============================================================================== CYBER THREAT INTELLIGENCE - INDICATORS OF COMPROMISE (IOC) LIST ============================================================================== Generated: 2026-09-15 12:15 UTC Report ID: IOC-20260915-121539 Total Indicators: 28 Classification: OPEN - Law Enforcement / DFIR use Sources: CISA KEV Catalog, OpenPhish SUMMARY ------------------------------------------------------------------------------ CISA KEV (Known Exploited Vulnerability): 10 Phishing URL: 9 Domain: 9 Severity: CRITICAL=28 ============================================================================== [CISA KEV (KNOWN EXPLOITED VULNERABILITY)] - 10 indicator(s) ============================================================================== #1 CVE-2026-76461 Severity: CRITICAL Description: Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. Product: Secure Email Gateway (Cisco) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-76461 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-14 Tags: kev,cisa,active-exploitation #2 CVE-2026-84869 Severity: CRITICAL Description: ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to file transfer and execution through an active remote sessions without authorization or host confirmation. Product: ScreenConnect (ConnectWise) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-84869 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-11 Tags: kev,cisa,active-exploitation #3 CVE-2026-42016 Severity: CRITICAL Description: JFrog Artifactory contains an incorrect authorization vulnerability that allows leads to privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope. Product: Artifactory (JFrog) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-42016 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-11 Tags: kev,cisa,active-exploitation #4 CVE-2026-42018 Severity: CRITICAL Description: JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources. Product: Artifactory (JFrog) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-42018 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-11 Tags: kev,cisa,active-exploitation #5 CVE-2026-85706 Severity: CRITICAL Description: GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits A Product: Community Edition and Enterprise Edition (GitLab) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-85706 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-11 Tags: kev,cisa,active-exploitation #6 CVE-2026-86060 Severity: CRITICAL Description: MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacked to change the trusted RouterOS policy mask, leading to privilege escalation. Product: RouterOS (MikroTik) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-86060 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-10 Tags: kev,cisa,active-exploitation #7 CVE-2026-67277 Severity: CRITICAL Description: MikroTik RouterOS contains a missing authenticaion for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service. Product: RouterOS (MikroTik) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-67277 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-10 Tags: kev,cisa,active-exploitation #8 CVE-2026-19490 Severity: CRITICAL Description: Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Pr Product: NetScaler (Citrix) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-19490 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-09 Tags: kev,cisa,active-exploitation #9 CVE-2025-25249 Severity: CRITICAL Description: Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets. Product: Multiple Products (Fortinet) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2025-25249 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-09 Tags: kev,cisa,active-exploitation #10 CVE-2026-87491 Severity: CRITICAL Description: Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, includin Product: Chromium V8 (Google) Source: CISA KEV Catalog NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-87491 URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Date: 2026-09-09 Tags: kev,cisa,active-exploitation ============================================================================== [PHISHING URL] - 9 indicator(s) ============================================================================== #11 https://www.site-ma-ga-zine-luiza.com/site-ma-ga-zine-luiza.com/produt Severity: CRITICAL Description: Active phishing URL: https://www.site-ma-ga-zine-luiza.com/site-ma-ga-zine-luiza.com/produt Source: OpenPhish URL: https://www.site-ma-ga-zine-luiza.com/site-ma-ga-zine-luiza.com/produt Date: Tags: phishing,openphish #12 http://es.uevangelica.edu.ar/ Severity: CRITICAL Description: Active phishing URL: http://es.uevangelica.edu.ar/ Source: OpenPhish URL: