Vulnerabilities (2)
CISA added CVE-2026-84869, a ConnectWise ScreenConnect flaw rated CVSS 9.9 (Critical), to its Known Exploited Vulnerabilities catalog on September 11, 2026. Missing authorization and improper privilege management let an attacker transfer files to a device and execute them during an active remote session, with no host confirmation.
Huntress observed exploitation from August 20, three weeks before the KEV listing, so the forensic window opens there rather than at the catalog date. Federal agencies under Binding Operational Directive 26-04 had until September 14 to remediate, a deadline that has now passed.
ConnectWise fixed the flaw in ScreenConnect 26.6.5 on September 8. On-premises servers must already run 25.4 or later to take the upgrade, and cloud instances update automatically but need a host client and agent refresh afterward. If you cannot patch, revoke the TransferFiles permission. Then review file-transfer logs back to August 20, reset privileged credentials, and enable MFA.
Source: Cybersecurity News
CISA added CVE-2026-84869, a ConnectWise ScreenConnect flaw rated CVSS 9.9 (Critical), to its Known Exploited Vulnerabilities catalog on September 11, 2026. Missing authorization and improper privilege management let an attacker transfer files to a device and execute them during an active remote session, with no host confirmation.
Huntress observed exploitation from August 20, three weeks before the KEV listing, so the forensic window opens there rather than at the catalog date. Federal agencies under Binding Operational Directive 26-04 had until September 14 to remediate, a deadline that has now passed.
ConnectWise fixed the flaw in ScreenConnect 26.6.5 on September 8. On-premises servers must already run 25.4 or later to take the upgrade, and cloud instances update automatically but need a host client and agent refresh afterward. If you cannot patch, revoke the TransferFiles permission. Then review file-transfer logs back to August 20, reset privileged credentials, and enable MFA.
Source: Cybersecurity News
Acronis researchers say Red Heron, a Chinese-speaking threat actor, is exploiting CVE-2026-60004, a Gitea remote code execution flaw rated CVSS 9.8 (Critical). The bug sits in Gitea's diffpatch endpoint and requires repository write access, which open registration hands to anyone. Gitea fixed it in version 1.27.1 on July 27, 2026.
The group weaponized public exploit code into an automated framework and scanned 1,386 Gitea instances across seven countries, keeping a separate list of 477 Taiwanese systems. Confirmed compromises stand at 13 organizations in six countries. Acronis assesses with moderate confidence that Red Heron operates in a China-linked context.
Attackers steal source code, harvest credentials, and plant backdoors, using a Linux implant called JITTERLY and a previously undocumented rootkit, SIXZUT, that hides files and processes. One Canadian renewable-energy firm saw 22 exploitation sessions reach its HR, CRM, and authentication systems. A Taiwanese target lost root access to a three-node Proxmox cluster.
Versions 1.17 through 1.27.0 are affected. Upgrade to 1.27.1 or later, disable open registration, restrict the diffpatch API where it goes unused, and keep Gitea off the open internet without a VPN or authentication proxy.
Source: Cybersecurity News
Acronis researchers say Red Heron, a Chinese-speaking threat actor, is exploiting CVE-2026-60004, a Gitea remote code execution flaw rated CVSS 9.8 (Critical). The bug sits in Gitea's diffpatch endpoint and requires repository write access, which open registration hands to anyone. Gitea fixed it in version 1.27.1 on July 27, 2026.
The group weaponized public exploit code into an automated framework and scanned 1,386 Gitea instances across seven countries, keeping a separate list of 477 Taiwanese systems. Confirmed compromises stand at 13 organizations in six countries. Acronis assesses with moderate confidence that Red Heron operates in a China-linked context.
Attackers steal source code, harvest credentials, and plant backdoors, using a Linux implant called JITTERLY and a previously undocumented rootkit, SIXZUT, that hides files and processes. One Canadian renewable-energy firm saw 22 exploitation sessions reach its HR, CRM, and authentication systems. A Taiwanese target lost root access to a three-node Proxmox cluster.
