{{first_name | Reader}},

In partnership with:

Opal Security The programmable access platform bridging policy intent and enforcement, combining AI with CISO context and an engineer's precision.

Smallstep — SCEP is a password. Passwords get stolen. Real Zero Trust starts with the device — begin with Wi-Fi, extend across apps and infrastructure.

LockThreat AI-powered GRC that replaces legacy tools and unifies compliance, risk, audit and vendor management in one platform.

Cite the record - The record behind this brief is public, inspectable, and citable.

The weekly brief is where things get worked out. The daily CISO briefing on Spotify is the fast version: two minutes each weekday on what actually moved. Follow it here.

CYBERSECURITYHQ

Structural Condition Report

Weekly Ratings and Actions

Issue No. 38 · 15 September 2026

CHQ maintains ratings on a standing set of structural security conditions. Each rating reflects the current maturity and confirmation of a condition, not a forecast. Conditions carry their permanent identifiers from the public CHQ Structural Conditions Registry, where dated definitions and falsification criteria are maintained. The report leads with what changed; the full board follows.

Major Rating Actions

SC-2026-006 · Exploitation Precedes Defender Awareness: rating under review after the criterion supporting this cycle's scheduled upgrade failed construct validation. The upgrade action is voided. Prior state, STRENGTHENING, stands.

A Fortinet flaw that entered the exploited catalog on September 9 had carried its identifier since February 2025. Nineteen months separate the reservation of the identifier from federal confirmation of exploitation, and this board's published test was twelve. The rule ran, and the rating moved.

Then external review found a defect in the rule itself, and this board agrees. A reserved identifier is not public knowledge; it can sit private for months. A vulnerability whose identifier was reserved nineteen months earlier, and whose vendor disclosed and fixed it in January, eight months before federal confirmation, is a case of delayed federal exploitation confirmation despite prior public disclosure and available fixes. That is the boundary this condition was defined to exclude, not the thing it was defined to detect. The observable the criterion uses does not measure the condition's name.

What happens now is not a reversal. Reversing would mean this board deciding the correct rating after the fact, which is the outcome-fitting the whole method exists to prevent. Instead the upgrade action is voided: a result produced by an instrument that does not measure the condition has no evidentiary standing, the way a laboratory invalidates a result from an assay found to read the wrong marker rather than preserving the diagnosis until the next scheduled test. The prior state, Strengthening, stands, and the condition is placed under review. A revised criterion is declared today: an instance qualifies only where exploitation is documented before public disclosure, with both dates established in the registry. Under that test the Fortinet case does not qualify. Several entries in the window are candidates, PaperCut and Metabase among them, and each is tested on its documented chronology before the scheduled review on September 24, not assumed from a label. If a candidate satisfies the revised criterion, Confirmed returns through a valid instrument. The revision works against the direction of the rating action just taken, reducing the risk that the new criterion was selected to preserve that outcome.

How this was decided. Criterion in force (v1.0): one review cycle containing an instance whose identifier was assigned twelve or more months before listing; published Issue No. 33, frozen through the evaluation. Instance chronology, all fields: CVE-2025-25249, Fortinet. Identifier reserved 2025-02-05. Vendor disclosure and first fixed releases 2026-01-13 (advisory FG-IR-25-084). Exploitation reported in a campaign delivering a Node.js remote-access tool (secondary reporting; date of first observation not established). Federal listing 2026-09-09. Action under v1.0: STRENGTHENING to CONFIRMED, executed September 12; VOIDED this issue. Construct finding: identifier reservation is not defender awareness; v1.0 measures identification-to-confirmation lag; results produced under v1.0 have no standing, including the Ray disqualification, which is re-run under v2.0. Criterion v2.0, declared this issue for use from September 24: an instance qualifies where exploitation is documented, by vendor or authority, before public disclosure; both dates recorded in the registry. Fortinet under v2.0: disclosure January 13, listing September 9; exploitation not documented before disclosure; non-qualifying. Candidates for September 24: tested on documented exploitation date versus disclosure date; none pre-adjudicated here. Open question for that review: whether v2.0 narrows the condition to pre-disclosure exploitation, in which case the condition is renamed to say so, or whether awareness is defined more broadly than disclosure. State: STRENGTHENING / Stable / under review.

The Audit, and What It Changed

Last week this board met a published trigger while already at the top of its scale and found that the rule defined no consequence. The criterion audit that closed that gap is complete, and it changed four things, each declared before any case could use it.

