareness, provide vetted cybersecurity practices, and move healthcare organizations towards consistency in mitigating the current most pertinent cybersecurity threats to the sector. Their website provides the latest resources and information as well as an opportunity for involvement.
- Helpful resources CISA has provided can be found on the following pages:
Talk to us!
We at MEDITECH would love to hear your feedback about this newsletter and we’d like to know what is on your mind. Is there something you would like us to address?
We also have a question for you that is important to us. What are your largest concerns or security hopes for 2026?
Please let us know by contacting us !
Until next time, stay alert out there!