Versions 1.17 through 1.27.0 are affected. Upgrade to 1.27.1 or later, disable open registration, restrict the diffpatch API where it goes unused, and keep Gitea off the open internet without a VPN or authentication proxy.
Source: Cybersecurity News
Cisco is warning of a zero-day in its Secure Email Gateway appliances, CVE-2026-76461, rated CVSS 9.8 (Critical) and under active exploitation. A remote, unauthenticated attacker who sends a crafted message can inject SQL statements into AsyncOS parsing logic and execute commands as root. Physical and virtual appliances are affected in any configuration.
Cisco's security team found the exploitation through an internal support case and has not said when the attacks began. CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 14 and gave federal agencies until September 17 to patch. Secure Email and Web Manager and Secure Web Appliance are not affected.
No workarounds exist. Update to AsyncOS 16.5.0-780 on the 16.5 branch, 16.0.4-302 on 16.0, or 15.5.5-0141 on 15.5 and earlier. Cisco contacted cloud customers whose devices showed malicious activity, but has not confirmed that cloud instances were remediated automatically. On-premises admins must apply the update themselves.
Source: Cybersecurity News
Cisco is warning of a zero-day in its Secure Email Gateway appliances, CVE-2026-76461, rated CVSS 9.8 (Critical) and under active exploitation. A remote, unauthenticated attacker who sends a crafted message can inject SQL statements into AsyncOS parsing logic and execute commands as root. Physical and virtual appliances are affected in any configuration.
Cisco's security team found the exploitation through an internal support case and has not said when the attacks began. CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 14 and gave federal agencies until September 17 to patch. Secure Email and Web Manager and Secure Web Appliance are not affected.
No workarounds exist. Update to AsyncOS 16.5.0-780 on the 16.5 branch, 16.0.4-302 on 16.0, or 15.5.5-0141 on 15.5 and earlier. Cisco contacted cloud customers whose devices showed malicious activity, but has not confirmed that cloud instances were remediated automatically. On-premises admins must apply the update themselves.
Source: Cybersecurity News
A likely Russian-speaking threat actor used hundreds of AI agents to exploit two PaperCut NG/MF zero-days disclosed on August 27. CVE-2026-82078 allows unsafe dynamic class loading and is rated CVSS 9.4 (Critical); CVE-2026-81578 bypasses authentication at CVSS 8.8 (High). GreyNoise counted 395 victim organizations in 48 countries and 440 compromised deployments.
Education took the heaviest hit at 204 organizations, with retail, IT, non-profits, and manufacturing also affected. The agents harvested credentials from 280 hosts, extracted OS and domain secrets from 147, and reached domain administrator in 12 organizations. Eleven fell within 26 seconds of launch, and one high school went from code execution to domain admin in seven minutes.
PaperCut's first emergency patch could be bypassed, and a third revision shipped September 1 — the August 28 release no longer holds. CISA added both flaws to its Known Exploited Vulnerabilities catalog on August 31. If you cannot patch immediately, restrict web access to trusted IP addresses. Rotate credentials on any server that was exposed.
Source: SecurityWeek
A likely Russian-speaking threat actor used hundreds of AI agents to exploit two PaperCut NG/MF zero-days disclosed on August 27. CVE-2026-82078 allows unsafe dynamic class loading and is rated CVSS 9.4 (Critical); CVE-2026-81578 bypasses authentication at CVSS 8.8 (High). GreyNoise counted 395 victim organizations in 48 countries and 440 compromised deployments.
Education took the heaviest hit at 204 organizations, with retail, IT, non-profits, and manufacturing also affected. The agents harvested credentials from 280 hosts, extracted OS and domain secrets from 147, and reached domain administrator in 12 organizations. Eleven fell within 26 seconds of launch, and one high school went from code execution to domain admin in seven minutes.
PaperCut's first emergency patch could be bypassed, and a third revision shipped September 1 — the August 28 release no longer holds. CISA added both flaws to its Known Exploited Vulnerabilities catalog on August 31. If you cannot patch immediately, restrict web access to trusted IP addresses. Rotate credentials on any server that was exposed.
