Cyber Threat Brief — September 26 2026
1. Microsoft SharePoint ToolPane SafeControls Code Injection — CVE-2026-65660 (NEW CISA KEV)
TL;DR: CISA (2026-09-25) added CVE-2026-65660 (CVSS 8.8, CWE-94) to KEV (due 2026-09-28, forensic triage Yes). Authenticated (low-priv) code injection in on-prem SharePoint ToolPane / WebPart markup: unescaped quotes in RegisterDirective.GetHtml() bypass SafeControls → XamlServices.Parse / LosFormatter deserialization → RCE in w3wp.exe (often in-memory memshell). Microsoft first labeled it “spoofing” (CVSS 6.5), later revised to RCE. Previdian honeypot (2026-09-24): anonymous two-stage chain via AddGallery.aspx / designgallery.aspx?DisplayMode=Edit + MSOTlPn_DWP (depends on anonymous viewing + separate June anonymous-delivery weakness); post-exploit webshell /_layouts/15/sphealth.aspx. Fixed builds: 2016 ≥16.0.5565.1001, 2019 ≥16.0.10417.20198, Subscription Edition ≥16.0.19725.20522 (Aug 11 2026 / KB5002893 train).
What’s New:
- First KEV listing (2026.09.25 / 1726); Microsoft confirmed observed attacks as of 2026-09-25
- Previdian: ITW prefers AddGallery/designgallery — ToolPane-only hunts miss this burst
- Disk IoC amplify:
sphealth.aspx+ side-loadedwt3k3sij.dll/24e5mo4s.dll(SHA-256 below)
Actionable Intel
| Artifact | Type | ATT&CK | Log Source | Action |
|---|---|---|---|---|
| CVE-2026-65660 on SharePoint Server 2016 <16.0.5565.1001, 2019 <16.0.10417.20198, Subscription Edition <16.0.19725.20522 (fix: Aug 2026 security updates / KB5002893; apply all packages offered for the SKU) | Vulnerable collab / KEV | T1190 | SharePoint build / patch inventory | Patch farms; 2016/2019 are EOL since 2026-07-15 — migrate; enable AMSI Full Mode; restrict internet exposure of /_layouts/15/*; finish forensic triage by 2026-09-28 |
POST to /_layouts/15/AddGallery.aspx or /_layouts/15/designgallery.aspx (incl. repeated /_layouts/ prefixes) with DisplayMode=Edit + form fields MSOTlPn_Uri / MSOTlPn_DWP; bodies containing ExpandedWrapper, XamlServices, ObjectDataProvider, LosFormatter, or ActivitySurrogate | Exploit probe / chain | T1190 | IIS / WAF / reverse-proxy | Alert + block those gadget strings; do not hunt only ToolPane.aspx — Previdian ITW used AddGallery/designgallery |
Webshell /_layouts/15/sphealth.aspx; DLLs wt3k3sij.dll (SHA-256 d3faa4b443d98f272363f3484a5e6a9bab90979086aa2d31a1694c1dc8178742) / 24e5mo4s.dll (SHA-256 a151a8fc193a96aac480fa749547b57c0f33116cf2cb8c82b6aa716c3c47f4b1); source IP seen in Previdian burst 169.150.248.21 | Post-exploit / IoC | T1505.003 | EDR file / IIS | Hunt LAYOUTS for unexpected .aspx; rotate SharePoint machine keys + app-pool creds if hit; w3wp.exe → cmd.exe/powershell.exe |
