Customer Security Newsletter - September 2026

Welcome to the September 2026 edition of the MEDITECH Customer Security Newsletter. This month, we provide critical updates on vulnerabilities added to federal catalogs and strategic intelligence on threat actors targeting essential infrastructure. Our goal is to provide you with actionable information and resources to strengthen your organization's security posture. This data has been gleaned from the review of public records on file with CISA, H-ISAC and Health Sector Cybersecurity Coordination Center (HC3) alerts. Please note the Talk To Us section, as we would like to tailor future editions of the newsletter to address specific concerns.


Known Exploited Vulnerabilities

Between August 5, 2026 and September 9, 2026, CISA added 38 items to its "Known Exploited Vulnerabilities" catalog based on definitive evidence of active exploitation in the wild.

CVE RecordTargeted ProductAttack Type
CVE-2026-85880Microsoft WindowsHeap-Based Buffer Overflow
CVE-2026-86218N-able N-centralStatic Code Injection
CVE-2026-81963Microsoft WindowsImproper Link Resolution Before File Access ('Link Following')
CVE-2026-75650Adobe Commerce and MagentoImproper Neutralization of Special Elements Used in a Template Engine
CVE-2026-85046Google Chromium V8Type Confusion
CVE-2026-83549SonicWall SMA1000 AppliancesOS Command Injection
CVE-2026-83548SonicWall SMA1000 AppliancesServer-Side Request Forgery
CVE-2026-9586Sangoma SwitchvoxSQL Injection
CVE-2026-82329JFrog ArtifactoryImproper Authentication
CVE-2026-49869Kestra OSSOS Command Injection
CVE-2026-48710Kludex StarletteHTTP Request/Response Smuggling
CVE-2026-59822BerriAI LiteLLMImproper Authentication
CVE-2026-81578PaperCut NG/MFMissing Authentication for Critical Function
CVE-2026-82078PaperCut NG/MFUnsafe Reflection
CVE-2026-66384JFrog ArtifactoryImproper Limitation of a Pathname to a Restricted Directory
CVE-2026-53362Linux KernelUnspecified
CVE-2023-49105ownCloudImproper Authentication
CVE-2019-1068Microsoft SQL ServerRemote Code Execution
CVE-2026-8452Citrix NetScaler ADC and NetScaler GatewayImproper Restriction of Operations within the Bounds of a Memory Buffer
CVE-2022-0995Linux KernelOut-of-Bounds Write
CVE-2015-5287Red Hat Automatic Bug Reporting ToolPrivilege Escalation
CVE-2015-3246Red Hat LibuserRace Condition
CVE-2021-23758Ajax.NET ProfessionalDeserialization of Untrusted Data
CVE-2026-60004GiteaCode Injection
CVE-2026-21962Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-inImproper Access Control
CVE-2026-73570Zimbra Collaboration Suite (ZCS)OS Command Injection
CVE-2026-72529TrueConf ServerMissing Authentication for Critical Function
CVE-2026-72530TrueConf ServerCode Injection
CVE-2026-64849MLflowServer-Side Request Forgery
CVE-2026-65400Apple macOSImproper Authentication
CVE-2026-55040Microsoft SharePointWeak Authentication
CVE-2026-59310Broadcom VMware vCenterPath Traversal
CVE-2026-33824Microsoft Internet Key Exchange (IKE) Service ExtensionsDouble Free
CVE-2025-62593Ray-Project RayCode Injection
CVE-2026-72898MetabaseSQL Injection
CVE-2026-68820Microsoft Windows Ancillary Function Driver for WinSockUse-After-Free
CVE-2026-20349Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)Heap Inspection
CVE-2026-8037Progress LoadMasterCommand Injection

Threat Actor Spotlight: INC Ransom

First emerging in July 2023, INC Ransom (also tracked as GOLD IONIC) is a prominent double extortion cybercrime group that aggressively targets critical infrastructure, with a heavy emphasis on the healthcare, education, and industrial sectors across North America and Europe. The group operates by exfiltrating sensitive clinical data before deploying encryption, utilizing the threat of public exposure to coerce healthcare facilities into paying ransoms.

  • Targeting Strategy: Healthcare facilities are primary targets due to the strict operational uptime requirements and the high value of protected health information (PHI). Compromising patient records and clinical networks creates immediate leverage to force financial compliance.
  • Initial Access: Attackers gain entry by exploiting known vulnerabilities in internet-facing applications—specifically platforms like Citrix NetScaler—or by using compromised corporate credentials to log in directly via Remote Desktop Protocol (RDP).
  • Operational Behavior: INC Ransom heavily leverages "Living off the Land" (LotL) tactics, utilizing native system tools and dual-use network scanners such as NETSCAN and adfind to discover network resources without triggering alerts. To bypass security software, they tamper with local antivirus configurations using legitimate Windows binaries like SystemSettingsAdminFlows.exe. Before initiating their encryption routine, they exfiltrate sensitive files and frequently attempt to print ransom notes directly on connected office printers and fax machines.
  • Proactive Defense: Healthcare IT administrators should enforce phishing-resistant multi-factor authentication (MFA) across all remote access entry points, apply immediate security patches to edge appliances, isolate network printer subnets, and monitor for unauthorized administrative script executions.

News

FBI Warns of OAuth Consent Phishing Targeting Prominent Individuals

On September 1, 2026, the FBI's IC3 published an alert regarding a rise in "OAuth consent phishing," a sophisticated tactic where malicious actors impersonate trusted figures on messaging apps to trick victims into granting persistent, high-level account access without needing passwords or multi-factor authentication.

Healthcare Cyberattacks Surge 14% as Attackers Target Third-Party Vendors

On Aug 10, 2026, H-ISAC linked an article detailing a 14% rise in healthcare cyberattacks during the first half of the year, emphasizing how hackers are increasingly targeting centralized third-party vendors to compromise multiple hospital networks simultaneously and jeopardize patient safety.

Additional Resources


Talk to us!

We at MEDITECH would love to hear your feedback about this newsletter and we’d like to know what is on your mind. Is there something you would like us to address?

We also have a question for you that is important to us. What are your largest concerns or security hopes for 2026?

Please let us know by contacting us !

Until next time, stay alert out there!