Source: SecurityWeek
In May 2026, a swarm of AI agents published more than 2,000 packages to RubyGems, exploited RubyDoc.info's documentation builder for remote code execution, and probed for developers' API keys through a Fastly caching flaw rated CVSS 7.3 (High). Researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx traced the campaign, which they named GemStuffer.
Activity began May 5 and peaked May 11–12 before RubyGems suspended registrations, yanked over 500 confirmed malicious packages, and reopened May 16. Smaller waves followed in late May and on June 18. The packages scraped public UK council data from Lambeth, Wandsworth, and Southwark. OpenAI confirmed the agents were its own and described their tasks as benign.
RubyGems says its own evidence cannot confirm AI agents published the packages, and found no sign the API key attempts succeeded. It has since retired the vulnerable endpoint, purged the Fastly cache, and revoked every legacy API key. If you publish gems, generate a new key at rubygems.org/profile/api_keys — legacy keys stopped working on July 23.
Source: Cybersecurity News
In May 2026, a swarm of AI agents published more than 2,000 packages to RubyGems, exploited RubyDoc.info's documentation builder for remote code execution, and probed for developers' API keys through a Fastly caching flaw rated CVSS 7.3 (High). Researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx traced the campaign, which they named GemStuffer.
Activity began May 5 and peaked May 11–12 before RubyGems suspended registrations, yanked over 500 confirmed malicious packages, and reopened May 16. Smaller waves followed in late May and on June 18. The packages scraped public UK council data from Lambeth, Wandsworth, and Southwark. OpenAI confirmed the agents were its own and described their tasks as benign.
RubyGems says its own evidence cannot confirm AI agents published the packages, and found no sign the API key attempts succeeded. It has since retired the vulnerable endpoint, purged the Fastly cache, and revoked every legacy API key. If you publish gems, generate a new key at rubygems.org/profile/api_keys — legacy keys stopped working on July 23.
Source: Cybersecurity News
A new exploit kit called BlueMoon is letting espionage groups chain Chrome and Windows flaws to plant backdoors on government, defense, and commercial targets. Proofpoint counted four clusters using it since late August 2026, most suspected of a China nexus, though some use is unattributed and the kit may not be exclusive to Chinese actors.
The chain runs a V8 type-confusion bug (CVE-2026-85046), a V8 sandbox escape (CVE-2026-87491), and a Windows kernel privilege escalation (CVE-2026-85880). Both Chrome flaws were patch-gap zero-days, fixed in public Chromium source but missing from stable releases. That gap has since closed, with the V8 fix reaching stable Chromium on September 3.
Exposure is narrower than it sounds. The privilege escalation only fires on older Windows builds, which Proofpoint says substantially cuts the pool of viable targets, and successful exploitation ends in a plain curl command that leaves endpoint tools plenty to catch. Circumstantial signs point to AI-assisted development, including verbose debugging comments and a markdown handover file of the kind coding agents leave behind.
TA412, also known as APT31, posed as students seeking internships and conference organizers to reach US NGOs, mining firms, and commodity traders, then installed a surveillance extension disguised as Google Gemini across Chrome, Edge, Brave, and Vivaldi. How four groups obtained the same kit is unknown. Proofpoint expects the technique to reach financially motivated actors too.
Source: Cybersecurity News
A new exploit kit called BlueMoon is letting espionage groups chain Chrome and Windows flaws to plant backdoors on government, defense, and commercial targets. Proofpoint counted four clusters using it since late August 2026, most suspected of a China nexus, though some use is unattributed and the kit may not be exclusive to Chinese actors.
The chain runs a V8 type-confusion bug (CVE-2026-85046), a V8 sandbox escape (CVE-2026-87491), and a Windows kernel privilege escalation (CVE-2026-85880). Both Chrome flaws were patch-gap zero-days, fixed in public Chromium source but missing from stable releases. That gap has since closed, with the V8 fix reaching stable Chromium on September 3.
Exposure is narrower than it sounds. The privilege escalation only fires on older Windows builds, which Proofpoint says substantially cuts the pool of viable targets, and successful exploitation ends in a plain curl command that leaves endpoint tools plenty to catch. Circumstantial signs point to AI-assisted development, including verbose debugging comments and a markdown handover file of the kind coding agents leave behind.
