Skip to main content

14th September – Threat Intelligence Report

0
High
Published: 09/14/2026 (09/14/2026, 12:22:06 UTC)
Source: Check Point Research

Description

The threat intelligence report from September 14, 2026, details multiple cyber incidents including data breaches, vulnerabilities, and AI-related threats. Notably, a data breach at Mathspace was caused by exploitation of CVE-2026-72898, a SQL injection vulnerability in the self-hosted Metabase tool, exposing user names, emails, usernames, and locations. Other significant vulnerabilities include Microsoft’s Patch Tuesday addressing 974 flaws including privilege escalation zero-days, and GitLab’s critical path traversal vulnerability CVE-2026-85706 allowing unauthenticated arbitrary file reads. MikroTik RouterOS vulnerabilities enabling passwordless SSH and privilege escalation were also fixed. The report includes AI threats involving prompt evasion and sandbox escapes. Check Point IPS provides protections for several mentioned vulnerabilities. The report does not specify affected versions for CVE-2026-72898. No CVSS score is provided for this vulnerability.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/14/2026, 12:26:01 UTC

Technical Analysis

This report highlights a range of cyber threats and vulnerabilities discovered or exploited in early September 2026. Among these, CVE-2026-72898 is a SQL injection vulnerability in the self-hosted Metabase tool that was exploited to access an internal reporting database at Mathspace, exposing personal information such as names, email addresses, usernames, and locations. The report also covers Microsoft’s extensive Patch Tuesday addressing 974 vulnerabilities including two privilege escalation zero-days, GitLab’s critical path traversal vulnerability CVE-2026-85706 with a CVSS score of 10.0 affecting versions 18.7 through 19.3.1, and MikroTik RouterOS vulnerabilities that allow passwordless SSH access and privilege escalation. AI-related threats include prompt evasion techniques and sandbox escapes in large language models. Check Point IPS offers protection signatures for several of these threats. The report does not provide patch or affected version details for CVE-2026-72898.

Potential Impact

Exploitation of CVE-2026-72898 enabled attackers to access internal reporting databases at Mathspace, exposing personal data including names, email addresses, usernames, and locations. Passwords and academic records were not compromised. Other vulnerabilities mentioned pose risks of privilege escalation, arbitrary file read, and full router compromise, potentially allowing attackers to control affected systems, manipulate network traffic, and access sensitive data. The AI threats could enable unauthorized execution of hidden instructions and data exfiltration across accounts. The report indicates active exploitation of some Microsoft vulnerabilities and public data breaches involving identity documents and financial data.

Defensive Guidance

For CVE-2026-72898, no explicit patch information is provided; however, Check Point IPS offers protection signatures against this SQL injection threat. Users of Metabase should monitor vendor advisories for patches and apply them promptly once available. For other vulnerabilities, Microsoft and GitLab have released official fixes, which should be applied immediately. MikroTik has issued patches for RouterOS vulnerabilities. Organizations should deploy IPS protections where available and follow vendor guidance. No indication that the Metabase vulnerability is already mitigated or that no action is required.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.78,"severitySource":"heuristic","classifier":"rss-v2"}
Article Source
{"url":"https://research.checkpoint.com/2026/14th-september-threat-intelligence-report/","fetched":true,"fetchedAt":"2026-09-14T12:25:50.353Z","wordCount":961}

Threat ID: 6aa7e7ce55bf5e2cf50ad76a

Added to database: 09/14/2026, 12:25:50 UTC

Last enriched: 09/14/2026, 12:26:01 UTC

Last updated: 09/14/2026, 12:50:50 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses