■ NCSC UK ■ CISA KEV ■ FCA ScamSmart ■ ICO Enforcement ■ GET-IT Intelligence

Threat Advisory

Active vulnerability alerts, financial fraud warnings, and data protection enforcement notices for UK businesses — plus original analysis, commentary, and real-world case studies from GET-IT. Curated from NCSC, CISA, FCA ScamSmart, ICO intelligence feeds, and our own research.

[ LAST UPDATED: 22 September 2026 at 22:26 UTC ]
█ New — MITRE-Lite Weekly

Our plain-English translation of the MITRE ATT&CK framework — who is targeting UK businesses this week, how they operate, and what to do about it. Updated every Monday.

Business Owner Edition → Technical Edition →

Analysis, Commentary & Case Studies

Browse all GET-IT Reads →

Active UK Advisories

Why this matters to your business: The NCSC issues alerts when vulnerabilities are being actively exploited against UK organisations. If you use any of the affected products below, patching should be treated as urgent.
NCSC MON, 21 SEP 2026

One does not simply defend agentically

Read NCSC Advisory →
NCSC THU, 17 SEP 2026

Adversary simulation: what you need to know

Read NCSC Advisory →
NCSC THU, 17 SEP 2026

Cyber Adversary Simulation (CyAS): scheme documents now available

Read NCSC Advisory →
NCSC TUE, 15 SEP 2026

Iranian cyber targeting of dissidents, activists and journalists

Read NCSC Advisory →
NCSC TUE, 15 SEP 2026

UK and allies expose spyware used by Iranian state actors to target dissidents, activists and journalists

Read NCSC Advisory →
NCSC MON, 07 SEP 2026

The hidden risks of shadow AI

Read NCSC Advisory →

Known Exploited Vulnerabilities — Active in the Wild

What is the CISA KEV Catalog? The US Cybersecurity and Infrastructure Security Agency maintains a list of vulnerabilities with confirmed evidence of active exploitation globally. These are not theoretical risks — they are being used by attackers right now. Many affect common software used by UK SMEs.
CISA KEV CRITICAL 2026-09-22
CVE-2026-93952 — Arista | VeloCloud Orchestrator

Arista VeloCloud Orchestrator Vulnerability

Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.

View CISA Advisory →
CISA KEV CRITICAL 2026-09-22
CVE-2026-94127 — F5 | BIG-IP APM

F5 BIG-IP APM Vulnerability

F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution.

View CISA Advisory →
CISA KEV CRITICAL 2026-09-22
CVE-2026-93616 — Check Point | Multiple Products

Check Point Multiple Products Vulnerability

Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary scripts.

View CISA Advisory →
CISA KEV CRITICAL 2026-09-22
CVE-2026-85102 — Check Point | Multiple Products

Check Point Multiple Products Vulnerability

Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.

View CISA Advisory →
CISA KEV CRITICAL 2026-09-21
CVE-2026-7273 — Zyxel | GS1900 Series Switches

Zyxel GS1900 Series Switches Vulnerability

Zyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.

View CISA Advisory →
CISA KEV CRITICAL 2026-09-18
CVE-2025-39964 — Linux | Kernel

Linux Kernel Vulnerability

Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state.

View CISA Advisory →

Financial Fraud Warnings & Action Fraud Alerts

Why this matters to your business: The FCA ScamSmart programme and Action Fraud publish warnings about unauthorised firms, clone investment scams, and financial services impersonation attacks targeting UK consumers and businesses. If your employees handle payments, invoices, or client funds, these alerts are directly relevant.
FCA ScamSmart FINANCIAL FRAUD TUESDAY, SEPTEMB

Debt advice warning: spot the red flags

People seeking debt advice are being urged to watch out for red flags. Free debt advice is available to everyone. However, the FCA is concerned that some consumers are being steered towards fee-paying debt solutions tha...

Read FCA Warning →
FCA ScamSmart FINANCIAL FRAUD MONDAY, SEPTEMBE

FCA takes Hunter Jones to High Court over alleged unauthorised activity

The FCA has begun High Court proceedings against Osborne Baldwin Limited, which trades as Hunter Jones and Hunter Jones Group. The FCA alleges that Hunter Jones, which sells loan notes, carries out regulated activity wi...

Read FCA Warning →
FCA ScamSmart FINANCIAL FRAUD FRIDAY, SEPTEMBE

Building a stronger UK investment culture

Speech by Lucy Castledine, director of consumer investments, at the 2026 Investor Summit. Speaker: Lucy Castledine, director, consumer investmentsEvent: Investor Summit 2026, LondonDelivered: 18 September 2026Note: This...

Read FCA Warning →
FCA ScamSmart FINANCIAL FRAUD THURSDAY, SEPTEM

Financial crime: protecting the hive

Speech by Steve Smart, executive director of enforcement and market oversight, at the Law Society Economic Crime Conference 2026. IntroductionA few weeks ago, I visited the Bank of England Museum to see a new exhibition...

Read FCA Warning →
FCA ScamSmart FINANCIAL FRAUD MONDAY, SEPTEMBE

Upper Tribunal upholds Crispin Odey ban

Crispin Odey’s ban from the financial services industry has been upheld by the Upper Tribunal, which found he lacked integrity. Mr Odey was the founder and majority owner of Odey Asset Management (OAM). He faced an inte...

Read FCA Warning →
FCA ScamSmart FINANCIAL FRAUD THURSDAY, SEPTEM

Man pleads guilty to fraud and forgery offences relating to fake takeover approach

Christopher Woolcott has pleaded guilty to 4 counts of fraud and forgery after creating a fake takeover bid for Touchstone Exploration Inc. Mr Woolcott held shares in Touchstone Exploration Inc and stood to benefit fina...

Read FCA Warning →

ICO Enforcement Notices & Data Protection Penalties

What the ICO publishes: The Information Commissioner's Office issues enforcement notices, monetary penalty notices, and reprimands against organisations that have failed to protect personal data under UK GDPR. These cases set precedent for what the ICO expects — and what it will act on — for businesses of all sizes.
ICOENFORCEMENT

ICO Enforcement Notices & Monetary Penalties

The ICO regularly issues fines and enforcement notices for data protection breaches under UK GDPR. View the full register of actions below.

View ICO Enforcement Register →

Is Your Business Exposed?

Many of these vulnerabilities affect software used by UK SMEs every day. A GET-IT threat intelligence scan will tell you exactly where your perimeter stands.

Book a Resilience Scan →

Intelligence sourced from NCSC UK, the CISA Known Exploited Vulnerabilities Catalog, the FCA ScamSmart programme, and the ICO Enforcement register. This page is updated automatically every 12 hours. For the most current advisories visit the source links directly. GET-IT Cyber Division curates this content for UK SME relevance but is not responsible for the accuracy of third-party source data.