Detection
| Source | Rule | Gap |
|---|---|---|
| Splunk ESCU | Partial — Windows SharePoint ToolPane Endpoint Exploitation Attempt (POST */_layouts/15/ToolPane.aspx* + DisplayMode=Edit; written for CVE-2025-53770 ToolShell). Logic would catch classic ToolPane path. Rejected spinstall0 analytics — ToolShell webshell name, not sphealth.aspx. Partial post-exploit: Web or Application Server Spawning a Shell / Windows Suspicious Child Process Spawned From WebServer (ParentImage w3wp.exe → shells) | No CVE-2026-65660 / AddGallery-specific analytic; ToolPane-only misses Previdian paths |
| Elastic | Partial — Potential IIS Web Shell File Creation (persistence_web_shell_aspx_write.toml): w3wp.exe writing .aspx under Web Server Extensions\*\TEMPLATE\LAYOUTS\ — would catch sphealth.aspx disk drop. No on-prem ToolPane/AddGallery HTTP rule for this CVE | No CVE-2026-65660 emerging-threat rule; memshell-only path leaves no file |
| Sigma | Partial — Suspicious File Write to SharePoint Layouts Directory (file_event_win_susp_filewrite_in_sharepoint_layouts_dir.yml): w3wp.exe/cmd/powershell writing .aspx to LAYOUTS — disk webshell aspect. No HTTP ToolPane/AddGallery ET rule for CVE-2026-65660 | No emerging-threat rule for CVE-2026-65660 |
Hunt hint: (1) Confirm builds ≥ fixed table. (2) Grep IIS for AddGallery.aspx|designgallery.aspx + DisplayMode=Edit + MSOTlPn_DWP since 2026-08-11. (3) LAYOUTS for sphealth.aspx. (4) Assume compromise on internet-facing anonymous farms — rotate machine keys.
Sources: CISA KEV alert 2026-09-25 (two CVEs), MSRC CVE-2026-65660, Canadian Centre AL26-023, Previdian honeypot, The Hacker News, SecurityAffairs
2. Oracle PeopleSoft PSEMHUB WAF-Bypass Mass Exploit — CVE-2026-35273 (UNC6240 / ShinyHunters renewed)
TL;DR: Mandiant/GTIG (2026-09-25): UNC6240 (ShinyHunters) resumed mass exploitation of CVE-2026-35273 (PeopleSoft PeopleTools 8.61/8.62 EMHub / PSEMHUB, CVSS 9.8, already on KEV since 2026-06-12, ransomware Known). New wave bypasses literal WAF path blocks by requesting /%50SEMHUB/ (%50 = P) — many WAFs match pre-decode; WebLogic decodes to /PSEMHUB/. Dozens of webshells across education, tech, IT services, healthcare, agriculture, transport, government. Post-exploit: x.jsp / u.jsp (hex/Base64 shells), Neo-reGeorg tunnel.jsp(x), Windows Ple64.exe (SHA-256 3ba215692665513abfffd4e815c5c45f2d41e5dcc4283a2a3b740930c5c417c3) → in-memory SIDEEYE C2 162.219.30.165:3333/3334, MeshAgent via winmanage-me.network / 104.219.234.138. Patch — do not rely on WAF.
