In 30 seconds
- One new KEV CVE (CVE-2026-85046) is confirmed as actively exploited. Treat it as a patch priority, not a backlog item.
- Channel Islands finance phishing remains live. QuickBooks themed lures are targeting payment workflows, and the fix is process as much as technology.
- Edge appliances are still the easiest way in. SonicWall SMA1000 zero-day reports mean your remote access kit needs checking this week.
Why it matters
This week is a classic mix of real world exploitation plus business process risk. The KEV addition tells you attackers are already using the weakness. The finance phishing tells you they are also happy to bypass technology entirely by targeting approvals and trust. And the SonicWall story is a reminder that the devices you rely on for secure remote access are themselves high-value targets.
For regulated Channel Islands organisations, the win is simple. Reduce exposure quickly, prove you did it, and make sure your finance controls do not rely on one person spotting a dodgy email.
CVE-2026-85046: the KEV signal
CISA added CVE-2026-85046 to the Known Exploited Vulnerabilities catalogue on 4 September. That means exploitation is confirmed, not theoretical. If you have the affected product in your environment, including any internet-facing instances, patch or mitigate immediately and then validate the fix took effect. Add a quick check for signs of compromise on any exposed systems, and confirm privileged credentials are not shared across systems.
QuickBooks phishing: process, not just technology
Local Channel Islands reporting continues to flag phishing activity targeting Intuit QuickBooks users. This is a high-impact route because it targets finance workflows, payment approvals, and supplier bank details. Even if you do not use QuickBooks, you may have suppliers, clients, or counterparties who do. Finance-targeted phishing is one of the fastest ways to trigger fraud, data exposure, and operational disruption, and it often bypasses technical controls by leaning on process gaps.
Re-confirm your payment change process, especially bank detail changes, and enforce call-back verification. Make sure finance teams know the current lure and have a simple escalation route. Review who has admin access to finance platforms and ensure MFA is enforced.
SonicWall SMA1000: edge devices under fire again
Cyber reporting is flagging actively exploited zero-day flaws affecting SonicWall SMA1000 appliances. These devices sit on the edge and are commonly used for remote access. If a remote access appliance is compromised, attackers can move quickly into sensitive systems, and you can end up in a position where you have to prove containment and evidence-based recovery.
Confirm whether you run SonicWall SMA1000 anywhere, including at suppliers who provide managed connectivity. If you do, apply the vendor's recommended mitigations and patching as soon as available, and review logs for unusual admin activity. Reduce exposure where possible: restrict management interfaces and enforce strong admin controls.
Questions to ask your team this week
- 1.Which systems are internet-facing, and who is accountable for patching each one end to end?
- 2.Do we have any of the products affected by this week's KEV addition (CVE-2026-85046), including at third parties?
- 3.What is our current process for verifying supplier bank detail changes, and is it consistently followed?
- 4.Which remote access appliances do we run, and when did we last review admin access and logs for them?
One thing to do this week
Run a 60-minute "edge and finance" check: confirm exposure and patch status for internet-facing systems (starting with the KEV item), then do a quick finance control walk-through for payment change verification and escalation.
Sources
- CISA, "CISA Adds One Known Exploited Vulnerability to Catalog" (4 September 2026):
cisa.gov - GCSC, "Phishing Investigation: Intuit QuickBooks":
gcsc.gg - BleepingComputer, "SonicWall warns of actively exploited SMA1000 zero-day flaws":
bleepingcomputer.com