http://es.uevangelica.edu.ar/ Date: Tags: phishing,openphish #13 https://paypal-app.online/ Severity: CRITICAL Description: Active phishing URL: https://paypal-app.online/ Source: OpenPhish URL: https://paypal-app.online/ Date: Tags: phishing,openphish #14 https://zyexx.com/t18674c21q3caa437ak9ae2e39dv1902ec25.html Severity: CRITICAL Description: Active phishing URL: https://zyexx.com/t18674c21q3caa437ak9ae2e39dv1902ec25.html Source: OpenPhish URL: https://zyexx.com/t18674c21q3caa437ak9ae2e39dv1902ec25.html Date: Tags: phishing,openphish #15 https://manjaresdelmar.com.ar/DROPBOXX.html Severity: CRITICAL Description: Active phishing URL: https://manjaresdelmar.com.ar/DROPBOXX.html Source: OpenPhish URL: https://manjaresdelmar.com.ar/DROPBOXX.html Date: Tags: phishing,openphish #16 http://yextugu.yourwebs.app/ Severity: CRITICAL Description: Active phishing URL: http://yextugu.yourwebs.app/ Source: OpenPhish URL: http://yextugu.yourwebs.app/ Date: Tags: phishing,openphish #17 http://www.companysphere-crm.com/public/index?ref=business-support-center-DASDFDSYUYEE43FJDSHFSDFsetting%25popup%3fclient_id=889943718806-ual26tplnot2ea8b7n5t4p77keo8eb Severity: CRITICAL Description: Active phishing URL: http://www.companysphere-crm.com/public/index?ref=business-support-center-DASDFDSYUYEE43FJDSHFSDFsetting%25popup%3fclien Source: OpenPhish URL: http://www.companysphere-crm.com/public/index?ref=business-support-center-DASDFDSYUYEE43FJDSHFSDFsetting%25popup%3fclient_id=889943718806-ual26tplnot2ea8b7n5t4p77keo8eb Date: Tags: phishing,openphish #18 http://www.companysphere-crm.com/ Severity: CRITICAL Description: Active phishing URL: http://www.companysphere-crm.com/ Source: OpenPhish URL: http://www.companysphere-crm.com/ Date: Tags: phishing,openphish #19 http://ur-ledgr-starts.pages.dev/ Severity: CRITICAL Description: Active phishing URL: http://ur-ledgr-starts.pages.dev/ Source: OpenPhish URL: http://ur-ledgr-starts.pages.dev/ Date: Tags: phishing,openphish ============================================================================== [DOMAIN] - 9 indicator(s) ============================================================================== #20 www.site Severity: CRITICAL Description: Phishing domain: www.site Source: OpenPhish URL: https://www.site-ma-ga-zine-luiza.com/site-ma-ga-zine-luiza.com/produt Date: Tags: phishing,openphish,domain #21 es.uevangelica Severity: CRITICAL Description: Phishing domain: es.uevangelica Source: OpenPhish URL: http://es.uevangelica.edu.ar/ Date: Tags: phishing,openphish,domain #22 paypal-app.online Severity: CRITICAL Description: Phishing domain: paypal-app.online Source: OpenPhish URL: https://paypal-app.online/ Date: Tags: phishing,openphish,domain #23 zyexx.com Severity: CRITICAL Description: Phishing domain: zyexx.com Source: OpenPhish URL: https://zyexx.com/t18674c21q3caa437ak9ae2e39dv1902ec25.html Date: Tags: phishing,openphish,domain #24 manjaresdelmar.com Severity: CRITICAL Description: Phishing domain: manjaresdelmar.com Source: OpenPhish URL: https://manjaresdelmar.com.ar/DROPBOXX.html Date: Tags: phishing,openphish,domain #25 yextugu.yourwebs Severity: CRITICAL Description: Phishing domain: yextugu.yourwebs Source: OpenPhish URL: http://yextugu.yourwebs.app/ Date: Tags: phishing,openphish,domain #26 www.companysphere Severity: CRITICAL Description: Phishing domain: www.companysphere Source: OpenPhish URL: http://www.companysphere-crm.com/public/index?ref=business-support-center-DASDFDSYUYEE43FJDSHFSDFsetting%25popup%3fclient_id=889943718806-ual26tplnot2ea8b7n5t4p77keo8eb Date: Tags: phishing,openphish,domain #27 ur-ledgr-starts.pages Severity: CRITICAL Description: Phishing domain: ur-ledgr-starts.pages Source: OpenPhish URL: http://ur-ledgr-starts.pages.dev/ Date: Tags: phishing,openphish,domain #28 us-cloud-ledgeer-live.pages Severity: CRITICAL Description: Phishing domain: us-cloud-ledgeer-live.pages Source: OpenPhish URL: http://us-cloud-ledgeer-live.pages.dev/ Date: Tags: phishing,openphish,domain ============================================================================== RECOMMENDED ACTIONS ============================================================================== 1. Search SIEM/network logs for all listed indicators 2. Block listed domains at DNS/proxy immediately 3. Scan endpoints for listed SHA256 hashes 4. Check email gateways for listed sender addresses/links 5. Block listed IP addresses at the firewall 6. Share IOCs with partner agencies and ISACs 7. Update detection rules (Sigma/YARA/Suricata/Splunk) 8. Monitor for indicator rotation (new domains, IP changes) ============================================================================== END OF IOC LIST - IOC-20260915-121539 ==============================================================================