September 2026 Cybersecurity Roundup

This September 2026 Cybersecurity Roundup covers a month in which ransomware kept disrupting public services and critical infrastructure, while flaws in widely used network appliances created serious exposures of their own. Attacks hit German government and utility networks, and a misconfigured database exposed 220 million Vietnam-linked travel records. Below are the month’s key cyberattacks and CVEs, with what each means for businesses.

Cyberattacks in the September 2026 Cybersecurity Roundup

Five September 2026 incidents across government, utilities, travel data, schools, and transport

Five incidents in September, from a state government to a railway group.

Berlin State Government

Berlin is still dealing with an August ransomware attack. Authorities said the intrusion hit two Senate departments (Mobility, Transport, Climate Protection and Environment, and Urban Development, Building and Housing), that data left the network between August 7 and 12, and that the affected systems were disconnected on August 14. The Rhysida group then offered the data for auction, with a starting price of 30 Bitcoin, roughly €2 million. Berlin refused to pay.

In early September, Rhysida published the data. The group claims the archive holds about 5.8 TB across 1.44 million files; those figures come from Rhysida, and Berlin had not independently verified them. Reporting on the leak pointed to personnel files, payslips, correspondence and identity documents. Berlin has confirmed a data outflow, but its investigation into the full scope was still running.

Rhysida is a ransomware-as-a-service operation that emerged in 2023 and uses double extortion: it steals data first, then encrypts systems. The FBI, CISA and MS-ISAC have warned about the group, which has targeted government, healthcare, education and manufacturing organizations.

Stadtwerke Landsberg

Stadtwerke Landsberg, the city-owned utility serving Landsberg am Lech in Bavaria, suffered a cyberattack in the night to September 1 that encrypted its central IT network. The utility disconnected affected systems from the internet, activated its crisis team and called in external specialists. Phone and email availability was limited while forensic work and recovery continued. The utility also said it could not rule out that customer data such as names, addresses, phone numbers, email addresses and bank details was accessed.

The attack stopped at corporate IT. The utility reported that electricity, water, wastewater treatment, district heating, its fiber network, charging infrastructure, swimming facilities and parking garages kept running.

Vietnam APIS Database

Security researchers at Kinryū Labs said they found an exposed database holding more than 220 million passenger and crew records linked to travel to, from or through Vietnam. They found it in early June, reported it to Vietnamese authorities and airlines from June 3, and saw access closed by June 8. The details became public in September. The records span January 2017 to April 2026 and appear to come from an Advance Passenger Information System (APIS), the kind of system airlines use to send passenger data to border authorities.

The data included names, dates of birth, nationalities, passport or travel-document numbers and expiry dates, flight routes, seat assignments and baggage references. The 220 million figure counts records, not people, so frequent travelers can appear many times. The data sat in an Elasticsearch cluster. The direct endpoint required authentication, but an alternate cloud path to the same cluster accepted default credentials. The server was traced to Viettel address space, and the operating organization has not been identified. There is no public evidence of a ransom demand or of the data being sold, and nothing public establishes whether anyone else accessed it before it was closed.

Massachusetts: Springfield Public Schools and Everett City Hall

Two separate incidents disrupted public services in Massachusetts in early September. Officials and local reporting found no indication that they were connected.

Springfield Public Schools, which serves roughly 23,000 students across more than 60 schools, had its online systems blocked and kept schools closed for four days from September 8. Staff were told to stay off the network, students were told not to use school-issued laptops, phones were affected, and administrators built manual workarounds for functions such as attendance. The FBI later told the district that data had been breached, including student and staff information.

In Everett, an intrusion into the city’s internal network and technology systems closed City Hall to the public from September 8, and it stayed closed for more than a week. Police, fire, 911, public works, schools and libraries kept operating. The city said it contained the attack and that only a small amount of city data was affected.

Keio Corporation, Japan

Japanese transport and hospitality group Keio detected system failures in the early hours of September 26 and then confirmed ransomware on servers across the Keio Group. It disconnected its network, notified police and brought in outside specialists to investigate the intrusion route and the impact. Whether customer or partner data was accessed was still being assessed.

