Back to Archive
THREAT INTELLIGENCE BRIEFยทWednesday, September 9, 2026ยทAI-Powered

This week is dominated by actively exploited, maximum-severity vulnerabilities in widely deployed enterprise software.

This week is dominated by actively exploited, maximum-severity vulnerabilities in widely deployed enterprise software. The most urgent threats are two zero-day vulnerabilities, CVE-2026-86218 in N-able N-central and CVE-2026-75650 in Adobe Commerce/Magento, both of which have been added to the CISA KEV list, confirming active exploitation. Compounding these targeted threats, Microsoft released a record-breaking Patch Tuesday, addressing 974 flaws, including two actively exploited zero-days in Windows. Additionally, Google has patched a seventh Chrome zero-day this year, also under active exploitation.

64 articles analysed2 CVEs mentioned

Threat Categories

๐Ÿ›Vulnerabilities4
๐Ÿ“งPhishing1

Article Analyses (5)

[CRITICAL] "N-able N-central Pre-Auth RCE Flaw Exploited in the Wild" โ€” The Hacker News

critical
CVE-2026-86218
KEVEPSS 0.4%

Details

A critical pre-authentication remote code execution (RCE) vulnerability in N-able N-central allows unauthenticated attackers to gain complete control of affected systems. The flaw has a maximum CVSS score of 10.0.

Affected Systems

N-able N-central

Potential Impact

Compromise of N-able N-central, a remote monitoring and management (RMM) platform, could allow attackers to gain administrative access to the networks of managed service providers (MSPs) and their downstream customers, leading to widespread system compromise.

Mitigations

Apply patches immediately. CISA has mandated that Federal Civilian Executive Branch (FCEB) agencies apply fixes by September 11, 2026.

The Hacker NewsDraft Post

[CRITICAL] "Adobe fixes critical Magento zero-day exploited to backdoor servers" โ€” BleepingComputer

critical
CVE-2026-75650
KEVEPSS 0.7%

Details

Tracked as CVE-2026-75650 and codenamed 'StyleSmuggler', this is an actively exploited zero-day vulnerability. The flaw allows an unauthenticated attacker to execute arbitrary code on vulnerable servers. Attackers have been observed exploiting it to deploy Rust backdoors and PHP web shells.

Affected Systems

Adobe Commerce and Magento Open Source (multiple versions).

Potential Impact

Successful exploitation allows attackers to take full control of e-commerce servers, leading to theft of customer data, payment card information, and installation of persistent backdoors for long-term access.

Mitigations

Apply the emergency security patches released by Adobe immediately.

BleepingComputerDraft Post

[CRITICAL] "Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days" โ€” The Hacker News

critical

Details

Microsoft's September 2026 Patch Tuesday is the largest in its history, addressing 974 vulnerabilities. The patches include fixes for two privilege escalation zero-day vulnerabilities that are confirmed to be actively exploited in the wild. Over 110 of the fixed flaws are rated as critical.

Affected Systems

Microsoft Windows, Office, SQL Server, and Developer Tools.

Potential Impact

The sheer volume of vulnerabilities, including actively exploited zero-days and over 100 critical flaws, presents a massive attack surface. Exploitation could lead to privilege escalation, remote code execution, and complete system compromise across workstations and servers.

Mitigations

Prioritize and deploy the September 2026 security updates across all affected Microsoft products. Focus first on the two actively exploited zero-days and any critical, internet-facing systems.

The Hacker NewsDraft Post

[CRITICAL] "Google warns of new Chrome zero-day bug exploited in attacks" โ€” BleepingComputer

critical

Details

Google has patched the seventh actively exploited zero-day vulnerability in its Chrome web browser since the beginning of the year. The flaw is being exploited in the wild, though technical details are being withheld to allow time for users to update.

Affected Systems

Google Chrome web browser on all platforms (Windows, macOS, Linux).

Potential Impact

Exploitation of a browser zero-day can lead to arbitrary code execution on user workstations simply by visiting a malicious website. This can result in credential theft, malware installation, and lateral movement into the corporate network.

Mitigations

Ensure all instances of Google Chrome are updated to the latest version immediately. Browser auto-update features should be enabled and verified.

BleepingComputerDraft Post

[CRITICAL] "Trezor customers hit with phishing calls and letters after shipping-partner breach" โ€” Help Net Security

critical

Details

A data breach at ShipMonk, a shipping partner for the hardware crypto-wallet manufacturer Trezor, has exposed the personal information of approximately 67,000 customers. Exposed data includes names, email addresses, phone numbers, and shipping addresses. This information is being actively used in targeted phishing campaigns.

Affected Systems

Trezor customers who had products shipped via ShipMonk.

Potential Impact

This is a supply chain attack targeting end-users. Employees, especially executives or finance personnel, who use these devices are at high risk of sophisticated, personalized phishing attacks (email, phone, physical mail) aimed at stealing cryptocurrency assets or corporate credentials.

Mitigations

Issue an immediate security advisory to all personnel, especially VIPs and finance teams, about this breach. Advise them to be extremely cautious of any unsolicited communications regarding their Trezor devices and to never share their recovery seeds.

Help Net SecurityDraft Post
Generated by gemini-2.5-pro