First, the ceiling rule: an escalation trigger met at Confirmed does not move the rating and does not create a new tier. It is recorded, counted, and opens a mandatory review for a Position under the registry's issuance gate. The autonomous-operations trigger met on September 3 has opened that review, on agent containment as a structural condition of agent deployment; issuance is not presumed. Second, the counting unit for the vendor risk-signal ledger is now defined as the vendor assessment event, so the denominator cannot shift with the direction of the evidence. Third and fourth, two conditions that had escalation paths but no de-escalation paths now have both, declared while neither is near a boundary.

Status. Methodology changes this issue: 6, including the SC-2026-006 criterion revision and a new state-machine rule: a rating action produced under a criterion that fails construct validation is voided, the prior state stands, and the condition is placed under review until evaluated under a valid criterion. Under review is an analytical status, not a rating; the last valid rating remains displayed until a valid criterion produces a subsequent action. A Criteria Governance Standard placing these rules above the registry is declared today and effective from the next issue; from then, rating actions cite its provisions. Applied criteria are listed by version at the close of this report, a practice that begins with this issue.

Rating Maintenance

SC-2026-009 · Security Tooling as Exploited Surface: affirmed CONFIRMED; Outlook moves to Accumulating. The quiet streak that ran six cycles ended with two entries in six days. Cisco's Firewall Management Center, the console that founded this condition in July, returned with an authentication bypass reaching root, exploited, per Cisco Talos reporting distinct from the PSIRT advisory, by multiple intrusion clusters that Talos characterizes as including a state actor and a ransomware affiliate. Cisco's Secure Email Gateway followed yesterday with an unauthenticated SQL injection, also to root. The de-escalation clock reset on the first and the Outlook moved on the second.

Status. SC-2026-009: CONFIRMED / Accumulating / no watch. Class entries: management console (FMC), email security gateway (SEG). Named-actor attribution held at reported grade.

SC-2026-002 · Edge and Management-Plane Compromise: affirmed CONFIRMED. Citrix NetScaler took its second entry in two weeks, MikroTik RouterOS entered with a pair, and GitLab entered at the top of the severity scale with an unauthenticated file read on the commits API, the second source-control platform in three weeks. Under the registry's chronology test, Fortinet's January advisory ran eight months ahead of its listing, the longest vendor-published lead observed in the registry to date.

SC-2026-010 · Vendor Risk-Signal Reliability: affirmed EMERGING, Outlook Receding. Under the registry's chronology test, seven vendor-ahead cases have appeared since the reset and no documented reversal. Re-escalation requires three new reversals.

SC-2026-008 · Autonomous AI Attack Operations: affirmed CONFIRMED. Counted set unchanged; the Position-candidacy review opened by the ceiling rule is underway.

SC-2026-007 · Enterprise Application Plane Exploitation: affirmed CONFIRMED. Adobe Commerce entered on a template-engine injection.

SC-2026-004 · AI Agent Runtime Compromise: affirmed EMERGING. Quiet on its own mechanism.

Evidence note: a disclosure converted. Boston Scientific, which disclosed a global operational disruption under Item 8.01 on August 26, filed under Item 1.05 on September 8: the incident is likely to have a material impact on third-quarter and full-year results, and the company does not expect to meet its guidance. Twelve days from disclosure to materiality. It is the first conversion observed in CHQ's reviewed set. Against the two-year population it is rare in a different sense: the two-year tracker counts twenty-nine issuers under the material-incident item, fifty under other events, and five that filed under both, in each case an 8.01 followed by a 1.05 on determination. Dual-item filers are one in ten of the 8.01 population; this one carried a guidance consequence in the filing itself.

Board statistics, this issue

Conditions rated

7

Rating changes

0

Rating actions voided

1

Scope refinements

0

Watch status changes

0

Published triggers newly met this issue, rating unchanged

0

Methodology changes

6

Corrections to prior issues

0

Program Record

Reconciliation, disclosed at full volume. This program now reads the exploited catalog directly from its authoritative data file rather than through search and mirrors. The first full reconciliation of that file against the registry, covering every entry since March, found fifty-four catalog entries absent. Forty-one predate July, before this program treated every catalog alert as owed; they are admitted for completeness and labeled as not owed under the rules then in force, and the July boundary is declared as a reconstruction that will not be moved to reclassify anything later. Thirteen entries from July onward are genuine misses, now keyed to their true dates. Two of them founded observations this board published: the entries existed in the observation layer and never as signal rows, which is a failure class with its own rule now. Every open intake flag closed in the same pass. The registry holds the full list; this report records the count and the mechanism.

