Back to Archive
THREAT INTELLIGENCE BRIEFยทSunday, September 6, 2026ยทAI-Powered

The most urgent threat this week is an unpatched, actively exploited zero-day vulnerability in Magento and Adobe Commerce, which requires immediate attention to mitigate ongoing attacks.

The most urgent threat this week is an unpatched, actively exploited zero-day vulnerability in Magento and Adobe Commerce, which requires immediate attention to mitigate ongoing attacks. Additionally, two vulnerabilities in PaperCut print management software, CVE-2026-81578 and CVE-2026-82078, are confirmed by CISA as actively exploited in the wild. Other critical flaws in the Elementor Pro WordPress plugin and VMware virtualization platforms also demand review and remediation to prevent potential exploitation.

11 articles analysed4 CVEs mentioned

Threat Categories

๐Ÿ›Vulnerabilities4
๐Ÿ“„Data Breach1

Article Analyses (5)

Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

critical

Details

A new, unpatched zero-day vulnerability, named 'StyleSmuggler', is being actively exploited in Magento Open Source and Adobe Commerce. The flaw allows unauthenticated attackers to execute arbitrary code on a server, enabling them to backdoor online stores. Attacks have been observed in the wild since September 4th.

Affected Systems

Magento Open Source, Adobe Commerce (specific versions not detailed in reporting).

Potential Impact

Complete compromise of e-commerce platforms, leading to data theft (customer data, payment information), installation of backdoors, and potential financial fraud.

Mitigations

As no official patch is available, organizations should immediately apply compensating controls. Monitor for indicators of compromise provided by security firms like Sansec and restrict access to administrative endpoints. Prepare to apply the official patch as soon as it is released by Adobe.

The Hacker NewsDraft Post

Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

critical
CVE-2026-81578CVE-2026-82078
KEVEPSS 1.7%

Details

Threat actors are chaining two vulnerabilities, CVE-2026-81578 (authentication bypass) and CVE-2026-82078 (remote code execution), to attack PaperCut NG/MF servers. The attack chain allows for command execution, reconnaissance, and credential theft. The education sector is a primary target.

Affected Systems

PaperCut NG/MF print management software.

Potential Impact

Unauthorized access to sensitive networks, credential theft, and lateral movement within the compromised organization, with a significant operational risk for educational institutions.

Mitigations

Both CVEs are on the CISA KEV list. Organizations using affected PaperCut software must apply the vendor-supplied security updates immediately to prevent exploitation.

The Hacker NewsDraft Post

Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

high
CVE-2026-32475
EPSS 2.4%

Details

A critical arbitrary file upload vulnerability, CVE-2026-32475 (CVSS 9.8), exists in the popular Elementor Pro WordPress plugin. The flaw is in a function that handles form submissions, allowing attackers to upload malicious files and potentially achieve remote code execution. The vulnerability is reportedly being exploited.

Affected Systems

Elementor Pro WordPress Plugin (specific vulnerable versions should be confirmed with the vendor).

Potential Impact

Complete website compromise, leading to defacement, data theft, or use of the server for further malicious activities like hosting malware or phishing pages.

Mitigations

Update the Elementor Pro plugin to the latest patched version immediately. Review website files for any signs of compromise or unauthorized uploads.

SecurityWeekDraft Post

Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

critical
CVE-2026-59346

Details

A critical integer-overflow vulnerability, CVE-2026-59346 (CVSS 9.3), affects VMware Workstation and Fusion. The flaw can be exploited by a local attacker with elevated privileges (such as a VM administrator) to execute arbitrary code on the host machine, effectively escaping the virtual machine.

Affected Systems

VMware Workstation and Fusion.

Potential Impact

Loss of segmentation between virtual environments and the host system. A compromised VM could lead to the compromise of the underlying physical hardware, enabling access to all other VMs and the host network.

Mitigations

Apply the security updates released by Broadcom for all affected VMware Workstation and Fusion installations. Restrict administrative privileges within VMs to trusted users only.

The Hacker NewsDraft Post

Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted

critical

Details

Hardware wallet maker Trezor disclosed a data breach at its third-party shipping provider, ShipMonk. The breach exposed the personal data of 67,000 U.S. customers, including names, email addresses, phone numbers, and shipping addresses for orders placed between November 2019 and August 2021.

Affected Systems

Trezor customers who placed orders in the U.S. between November 2019 and August 2021.

Potential Impact

Increased risk of targeted phishing, social engineering, and physical threats against Trezor hardware wallet owners. The breach does not affect the security of the hardware wallets themselves but exposes their owners to external threats.

Mitigations

Notify affected customers and advise them to be vigilant against phishing attempts. Review third-party vendor security policies and data retention agreements to ensure compliance and minimize future supply chain risks.

The Hacker NewsDraft Post
Generated by gemini-2.5-pro