What’s New:
- Renewed N-day campaign adapting to June WAF guidance (Mandiant primary)
- Actionable encoded-path + SIDEEYE / Ple64 / dual-JSP IoCs for DE hunts
- Distinct from Sep 25 audit’s “unverified FBI claim” exclusion — Mandiant now confirms global mass exploit
Actionable Intel
| Artifact | Type | ATT&CK | Log Source | Action |
|---|---|---|---|---|
| CVE-2026-35273 on PeopleSoft PeopleTools 8.61 / 8.62 with EMHub / PSEMHUB exposed (Oracle Security Alert 2026-06-10) | Vulnerable ERP / KEV | T1190 | PeopleTools version / EMHub inventory | Apply Oracle alert patch; disable EMHub (multi-server) or remove PSEMHUB app (single-server); never treat WAF-only as mitigation |
HTTP path /%50SEMHUB/ (and any percent-encoded / mixed-case /PSEMHUB/ variant); POST /%50SEMHUB/hub with serialized Java body (5–15 verify probes); follow-on .jsp under PSEMHUB | Exploit / WAF bypass | T1190 / T1027 | PIA WebLogic access / WAF (normalized URI) | Block on normalized path; hunt both /PSEMHUB/ and /%50SEMHUB/ (and other encodings) from external IPs |
Host: <PS_CFG_HOME>/webserv/<domain>/applications/peoplesoft/PSEMHUB.war/ files x.jsp (SHA-256 48b4a0827da7bbfce9fb52464f8a659dea7a035189c52c506c0bfb4b1c3fe494), u.jsp (2bee941fb40519d0d1ec52bd79a8f63fc65aac6455c8f2d6b668e3360dfdb5d7), tunnel.jsp / tunnel.jspx, Ple64.exe (3ba215692665513abfffd4e815c5c45f2d41e5dcc4283a2a3b740930c5c417c3); C2 162.219.30.165 TCP 3333/3334; staging 5.199.162.157, 104.219.234.138, winmanage-me.network | Webshell / SIDEEYE / C2 | T1505.003 / T1219 / T1090 | EDR / NetFlow / WebLogic FS | Wipe unexpected JSP/EXE under PSEMHUB.war; alert java/WebLogic → cmd.exe//bin/sh; rotate DB/IB/cloud creds from psappsrv.cfg; treat as compromised if shell found |
Detection
| Source | Rule | Gap |
|---|---|---|
| Splunk ESCU | None — verified search for CVE-2026-35273 / PSEMHUB / %50SEMHUB / SIDEEYE / Ple64. Partial only for fileless post-exploit: Web or Application Server Spawning a Shell (parent_process_name java / java.exe → shells) — would catch Mandiant’s fileless cmd.exe//bin/sh spawn, not the WAF-bypass HTTP path | No PeopleSoft / PSEMHUB analytic |
| Elastic | None — verified search for PeopleSoft / PSEMHUB / SIDEEYE / CVE-2026-35273 | No Frontline-equivalent rule in local tree (Mandiant notes SecOps pack separately) |
| Sigma | None — verified search | No emerging-threat rule for CVE-2026-35273 / %50SEMHUB |
Hunt hint: (1) Patch + disable/remove EMHub. (2) Access logs: /PSEMHUB/ and /%50SEMHUB/ POSTs to /hub. (3) Inventory all load-balanced WebLogic nodes for x.jsp/u.jsp/Ple64.exe. (4) Outbound to 162.219.30.165:3333/3334 and MeshAgent domains.
Sources: Mandiant/GTIG renewed campaign 2026-09-25, Mandiant June 2026 zero-day post, CyberInsider, CISA KEV entry CVE-2026-35273, The Hacker News
3. Roundcube virtuser_query Pre-Auth SQL Injection — CVE-2026-48842 (ITW)
TL;DR: Canadian Centre for Cyber Security (AV26-503 Update 1, updated 2026-09-21, amplified 2026-09-25): CVE-2026-48842 (CVSS 8.1) pre-authentication SQL injection in Roundcube Webmail plugins/virtuser_query via preg_replace() backslash-escape bypass — unauth attacker can inject SQL → mail credentials / stored messages. Affects 1.6.x <1.6.16 and 1.7.x <1.7.1; fixed 1.6.16 / 1.7.1 (May 2026). Shadowserver: ~523k internet-exposed Roundcube; 10 flagged vulnerable as of 2026-09-23. Not on KEV (as of catalog 2026.09.25). Prior Roundcube ITW context: UNK_MassTraction / VShell (Jul 2026); older KEV pair CVE-2025-49113 / CVE-2025-68461.