Intake. The catalog data file is now pulled at every run. Catalog census from the versioned file: 1,710 entries.

Applied criteria, by version. Rating scale v1.2 (18 Aug 2026); Watch and Outlook definitions v1.0 (Jul 2026); state machine, pause and reset rules v1.0 (17–18 Aug 2026); ceiling-consequence rule v1.0 (9 Sep 2026); SC-2026-010 independence unit v1.0 (9 Sep 2026); SC-2026-004 and SC-2026-006 de-escalation paths v1.0 (9 Sep 2026); SC-2026-006 lag criterion v1.0 (11 Aug 2026, applied this issue, invalidated) and v2.0 (15 Sep 2026, effective 24 Sep 2026); criterion-invalidation and void-action rule v1.0 (15 Sep 2026); sub-class accrual rule v1.0 (26 Aug 2026).

Standing Condition Board

ID

Condition

Rating

Outlook

This week

Reclassification / review criterion

SC-2026-007

Enterprise Application Plane Exploitation

CONFIRMED

Accumulating

Affirmed

New confirmed-exploited platform in the class; de-escalates on two consecutive quiet quarterly cycles

SC-2026-002

Edge and Management-Plane Compromise

CONFIRMED

Accumulating

Affirmed

De-escalates on two consecutive quarterly cycles with no new confirmed-exploitation entry across the declared sub-classes

SC-2026-008

Autonomous AI Attack Operations

CONFIRMED

Accumulating

Affirmed; Position review open

Second containment escape: met; Position-candidacy review under the issuance gate. Novel-discovery campaign forces review. Two quiet quarterly cycles across both sub-classes support de-escalation

SC-2026-006

Exploitation Precedes Defender Awareness

STRENGTHENING

Stable

Upgrade action voided on construct failure; rating under review; evaluation Sep 24 under v2.0

v2.0 from Sep 24: qualifying instance = exploitation documented before public disclosure. Two consecutive quarterly cycles without a qualifying instance move it down one tier

SC-2026-009

Security Tooling as Exploited Surface

CONFIRMED

Accumulating

Affirmed; Outlook raised

Two consecutive quarterly cycles with no new confirmed-exploitation entry across the declared classes move it down; campaign linkage forces review

SC-2026-010

Vendor Risk-Signal Reliability

EMERGING

Receding

Affirmed

Re-escalation requires three new documented reversals occurring after the de-escalation

SC-2026-004

AI Agent Runtime Compromise

EMERGING

Stable

Affirmed

First confirmed production incident reclassifies to Confirmed; retirement review after four quiet quarterly cycles

Rating Scale

  • EMERGING: condition observed, but evidence remains limited, contested, or below the condition's defined confirmation threshold.

  • STRENGTHENING: recurring across two or more independent instances; evidence accumulating toward the condition's defined confirmation threshold.

  • CONFIRMED: the condition has crossed its declared confirmation threshold through sustained independent evidence or a qualifying real-world event.

For exploitation conditions, the confirmation threshold is confirmed production exploitation; each non-exploitation condition declares its own threshold in the registry.

Outlook describes the direction of evidence accumulation in the trailing window: Accumulating, Stable, Receding. It is not a prediction. Watch indicates a defined reclassification trigger is mechanically near, and is directional; when proximity exists in both directions, both are shown.

Institutional Question

In three weeks this board has moved a condition down, recorded a trigger it could not act on, moved a condition up, and then found that the rule behind the upgrade measured the wrong thing and voided the move, each step by a rule published before the evidence arrived, and it has disclosed that its own intake was incomplete for months before it read the source directly. The question for the reader: when you last changed how your program collects evidence, did you go back and check what the old method had missed, or did you start the clock again from the day you fixed it?

Three questions for your own program this week. For your highest-consequence systems, is patch urgency keyed to the vendor advisory date, the identifier date, or the catalog date? If your security appliances, the ones that inspect and manage everything else, were reached to root tomorrow, would your monitoring see it or only your vendor's? And does your disclosure playbook define the trigger for revisiting a non-material determination, or does it wait for the next filing to force the question?

CybersecurityHQ publishes independent structural intelligence for security leadership. Conditions, positions, and falsification criteria are maintained at record.cybersecurityhq.com. Ratings reflect observable structural conditions at a point in time. They are not forecasts and do not assess applicability to any specific organization's environment.

Reply

Avatar

or to participate