This page translates real, active cyber threat intelligence into plain English for UK business owners. No acronyms. No jargon. Just what you need to know and what you should do about it.
Last updated: 28 September 2026 · September 2026 Edition · Next update: October 2026
Every month we assess the overall risk level for UK small businesses in financial services — insurance brokers, financial advisers, mortgage intermediaries, and professional services firms. This is based on real intelligence from the UK's National Cyber Security Centre (NCSC), US cyber agencies, and industry reporting.
Seven criminal and state-sponsored groups continue running active operations targeting UK businesses in your sector. This month brought the highest number of confirmed, actively-exploited vulnerabilities MITRE-Lite has tracked in a single month — seventeen in total — concentrated in the software that connects your business to the internet: VPN and remote-access appliances from Citrix, Cisco and F5, plus fresh confirmed exploits in WordPress and Microsoft SharePoint, and two separate zero-day flaws in the Chrome/Edge browser engine. The UK's National Cyber Security Centre had already flagged this exact pattern in late August, warning specifically about the risk from internet-exposed systems and edge devices.
Each week we identify the single highest-risk attack technique that is seeing a spike in use against UK businesses. This week:
Seventeen separate security flaws were confirmed as actively being used in real attacks this month — the highest number MITRE-Lite has tracked in a single month since we started this dashboard. Most of them share one thing in common: they're in the equipment and software that sits at the edge of your network, connecting your business to the internet.
Citrix NetScaler — a piece of equipment many businesses use to let staff connect to office systems remotely, especially since the shift to hybrid working — had two separate flaws confirmed exploited in the same week. One of them lets an attacker with no username or password run commands on the device directly. Cisco had three separate confirmed exploits across its network security and email filtering products, including one that hands an attacker full administrator-level access. If your business uses any of this equipment — usually set up and managed by your IT provider rather than something you'd interact with day to day — it needs checking urgently.
Separately, WordPress — the software behind a very large share of small business websites in the UK — had a serious flaw confirmed exploited that can let an attacker take over the server your website runs on. If your website was built on WordPress, this is worth raising with whoever hosts or maintains it. And Microsoft SharePoint picked up its fifth confirmed exploit of the year, continuing a pattern we've flagged in previous editions — if your business stores documents or runs an intranet on SharePoint, confirm this month's patches have been applied.
Finally, and this one affects literally everyone: Google confirmed two separate serious flaws in the technology that powers Chrome, Microsoft Edge, and Opera — the browsers most UK businesses use every day. Both let an attacker take control of your computer just by getting you to visit a malicious web page, no download required.
These are the pieces of equipment that let your staff connect to office systems from home, or that filter your email and protect your network perimeter. They're usually set up once by an IT provider and rarely thought about again — which is exactly why they're a target. This month, two separate flaws in Citrix NetScaler were confirmed exploited, one of which lets an attacker run commands without any login at all. Cisco had three separate confirmed exploits, including one that hands an attacker full administrator access. If you don't know whether your business uses this kind of equipment, that's the first question to ask your IT provider — many businesses use it without realising, bundled into their VPN or firewall setup.
Why now: Citrix NetScaler flaws confirmed exploited 27 September 2026 (CVE-2026-88771, CVE-2026-88772); Cisco flaws confirmed exploited 9–16 September 2026 (CVE-2026-76460, CVE-2026-76461, CVE-2026-20079). Several require no valid login to exploit.
WordPress powers a very large share of small business websites in the UK — if you're not sure whether yours does, ask whoever built or hosts it. A serious flaw confirmed this month allows an attacker to trick the site into loading a file of their choosing from outside its normal folders, which can lead to them taking full control of the server your website runs on. Most reputable hosts and developers will patch this automatically, but it's worth a direct check — especially if your site uses older plugins or a developer you haven't heard from in a while.
Why now: CVE-2026-87902 confirmed exploited 25 September 2026. The flaw requires no login and can lead to complete server takeover.
Google confirmed two separate serious flaws this month in the underlying technology that powers Chrome, Microsoft Edge, and Opera. Both allow an attacker to take control of a computer simply by getting someone to visit a malicious web page — no download or file needed. Browsers usually update themselves in the background, but the update often only takes effect once the browser is fully restarted, and staff frequently leave dozens of tabs open for weeks without restarting. Encourage staff to fully close and reopen their browser every few days, and check with your IT provider that automatic updates haven't been disabled anywhere.
Why now: CVE-2026-87491 confirmed exploited 9 September 2026; CVE-2026-85046 confirmed exploited 4 September 2026. Both are actively exploited sandbox-escape flaws affecting nearly every UK business's browser.
A GET-IT resilience scan maps your current defences against the active threat techniques on this page and tells you exactly where your gaps are — in plain English, with costs to fix them.
Book a Free Resilience Scan → View Technical Version