Threat Analysis: WatchGuard Ransomware Exploitation and the BlueMoon Chrome Zero-Day Chain

Threats & Attacks

Threat Analysis: WatchGuard Ransomware Exploitation and the BlueMoon Chrome Zero-Day Chain

This is your Daily Threat Analysis for the 10th of September 2026.

Two active exploitation events dominate today’s picture. One involves a vulnerability that was supposed to be dealt with in December. The other is a zero-day exploit chain that four separate state-aligned actors have adopted within days of each other. Neither requires sophisticated analysis to understand. Both require action today.

WatchGuard Firebox: Ransomware Operators Are Still Finding Unpatched Devices

CISA confirmed this morning that ransomware gangs are actively exploiting a critical remote code execution vulnerability in WatchGuard Firebox and FireboxV appliances. The flaw allows a remote, unauthenticated attacker to execute arbitrary code on the affected device, which is to say, it allows them to own your firewall from the internet without needing credentials.

This is not new intelligence about a new vulnerability. CISA added this flaw to its Known Exploited Vulnerabilities catalogue in December 2025. What is new is that ransomware operators are now confirmed to be weaponising it, meaning the exploitation has moved from targeted intrusion to commodity criminal activity. When ransomware affiliates are using a vulnerability, the volume of attempts scales up significantly. These groups run automated scanning infrastructure. If your device is reachable and unpatched, it will be found.

WatchGuard is widely deployed in UK SMBs. It is often positioned as a complete security solution by managed service providers, which makes the optics here particularly uncomfortable. If you have a WatchGuard Firebox in your environment and you are asking whether your MSP has kept it patched, that is exactly the right question.

What the advisory does not say, but is worth stating clearly: the gap between a flaw appearing on the KEV list and ransomware operators adopting it has been compressing for the past two years. Nine months is not the window you have to act anymore. In several recent campaigns, ransomware affiliates have weaponised KEV-listed vulnerabilities within weeks of them being catalogued. The fact that this particular flaw is still finding victims in September 2026 tells you that a meaningful number of WatchGuard deployments have not been touched since before Christmas.

If your IT provider tells you this does not affect you because you have WatchGuard managed centrally, ask them to confirm which firmware version is currently running and when it was last updated. Get that answer in writing.

Immediate action: Check your WatchGuard Firebox firmware version against WatchGuard’s current security advisories. If you are not on the patched release, apply the update before close of business today. If you do not have direct access to do this, escalate to your IT provider and confirm it is done.

BlueMoon: Four State-Aligned Actors, One Chrome Zero-Day Chain, Days Apart

This is the more operationally significant story, and it deserves careful reading.

Researchers at Proofpoint and Volexity have both published analysis of what is being tracked as the BlueMoon exploit kit, a chain combining CVE-2026-85046 (a type-confusion vulnerability in Chrome’s V8 JavaScript engine) with CVE-2026-85880 (a Windows kernel elevation-of-privilege flaw). Together, these two vulnerabilities give an attacker arbitrary code execution in the browser followed by a full escape to SYSTEM-level access on the underlying Windows machine. Visiting a compromised or attacker-controlled webpage is sufficient. No file download. No macro. No user interaction beyond the initial click.

The attribution picture is notable. China-aligned TA412 was the first observed actor deploying this chain, on 28 August 2026. Within days, at least three other suspected China-nexus groups had adopted identical or near-identical exploitation. Volexity’s reporting adds UTA0560 and JungleBamboo to the picture. Proofpoint tracks a fourth group under the BlueMoon umbrella.

The advisory attributes this to espionage-motivated actors. What it does not say explicitly, though the operational pattern implies it, is that when multiple well-resourced state actors converge on the same exploit chain this quickly, it suggests either shared tooling, shared access to the original vulnerability research, or both. The rapid adoption across distinct actor groups within days of each other is not coincidence. This is a coordinated or brokered exploitation pattern.

For UK SMBs, the direct exposure vector is the browser. The initial targeting has been observed against NGOs and organisations likely to hold politically or strategically relevant data, think professional services firms advising on government contracts, legal firms handling sensitive matters, healthcare organisations. If your business handles data that a foreign state might consider valuable, this is relevant to you. If you use Chrome on Windows, it is relevant to you regardless.

The patches are available. Google pushed the fix for CVE-2026-85046 in the current Chrome release. Microsoft addressed CVE-2026-85880 in the September 2026 Patch Tuesday update, published this week. The window between patch availability and exploitation is now negative, these patches are being applied in an environment where exploitation is already active. This is not a situation where you can wait for the next scheduled maintenance window.

Immediate action: Confirm Chrome is on the latest stable release across all devices. Apply September 2026 Patch Tuesday Windows updates immediately, or confirm with your IT provider that this has been done. For organisations that manage their own devices, consider enabling automatic Chrome updates if they are not already active.

The Third Thing Worth Noting

Separately, Cisco Talos is tracking active exploitation of two vulnerabilities in Cisco Secure Firewall Management Center, CVE-2026-20079, a critical authentication bypass allowing root access, and CVE-2026-20316, which enables privilege escalation. This is not yet confirmed as ransomware-related, but the Qilin ransomware group has been observed in connection with related Cisco FMC activity. Cisco FMC is less common in pure SMB environments than WatchGuard, but it does appear in mid-market professional services firms and managed security provider infrastructure. If you have Cisco FMC in your environment, check Talos’s advisory and your patch status.

What Today Looks Like in Practice

Three network security products actively exploited in the same news cycle. Two of them, WatchGuard and Chrome, are directly relevant to the average UK SMB. The NCSC has published guidance on patch management cadence and the risks of internet-facing appliances that are not regularly updated. The fact that a WatchGuard vulnerability from December 2025 is still being exploited in September 2026 is not a commentary on WatchGuard. It is a commentary on how organisations treat patching as optional.

The question to ask your IT provider or internal team today is simple: which of our internet-facing devices and applications were updated in the last 30 days, and which were not? If you cannot get a clear answer to that question, you have a more fundamental problem than any individual vulnerability.


If Threat Analysis is useful to you, follow the show wherever you listen so tomorrow’s briefing lands automatically. And if someone in your network needs the heads-up on what is happening today, pass this along to them.


Sources

SourceTitleURL
BleepingComputerCISA: WatchGuard RCE flaw now exploited in ransomware attackshttps://www.bleepingcomputer.com/news/security/cisa-watchguard-rce-flaw-now-exploited-in-ransomware-attacks/
Proofpoint Threat ResearchOnce in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chainhttps://www.proofpoint.com/us/blog/threat-insight/once-bluemoon-multiple-state-aligned-threat-actors-rapidly-adopt-novel-exploit
VolexityMind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windowshttps://www.volexity.com/blog/2026/09/09/mind-the-patch-gap-multiple-chinese-threat-actors-chain-0-day-exploits-in-chrome-windows/
CISAKnown Exploited Vulnerabilities Cataloguehttps://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cisco TalosActive exploitation of Cisco Secure Firewall Management Center vulnerabilitieshttps://blog.talosintelligence.com/fmc-ongoing-exploitation/
Arctic WolfSecurity Bulletin: Active Cloud Data Theft and Extortion Campaign (PREY-0058)https://arcticwolf.com/resources/blog/security-bulletin-active-cloud-data-theft-and-extortion-campaign-targeting-microsoft-365-and-saas-platforms/

Filed under

  • ransomware-groups
  • smb-security
  • uk-business
  • nation-state-attacks
  • remote-access
  • vendor-risk
  • supply-chain-risk