Keio is best known as a private railway operator with 69 stations and about 85 kilometers of track, and it also runs 25 hotels. Rail services kept running normally. The disruption fell mainly on the hospitality and retail side: some Keio Store locations could not process card, e-money or points payments, and hotel customers were warned of delays to some services.

Key CVEs in the September 2026 Cybersecurity Roundup

Four September 2026 CVEs in network appliances, all exploited in the wild

All four network-edge flaws were exploited in the wild.

Four flaws in network and email appliances were exploited in the wild in September. Three of them were listed in CISA’s Known Exploited Vulnerabilities catalog (Cisco, Zyxel and Citrix), and CERT Polska observed exploitation of the MikroTik chain.

  • Cisco Secure Email Gateway (CVE-2026-76461, CVSS 9.8): a SQL injection in the email-parsing logic of Cisco AsyncOS. An unauthenticated attacker can send a crafted email through an affected gateway and run commands as root. Email gateways accept traffic from untrusted senders by design, so exploitation needs no management access and no user interaction. Cisco says a root compromise can also expose the SSH keys used between clustered gateways, which can spread the attack beyond one appliance. Cisco warned of active exploitation when it disclosed the flaw, and CISA added it to the KEV catalog on September 14.
  • Zyxel GS1900 switches (CVE-2026-7273, CVSS 8.8): a stack-based buffer overflow in the CGI program that lets an unauthenticated attacker with LAN access run OS commands through a crafted HTTP request. Zyxel patched it on June 16. GreyNoise reports that a Chinese-speaking actor exploited the flaw from around August 17, taking configuration data, network information and hashed root credentials from 996 devices in 48 countries. CISA added it to the KEV catalog on September 21. These switches are common in small businesses, schools, hotels and retail, where network gear often gets less patching attention than endpoints.
  • Citrix NetScaler ADC and Gateway (CVE-2026-88772, CVSS 9.5): a memory overflow reachable when DTLS is enabled, which can lead to remote code execution or denial of service. Citrix disclosed it on September 27 together with CVE-2026-88771, and both had already been exploited as zero-days since early September against government, financial, education and legal organizations in North America and Europe. Mandiant and Google’s threat intelligence group describe custom web shells called WHIPSHOT and SLAPSHOT. Because exploitation came before any patch, patching alone does not settle the risk: teams should also hunt for persistence on affected appliances.
  • MikroTik RouterOS (CVE-2026-67276 and CVE-2026-86060, CVSS 9.2 each): the “MikroTrick” chain. CVE-2026-67276 is an SSH authentication bypass: RouterOS did not compare the entire RSA public key, so an attacker who knows a username and the public modulus of that user’s key can craft a different key and log in without the private key. CVE-2026-86060 then mishandles usernames that begin with a disallowed character, and a crafted username gives the session full administrative privileges. Together they take over a router with reachable SSH without valid credentials. CERT Polska reported exploitation from September 2, before its disclosure on September 5. MikroTik fixed the flaws in RouterOS 6.49.21, 7.23.4, 7.24.2 and 7.25beta3. A compromised router lets attackers change firewall and routing rules and set up tunnels at a layer that endpoint tools do not watch.

Limiting the Damage When Defenses Fail

A security team reviewing penetration test findings and exposure monitoring results together

Knowing what is exposed, inside and outside the network, comes before fixing it.

September’s incidents show that resilience has to go beyond keeping attackers out. Stadtwerke Landsberg and Keio both lost IT systems while their essential physical services kept running, which shows what limiting the spread of a compromise is worth. Berlin shows the other side: once sensitive data has left the network, the consequences continue long after the attackers are gone.

That makes visibility important on both sides of the perimeter. Regular penetration testing can find exposed services, vulnerable infrastructure and configuration weaknesses before attackers do. Organizations also need to know what has already left their control. Credentials, internal documents and personal data can circulate through infostealer logs, underground forums, marketplaces and private criminal channels, and any of it can be the starting point for the next attack.

If September’s incidents raise questions about your own exposure, such as how far a compromise could spread in your network or what has already left it, we are happy to discuss those questions with you.

Contact DIESEC to learn how we can help strengthen your cybersecurity posture.