This week in security: Windows zero-days, Flax Typhoon, Oracle Health breach
This weekly security digest for 2026-W41 covers two exploited Windows privilege-escalation flaws, an FBI seizure of Flax Typhoon domains and a reported Oracle Health Cerner breach affecting nearly 20 million people. CISA added eight vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, five of them due for remediation on 11 October 2026.
Top stories
- Windows zero-days CVE-2026-81963, CVE-2026-85880 exploited: two privilege-escalation flaws from September Patch Tuesday are in CISA KEV, so check affected builds first.
- FBI seizes Flax Typhoon domains behind MicroScan and FishHub tools: seven domains were seized, which gives defenders new infrastructure to hunt for.
- CISA AA26-281A: China-linked actors exploit 8 known CVEs: the advisory names ProFTPD, BIND and Struts exposure to check before the 11 October deadline.
- Oracle Health Cerner breach reportedly nears 20 million people: a very large healthcare data exposure, with several details still unconfirmed.
- Rejetto HFS session forgery flaw probed in the wild (CVE-2026-61500): a critical flaw allowing admin cookie forgery and RCE, with a fixed release available.
- Atlassian CVE-2026-21589 file access flaw hits 8 Data Center products: a CVSS 9.3 flaw that lets unauthenticated attackers read known files.
- Fortinet FortiMail path traversal exploited (CVE-2026-104286): CISA says this critical flaw allowing unauthenticated file writes is exploited.
- Exchange Server CVE-2026-96940: mailbox access flaw patched: Microsoft shipped an out-of-band update for a CVSS 8.8 flaw.
- Cisco Meraki hardening release fixes 7 CVEs, up to CVSS 9.6: no workarounds exist, so plan the update.
- Denmark CPR register breach exposes data of 8.8 million people: names, addresses and CPR numbers were exposed.
Also this week: a Qilin ransomware suspect was extradited from Japan to Germany, the MonsterCloud owner was charged with secretly paying ransoms and fake AI ad portals were found using browser-in-the-browser phishing to steal MFA codes.
Newly exploited vulnerabilities
CISA added these eight entries to the KEV catalog this week.
| CVE | Vendor / product | Issue | Due date |
|---|---|---|---|
| CVE-2015-5477 | ISC BIND | Data processing errors | 2026-10-11 |
| CVE-2016-3081 | Apache Struts | Command injection | 2026-10-11 |
| CVE-2023-22894 | Strapi | Cleartext storage of sensitive information | 2026-10-11 |
| CVE-2021-3199 | ONLYOFFICE Docs | Server path traversal | 2026-10-11 |
| CVE-2015-3306 | ProFTPD | Improper access control | 2026-10-11 |
| CVE-2026-88779 | Citrix NetScaler | Memory buffer bounds restriction | 2026-10-07 |
| CVE-2026-102490 | Zammad | Improper privilege management | 2026-10-05 |
| CVE-2026-102489 | Zammad | Session fixation | 2026-10-05 |
Why this matters
Analysis: Several of this week’s KEV entries are old CVEs (2015 to 2023) in widely deployed software such as BIND, Struts and ProFTPD. Attackers keep using flaws that were patched years ago, so unpatched or forgotten internet-facing systems are the realistic risk for a typical environment.
What to prioritise next week
- Check the 11 October KEV deadline items first. Look for BIND, Struts, ProFTPD, Strapi and ONLYOFFICE Docs in your asset inventory; patch or restrict affected Strapi and ONLYOFFICE Docs versions.
- Patch the Windows zero-days (CVE-2026-81963 and CVE-2026-85880) from the September Patch Tuesday release, since both are in KEV.
- Treat Citrix NetScaler (CVE-2026-88779) and Zammad (CVE-2026-102489, CVE-2026-102490) as overdue: their KEV due dates have already passed, so verify they are fixed and review sessions and admin access.
- Review internet-exposed admin tools such as Rejetto HFS (upgrade to the fixed release) and Atlassian Data Center products, and restrict access while you update.
- Hunt for Flax Typhoon activity using the details in our seizure coverage, and check Exchange Server and FortiMail versions against the vendor fixes.
