Cyber Threat Brief — September 26 2026

⚠️ This report is AI-generated. Always validate findings.

1. Microsoft SharePoint ToolPane SafeControls Code Injection — CVE-2026-65660 (NEW CISA KEV)

TL;DR: CISA (2026-09-25) added CVE-2026-65660 (CVSS 8.8, CWE-94) to KEV (due 2026-09-28, forensic triage Yes). Authenticated (low-priv) code injection in on-prem SharePoint ToolPane / WebPart markup: unescaped quotes in RegisterDirective.GetHtml() bypass SafeControls → XamlServices.Parse / LosFormatter deserialization → RCE in w3wp.exe (often in-memory memshell). Microsoft first labeled it “spoofing” (CVSS 6.5), later revised to RCE. Previdian honeypot (2026-09-24): anonymous two-stage chain via AddGallery.aspx / designgallery.aspx?DisplayMode=Edit + MSOTlPn_DWP (depends on anonymous viewing + separate June anonymous-delivery weakness); post-exploit webshell /_layouts/15/sphealth.aspx. Fixed builds: 2016 ≥16.0.5565.1001, 2019 ≥16.0.10417.20198, Subscription Edition ≥16.0.19725.20522 (Aug 11 2026 / KB5002893 train).

What’s New:

  • First KEV listing (2026.09.25 / 1726); Microsoft confirmed observed attacks as of 2026-09-25
  • Previdian: ITW prefers AddGallery/designgallery — ToolPane-only hunts miss this burst
  • Disk IoC amplify: sphealth.aspx + side-loaded wt3k3sij.dll / 24e5mo4s.dll (SHA-256 below)

Actionable Intel

ArtifactTypeATT&CKLog SourceAction
CVE-2026-65660 on SharePoint Server 2016 <16.0.5565.1001, 2019 <16.0.10417.20198, Subscription Edition <16.0.19725.20522 (fix: Aug 2026 security updates / KB5002893; apply all packages offered for the SKU)Vulnerable collab / KEVT1190SharePoint build / patch inventoryPatch farms; 2016/2019 are EOL since 2026-07-15 — migrate; enable AMSI Full Mode; restrict internet exposure of /_layouts/15/*; finish forensic triage by 2026-09-28
POST to /_layouts/15/AddGallery.aspx or /_layouts/15/designgallery.aspx (incl. repeated /_layouts/ prefixes) with DisplayMode=Edit + form fields MSOTlPn_Uri / MSOTlPn_DWP; bodies containing ExpandedWrapper, XamlServices, ObjectDataProvider, LosFormatter, or ActivitySurrogateExploit probe / chainT1190IIS / WAF / reverse-proxyAlert + block those gadget strings; do not hunt only ToolPane.aspx — Previdian ITW used AddGallery/designgallery
Webshell /_layouts/15/sphealth.aspx; DLLs wt3k3sij.dll (SHA-256 d3faa4b443d98f272363f3484a5e6a9bab90979086aa2d31a1694c1dc8178742) / 24e5mo4s.dll (SHA-256 a151a8fc193a96aac480fa749547b57c0f33116cf2cb8c82b6aa716c3c47f4b1); source IP seen in Previdian burst 169.150.248.21Post-exploit / IoCT1505.003EDR file / IISHunt LAYOUTS for unexpected .aspx; rotate SharePoint machine keys + app-pool creds if hit; w3wp.exe → cmd.exe/powershell.exe

Detection

SourceRuleGap
Splunk ESCUPartial — Windows SharePoint ToolPane Endpoint Exploitation Attempt (POST */_layouts/15/ToolPane.aspx* + DisplayMode=Edit; written for CVE-2025-53770 ToolShell). Logic would catch classic ToolPane path. Rejected spinstall0 analytics — ToolShell webshell name, not sphealth.aspx. Partial post-exploit: Web or Application Server Spawning a Shell / Windows Suspicious Child Process Spawned From WebServer (ParentImage w3wp.exe → shells)No CVE-2026-65660 / AddGallery-specific analytic; ToolPane-only misses Previdian paths
ElasticPartial — Potential IIS Web Shell File Creation (persistence_web_shell_aspx_write.toml): w3wp.exe writing .aspx under Web Server Extensions\*\TEMPLATE\LAYOUTS\ — would catch sphealth.aspx disk drop. No on-prem ToolPane/AddGallery HTTP rule for this CVENo CVE-2026-65660 emerging-threat rule; memshell-only path leaves no file
SigmaPartial — Suspicious File Write to SharePoint Layouts Directory (file_event_win_susp_filewrite_in_sharepoint_layouts_dir.yml): w3wp.exe/cmd/powershell writing .aspx to LAYOUTS — disk webshell aspect. No HTTP ToolPane/AddGallery ET rule for CVE-2026-65660No emerging-threat rule for CVE-2026-65660

Hunt hint: (1) Confirm builds ≥ fixed table. (2) Grep IIS for AddGallery.aspx|designgallery.aspx + DisplayMode=Edit + MSOTlPn_DWP since 2026-08-11. (3) LAYOUTS for sphealth.aspx. (4) Assume compromise on internet-facing anonymous farms — rotate machine keys.

