Daily Signal — 2026-09-11
This is FLLC's automated morning scan of named public sources. It is intentionally concise: what changed, why it may matter, what to verify next, and where the claim came from. 5/5 sources were live for this edition.
At a glance
- CVE-2026-86060 leads the latest CISA exploited-vulnerability entries.
- CISA advisory watch: China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies.
- M5.9 was the strongest M4.5+ event in the USGS 24-hour feed.
- Falcon 9 Block 5 | USSF-153 is next on the public launch manifest.
Exploited vulnerabilities
- CVE-2026-86060 — MikroTik RouterOS. Added 2026-09-10; remediation due 2026-09-13. MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacked to change the trusted RouterOS policy mask, leading to privilege escalation. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- CVE-2026-67277 — MikroTik RouterOS. Added 2026-09-10; remediation due 2026-09-13. MikroTik RouterOS contains a missing authenticaion for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- CVE-2026-19490 — Citrix NetScaler. Added 2026-09-09; remediation due 2026-09-12. Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
KEV priority queue
- CVE-2026-86060 · MikroTik RouterOS · added 2026-09-10 · due 2026-09-13
- CVE-2026-67277 · MikroTik RouterOS · added 2026-09-10 · due 2026-09-13
- CVE-2026-19490 · Citrix NetScaler · added 2026-09-09 · due 2026-09-12
- CVE-2025-25249 · Fortinet Multiple Products · added 2026-09-09 · due 2026-09-12
- CVE-2026-87491 · Google Chromium V8 · added 2026-09-09 · due 2026-09-23
- CVE-2026-20079 · Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management · added 2026-09-09 · due 2026-09-12
- CVE-2026-75650 · Adobe Commerce and Magento · added 2026-09-08 · due 2026-09-11
- CVE-2026-81963 · Microsoft Windows · added 2026-09-08 · due 2026-09-22
Defensive move: match the cited products against your actual inventory, follow the vendor remediation, and prioritize internet-facing or privileged systems. A catalog entry is evidence of exploitation in the wild—not proof that your environment is compromised.
Threat-actor and campaign watch
- China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies — published 2026-09-08 12:00 UTC. This is an actor-linked signal because the official CISA title or summary explicitly names an actor, campaign, or ransomware operation; FLLC is not independently assigning attribution.
Trace responsibly: preserve the source and timestamp, map only explicitly reported infrastructure and MITRE ATT&CK behaviors, separate observed facts from assessment, and record confidence. A vendor, geography, malware family, or IP address alone is not actor attribution.
Earth systems
-
M5.9 — 253 km ENE of Lospalos, Timor Leste, 2026-09-11 11:56 UTC. The M4.5+ day feed contained 7 events when retrieved. Open the USGS event.
-
NOAA space-weather data was unavailable or malformed during this run.
Interpretation boundary: earthquake magnitude does not establish local impact, and Kp is planetary-scale context. Follow the issuing agency and local authorities for decisions.
Orbital watch
- Falcon 9 Block 5 | USSF-153 — SpaceX; Launch Successful; no-earlier-than 2026-09-10 15:42 UTC. Pad: Space Launch Complex 4E · Vandenberg SFB, CA, USA.
Launch times and status can move. Confirm with the launch provider before travel, viewing, or operational decisions.
Source health
- CISA: live
- ADVISORIES: live
- USGS: live
- NOAA: live
- LAUNCHES: live
Primary sources
- CISA Known Exploited Vulnerabilities
- CISA Cybersecurity Advisories
- USGS M4.5+ earthquakes, past day
- NOAA SWPC planetary K-index
- Launch Library 2 upcoming manifest
Retrieved 2026-09-11 15:15 UTC. Automated, source-linked, and reviewed by machine rules for completeness. It is not emergency, navigational, investment, or legal advice.