STRATQUAD
CYBER THREAT INTELLIGENCE BRIEF
Daily Brief · 11 September 2026 · 24h windowRISKCRITICAL
StratQuad CTI Daily Brief, 11 September 2026

Compiled from 52 monitored sources · 319 articles reviewed

Today’s Briefing

CISA added two MikroTik RouterOS vulnerabilities to the KEV catalogue, CVE-2026-67277 (missing authentication in the btest service allowing kernel memory disclosure and denial of service) and CVE-2026-86060 (argument delimiter neutralisation flaw enabling privilege escalation via policy mask manipulation), both under active exploitation. Check Point published an advisory for CVE-2026-85102, a critical unauthenticated remote code execution flaw in Security Gateway that could lead to complete device compromise. ConnectWise patched CVE-2026-84869 in ScreenConnect, a vulnerability permitting unauthorised file transfer and execution through active remote sessions. Multiple critical Chrome vulnerabilities appeared on the watchlist including CVE-2026-87654 (buffer overflow in ANGLE on Windows), CVE-2026-87650 (out of bounds read in WebGL), and CVE-2026-87646 (use after free in Web Authentication), all rated for potential arbitrary code execution outside the sandbox.

Top Stories

  1. BlueMoon exploit kit turns Chrome and Windows flaws into attacks
  2. CC-4849 - Check Point Releases Security Advisory for Critical Vulnerability in Security Gateway
  3. CISA Adds Two Known Exploited Vulnerabilities to Catalog
  4. AVEVA Pipeline Integrity Monitor
  5. CC-4848 - ConnectWise Releases Security Update for ScreenConnect

Full brief available to subscribers

The complete operator brief — action items with patch deadlines, the vulnerability appendix and named actor activity — goes out by email each morning. Subscribe free to receive it.

All briefs