Sources: CISA KEV alert 2026-09-25 (two CVEs), MSRC CVE-2026-65660, Canadian Centre AL26-023, Previdian honeypot, The Hacker News, SecurityAffairs


2. Oracle PeopleSoft PSEMHUB WAF-Bypass Mass Exploit — CVE-2026-35273 (UNC6240 / ShinyHunters renewed)

TL;DR: Mandiant/GTIG (2026-09-25): UNC6240 (ShinyHunters) resumed mass exploitation of CVE-2026-35273 (PeopleSoft PeopleTools 8.61/8.62 EMHub / PSEMHUB, CVSS 9.8, already on KEV since 2026-06-12, ransomware Known). New wave bypasses literal WAF path blocks by requesting /%50SEMHUB/ (%50 = P) — many WAFs match pre-decode; WebLogic decodes to /PSEMHUB/. Dozens of webshells across education, tech, IT services, healthcare, agriculture, transport, government. Post-exploit: x.jsp / u.jsp (hex/Base64 shells), Neo-reGeorg tunnel.jsp(x), Windows Ple64.exe (SHA-256 3ba215692665513abfffd4e815c5c45f2d41e5dcc4283a2a3b740930c5c417c3) → in-memory SIDEEYE C2 162.219.30.165:3333/3334, MeshAgent via winmanage-me.network / 104.219.234.138. Patch — do not rely on WAF.

What’s New:

  • Renewed N-day campaign adapting to June WAF guidance (Mandiant primary)
  • Actionable encoded-path + SIDEEYE / Ple64 / dual-JSP IoCs for DE hunts
  • Distinct from Sep 25 audit’s “unverified FBI claim” exclusion — Mandiant now confirms global mass exploit

Actionable Intel

ArtifactTypeATT&CKLog SourceAction
CVE-2026-35273 on PeopleSoft PeopleTools 8.61 / 8.62 with EMHub / PSEMHUB exposed (Oracle Security Alert 2026-06-10)Vulnerable ERP / KEVT1190PeopleTools version / EMHub inventoryApply Oracle alert patch; disable EMHub (multi-server) or remove PSEMHUB app (single-server); never treat WAF-only as mitigation
HTTP path /%50SEMHUB/ (and any percent-encoded / mixed-case /PSEMHUB/ variant); POST /%50SEMHUB/hub with serialized Java body (5–15 verify probes); follow-on .jsp under PSEMHUBExploit / WAF bypassT1190 / T1027PIA WebLogic access / WAF (normalized URI)Block on normalized path; hunt both /PSEMHUB/ and /%50SEMHUB/ (and other encodings) from external IPs
Host: <PS_CFG_HOME>/webserv/<domain>/applications/peoplesoft/PSEMHUB.war/ files x.jsp (SHA-256 48b4a0827da7bbfce9fb52464f8a659dea7a035189c52c506c0bfb4b1c3fe494), u.jsp (2bee941fb40519d0d1ec52bd79a8f63fc65aac6455c8f2d6b668e3360dfdb5d7), tunnel.jsp / tunnel.jspx, Ple64.exe (3ba215692665513abfffd4e815c5c45f2d41e5dcc4283a2a3b740930c5c417c3); C2 162.219.30.165 TCP 3333/3334; staging 5.199.162.157, 104.219.234.138, winmanage-me.networkWebshell / SIDEEYE / C2T1505.003 / T1219 / T1090EDR / NetFlow / WebLogic FSWipe unexpected JSP/EXE under PSEMHUB.war; alert java/WebLogic → cmd.exe//bin/sh; rotate DB/IB/cloud creds from psappsrv.cfg; treat as compromised if shell found

Detection

SourceRuleGap
Splunk ESCUNone — verified search for CVE-2026-35273 / PSEMHUB / %50SEMHUB / SIDEEYE / Ple64. Partial only for fileless post-exploit: Web or Application Server Spawning a Shell (parent_process_name java / java.exe → shells) — would catch Mandiant’s fileless cmd.exe//bin/sh spawn, not the WAF-bypass HTTP pathNo PeopleSoft / PSEMHUB analytic
ElasticNone — verified search for PeopleSoft / PSEMHUB / SIDEEYE / CVE-2026-35273No Frontline-equivalent rule in local tree (Mandiant notes SecOps pack separately)
SigmaNone — verified searchNo emerging-threat rule for CVE-2026-35273 / %50SEMHUB

Hunt hint: (1) Patch + disable/remove EMHub. (2) Access logs: /PSEMHUB/ and /%50SEMHUB/ POSTs to /hub. (3) Inventory all load-balanced WebLogic nodes for x.jsp/u.jsp/Ple64.exe. (4) Outbound to 162.219.30.165:3333/3334 and MeshAgent domains.