What’s New:
- Official Canadian Centre ITW confirmation (open-source reporting) — elevates from patched-but-latent to active hunt
- High exposure surface vs low remaining vulnerable count — still patch/verify virtuser_query deployments
- Concrete fix trains + plugin path for DE inventory
Actionable Intel
| Artifact | Type | ATT&CK | Log Source | Action |
|---|---|---|---|---|
CVE-2026-48842 on Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 with plugins/virtuser_query enabled (fix: ≥1.6.16 or ≥1.7.1; commits 3406183a / 87124cc) | Vulnerable webmail | T1190 / T1190+T1213 | Package / container inventory (roundcube --version / composer) | Upgrade all instances; disable virtuser_query if unused until patched |
| Pre-auth HTTP requests hitting virtuser_query login/identity mapping with anomalous SQL metacharacters / backslash-escape patterns in mapped identity fields | Exploit probe | T1190 | Web / reverse-proxy / Roundcube logs | Alert unauth SQLi-shaped payloads to virtuser endpoints; correlate with sudden mailbox dumps |
| Post-exploit: unexpected PHP webshells under Roundcube webroot; mass mailbox access / credential table reads; historical UNK_MassTraction → VShell pattern | Impact | T1505.003 / T1114 | EDR / mail DB audit | If vulnerable during ITW window: rotate mailbox creds, review users/identities tables, hunt webshells |
Detection
| Source | Rule | Gap |
|---|---|---|
| Splunk ESCU | None — verified search for CVE-2026-48842 / Roundcube / virtuser_query | No Roundcube analytic |
| Elastic | None — verified search (rejected generic Linux webserver file-create — wrong class) | No Roundcube / CVE-2026-48842 rule |
| Sigma | None — verified search | No emerging-threat rule for CVE-2026-48842 |
Hunt hint: (1) Inventory Roundcube versions — flag <1.6.16 / <1.7.1. (2) Confirm whether virtuser_query is enabled. (3) Review web logs for pre-auth anomalies to identity-mapping endpoints since 2026-09-21. (4) Shadowserver exposure is low on known-vulnerable — still verify internal/on-prem copies.
Sources: Canadian Centre AV26-503 Update 1, The Hacker News, Roundcube 1.6.16 release, Fix commit 87124cc, NVD CVE-2026-48842
Status Updates
- CVE-2026-87902 (WordPress Core): NEW CISA KEV (2026-09-25, due 2026-09-28, forensic triage Yes) — was Sep 24 lead; still patch ≥7.1.2 (branch backports through 4.7.37); keep pearcmd
/tmp/wp-pear-*.php+ double-encodedpagenamehunts. Sep 24 - CVE-2026-67279 (MikroTik RouterOS SSH rekey→channel): NEW CISA KEV (2026-09-25, due 2026-09-28, forensic triage No) — MikroTrick prerequisite chained with CVE-2026-86060; fix RouterOS ≥6.49.21 / ≥7.23.4 / ≥7.24.2; hunt
login failure for user -2+ privilegedopsaccount; restrict SSH. Amplify of Sep 06 MikroTrick · CERT.pl deep-dive. - CVE-2026-5430 (WSO2) / CVE-2026-71362 (Adobe Magento): KEV due TOMORROW 2026-09-27 (forensic triage Yes) — finish update levels / -2026-aug patches; JWT
alg+editPost id=hunts. Sep 25 - CVE-2026-94127 (F5) / CVE-2026-93616 (CP Mgmt) / CVE-2026-93952 (Arista) / CVE-2026-85102 (CP VPN) / CVE-2026-42016+42018 (JFrog): KEV due was 2026-09-25 — confirm Eng HF / Jumbo / VCO ≥5.2.3.16|≥6.4.2.8 / sk1000117 / Artifactory patch + hunts. Sep 23 · Sep 12 · Sep 11
- CVE-2026-61674 (Fluent Bit): No material change — keep agents ≥5.0.8. Sep 25
- CVE-2026-63077 (TeamCity) / CVE-2026-80521 (Ubuntu AF_UNIX) / CVE-2026-32996 (Veeam) / CVE-2026-93485 (Comment2Shell): No material change — TeamCity ≥2025.11.7/≥2026.1.3, Veeam Agent 13.0.3.1220, WP Comment2Shell ≥7.1.1 (87902 still needs ≥7.1.2). Sep 24 · Sep 22