Back to Archive
THREAT INTELLIGENCE BRIEFยทTuesday, September 8, 2026ยทAI-Powered

This morning's top threat is a critical zero-day vulnerability in N-able's N-central RMM software (CVE-2026-86218), which is reportedly exploited in the wild.

This morning's top threat is a critical zero-day vulnerability in N-able's N-central RMM software (CVE-2026-86218), which is reportedly exploited in the wild. While not yet on the CISA KEV list, this pre-authentication RCE flaw poses a significant risk to managed service providers and their clients, demanding immediate patching. Other major threats include the active exploitation of an unpatched zero-day in Adobe Commerce and Magento dubbed 'StyleSmuggler', a flaw chain enabling the hijacking of MikroTik routers, and the public release of zero-day exploits for CrowdStrike, Nvidia, and Avast software.

39 articles analysed1 CVEs mentioned

Threat Categories

๐Ÿ›Vulnerabilities4
๐Ÿ’€Malware1

Article Analyses (5)

[CRITICAL] "N-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218)"

critical
CVE-2026-86218
EPSS 0.4%

Details

A critical pre-authentication remote code execution (RCE) vulnerability, CVE-2026-86218, has been discovered in N-able's N-central RMM solution. The flaw allows an attacker to execute code on the N-central server without needing to authenticate. At least one report indicates the vulnerability has been exploited in the wild as a zero-day.

Affected Systems

All on-premises N-able N-central builds below 2026.3.1.14.

Potential Impact

Successful exploitation could lead to a complete compromise of the N-central server, enabling attackers to control the remote monitoring and management infrastructure. This could provide downstream access to the networks of all managed service provider (MSP) clients, leading to widespread data breaches and ransomware deployment.

Mitigations

Immediately apply Hotfix 4 for N-central 2026.3 to update to build version 2026.3.1.14 or later.

Help Net SecurityDraft Post

[CRITICAL] "Adobe Commerce Zero-Day Exploited to Backdoor Online Stores"

critical

Details

A zero-day vulnerability named 'StyleSmuggler' is being actively exploited to attack Adobe Commerce and Magento stores. The flaw allows unauthenticated attackers to execute code and deploy a stealthy backdoor on vulnerable e-commerce platforms.

Affected Systems

All versions of Magento Open Source and Adobe Commerce.

Potential Impact

Attackers can gain persistent control over online stores, potentially leading to the theft of customer data, payment card information, and intellectual property. The backdoor could also be used to launch further attacks against customers.

Mitigations

As this is an unpatched zero-day, no official patch is available. Organizations should monitor for security updates from Adobe, review their systems for indicators of compromise, and consider implementing enhanced access controls and web application firewall (WAF) rules to mitigate risk.

SecurityWeekDraft Post

[CRITICAL] "Hackers exploit new MikroTik RouterOS flaws to hijack routers"

critical

Details

Attackers are actively exploiting a chain of two recently disclosed vulnerabilities in MikroTik's RouterOS. The exploit chain, named 'MikroTrick' by CERT Polska, allows an unauthenticated attacker to take full control of a device.

Affected Systems

MikroTik routers with SSH services exposed to the internet.

Potential Impact

Compromise of network routers can lead to man-in-the-middle attacks, traffic interception, DNS hijacking, and use of the device as a pivot point into the internal network. This poses a severe risk to network integrity and data confidentiality.

Mitigations

Ensure MikroTik devices are updated with the latest RouterOS patches. As a best practice, do not expose SSH services to the public internet. If remote management is necessary, use a secure VPN with multi-factor authentication.

BleepingComputerDraft Post

[HIGH] "Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits"

high
PoC

Details

Proof-of-concept (PoC) exploits for zero-day vulnerabilities affecting CrowdStrike, Nvidia, and Avast products have been publicly released. The exploits lead to privilege escalation, allowing an attacker to spawn a shell with SYSTEM-level privileges.

Affected Systems

Specific versions of CrowdStrike, Nvidia, and Avast software (details not specified in articles).

Potential Impact

Successful exploitation allows a low-privileged user to gain full administrative control over an affected system. This can be used to disable security controls, steal sensitive data, deploy malware, and establish persistence within the network.

Mitigations

The release of PoC code significantly increases the likelihood of exploitation. Organizations using these products should urgently monitor for security advisories and patches from the respective vendors and prepare for rapid deployment.

SecurityWeekDraft Post

[MEDIUM] "Modified ScreenConnect Clients Used in Worm-Like Campaign"

medium

Details

A malicious campaign is abusing ConnectWise ScreenConnect, using backdoored clients to automatically transfer and execute a four-stage VBScript payload to newly connected systems. The activity exhibits worm-like characteristics, enabling it to spread across connected hosts.

Affected Systems

Environments using ConnectWise ScreenConnect for remote support and administration.

Potential Impact

The worm-like behavior can lead to rapid and widespread compromise across an organization's managed endpoints, allowing attackers to execute malicious payloads on affected systems.

Mitigations

Monitor ScreenConnect instances for unauthorized modifications or suspicious behavior. Ensure initial access vectors like phishing and tech-support scams are addressed through user training and security controls. Review logs for unusual client connection patterns.

SecurityWeekDraft Post
Generated by gemini-2.5-pro