Sources: Mandiant/GTIG renewed campaign 2026-09-25, Mandiant June 2026 zero-day post, CyberInsider, CISA KEV entry CVE-2026-35273, The Hacker News


3. Roundcube virtuser_query Pre-Auth SQL Injection — CVE-2026-48842 (ITW)

TL;DR: Canadian Centre for Cyber Security (AV26-503 Update 1, updated 2026-09-21, amplified 2026-09-25): CVE-2026-48842 (CVSS 8.1) pre-authentication SQL injection in Roundcube Webmail plugins/virtuser_query via preg_replace() backslash-escape bypass — unauth attacker can inject SQL → mail credentials / stored messages. Affects 1.6.x <1.6.16 and 1.7.x <1.7.1; fixed 1.6.16 / 1.7.1 (May 2026). Shadowserver: ~523k internet-exposed Roundcube; 10 flagged vulnerable as of 2026-09-23. Not on KEV (as of catalog 2026.09.25). Prior Roundcube ITW context: UNK_MassTraction / VShell (Jul 2026); older KEV pair CVE-2025-49113 / CVE-2025-68461.

What’s New:

  • Official Canadian Centre ITW confirmation (open-source reporting) — elevates from patched-but-latent to active hunt
  • High exposure surface vs low remaining vulnerable count — still patch/verify virtuser_query deployments
  • Concrete fix trains + plugin path for DE inventory

Actionable Intel

ArtifactTypeATT&CKLog SourceAction
CVE-2026-48842 on Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 with plugins/virtuser_query enabled (fix: ≥1.6.16 or ≥1.7.1; commits 3406183a / 87124cc)Vulnerable webmailT1190 / T1190+T1213Package / container inventory (roundcube --version / composer)Upgrade all instances; disable virtuser_query if unused until patched
Pre-auth HTTP requests hitting virtuser_query login/identity mapping with anomalous SQL metacharacters / backslash-escape patterns in mapped identity fieldsExploit probeT1190Web / reverse-proxy / Roundcube logsAlert unauth SQLi-shaped payloads to virtuser endpoints; correlate with sudden mailbox dumps
Post-exploit: unexpected PHP webshells under Roundcube webroot; mass mailbox access / credential table reads; historical UNK_MassTraction → VShell patternImpactT1505.003 / T1114EDR / mail DB auditIf vulnerable during ITW window: rotate mailbox creds, review users/identities tables, hunt webshells

Detection

SourceRuleGap
Splunk ESCUNone — verified search for CVE-2026-48842 / Roundcube / virtuser_queryNo Roundcube analytic
ElasticNone — verified search (rejected generic Linux webserver file-create — wrong class)No Roundcube / CVE-2026-48842 rule
SigmaNone — verified searchNo emerging-threat rule for CVE-2026-48842

Hunt hint: (1) Inventory Roundcube versions — flag <1.6.16 / <1.7.1. (2) Confirm whether virtuser_query is enabled. (3) Review web logs for pre-auth anomalies to identity-mapping endpoints since 2026-09-21. (4) Shadowserver exposure is low on known-vulnerable — still verify internal/on-prem copies.

Sources: Canadian Centre AV26-503 Update 1, The Hacker News, Roundcube 1.6.16 release, Fix commit 87124cc, NVD CVE-2026-48842


Status Updates

  • CVE-2026-87902 (WordPress Core): NEW CISA KEV (2026-09-25, due 2026-09-28, forensic triage Yes) — was Sep 24 lead; still patch ≥7.1.2 (branch backports through 4.7.37); keep pearcmd /tmp/wp-pear-*.php + double-encoded pagename hunts. Sep 24
  • CVE-2026-67279 (MikroTik RouterOS SSH rekey→channel): NEW CISA KEV (2026-09-25, due 2026-09-28, forensic triage No) — MikroTrick prerequisite chained with CVE-2026-86060; fix RouterOS ≥6.49.21 / ≥7.23.4 / ≥7.24.2; hunt login failure for user -2 + privileged ops account; restrict SSH. Amplify of Sep 06 MikroTrick · CERT.pl deep-dive.
  • CVE-2026-5430 (WSO2) / CVE-2026-71362 (Adobe Magento): KEV due TOMORROW 2026-09-27 (forensic triage Yes) — finish update levels / -2026-aug patches; JWT alg + editPost id= hunts. Sep 25
  • CVE-2026-94127 (F5) / CVE-2026-93616 (CP Mgmt) / CVE-2026-93952 (Arista) / CVE-2026-85102 (CP VPN) / CVE-2026-42016+42018 (JFrog): KEV due was 2026-09-25 — confirm Eng HF / Jumbo / VCO ≥5.2.3.16|≥6.4.2.8 / sk1000117 / Artifactory patch + hunts. Sep 23 · Sep 12 · Sep 11
  • CVE-2026-61674 (Fluent Bit): No material change — keep agents ≥5.0.8. Sep 25
  • CVE-2026-63077 (TeamCity) / CVE-2026-80521 (Ubuntu AF_UNIX) / CVE-2026-32996 (Veeam) / CVE-2026-93485 (Comment2Shell): No material change — TeamCity ≥2025.11.7/≥2026.1.3, Veeam Agent 13.0.3.1220, WP Comment2Shell ≥7.1.1 (87902 still needs ≥7.1.2). Sep 24 · Sep 22