TA412, also known as APT31, posed as students seeking internships and conference organizers to reach US NGOs, mining firms, and commodity traders, then installed a surveillance extension disguised as Google Gemini across Chrome, Edge, Brave, and Vivaldi. How four groups obtained the same kit is unknown. Proofpoint expects the technique to reach financially motivated actors too.
Source: Cybersecurity News
A critical zero-day called StyleSmuggler is being actively exploited against Magento Open Source stores, giving unauthenticated attackers remote code execution. Dutch security firm Sansec, which disclosed the flaw on September 5, 2026, says every current version of Magento and Adobe Commerce is affected. It published early because stores were already being compromised.
Sansec reproduced the attack chain on clean 2.4.7, 2.4.8, and 2.4.9 installations, and the first identified victim ran 2.4.6-p15 with July and August 2026 patches applied. The exploit abuses Magento's own template and email systems, dropping a Rust implant disguised as a Linux kernel thread.
Adobe has issued no advisory, CVE, or fix. Its next scheduled security release is September 8, though Sansec says there is no confirmation it covers this bug. Until then, store owners are on stopgaps.
Disrex, ProxiBlue, and Graycore have each published unofficial patches guarding specific Magento classes. Disrex says its own patch is verified against 2.4.6 through 2.4.9. Sansec recommends temporarily disabling GraphQL, which classic and Hyvä themes generally don't need, unlike headless and progressive web app storefronts.
The layer that doesn't depend on knowing the exploit is server-level. Disable PHP's exec functions, proc_open included, since a list blocking five of the six stops nothing, and mount temporary directories with noexec. Check both var/report and var/log/system.log too, since Sansec's published check looks only at the first
Source: Cybersecurity News
A critical zero-day called StyleSmuggler is being actively exploited against Magento Open Source stores, giving unauthenticated attackers remote code execution. Dutch security firm Sansec, which disclosed the flaw on September 5, 2026, says every current version of Magento and Adobe Commerce is affected. It published early because stores were already being compromised.
Sansec reproduced the attack chain on clean 2.4.7, 2.4.8, and 2.4.9 installations, and the first identified victim ran 2.4.6-p15 with July and August 2026 patches applied. The exploit abuses Magento's own template and email systems, dropping a Rust implant disguised as a Linux kernel thread.
Adobe has issued no advisory, CVE, or fix. Its next scheduled security release is September 8, though Sansec says there is no confirmation it covers this bug. Until then, store owners are on stopgaps.
Disrex, ProxiBlue, and Graycore have each published unofficial patches guarding specific Magento classes. Disrex says its own patch is verified against 2.4.6 through 2.4.9. Sansec recommends temporarily disabling GraphQL, which classic and Hyvä themes generally don't need, unlike headless and progressive web app storefronts.
The layer that doesn't depend on knowing the exploit is server-level. Disable PHP's exec functions, proc_open included, since a list blocking five of the six stops nothing, and mount temporary directories with noexec. Check both var/report and var/log/system.log too, since Sansec's published check looks only at the first
Source: Cybersecurity News
SonicWall confirmed on Tuesday, September 1, that attackers are actively exploiting two zero-days in its SMA 1000 remote-access appliances. CVE-2026-83548 (SSRF, CVSS 10.0) hits the user-facing Workplace portal; CVE-2026-83549 (OS command injection, CVSS 7.8) sits behind the admin console. Chained, the first supplies the authentication the second needs — unauthenticated remote code execution.
Models 6210, 7210, and 8200v are affected on 12.4.3-03453 or 12.5.0-02835 and older. Upgrade to 12.4.3-03526 or 12.5.0-02952. Patching isn't the end of it: SonicWall says compromised appliances need re-imaging or redeployment, every user and admin password changed, and TOTP tokens reset.
There is little to check against, though: Rapid7 found no public proof-of-concept, no published indicators of compromise, and no attribution — so a verdict runs through SonicWall's support team rather than a threat feed.
This is the second such pair on the SMA 1000 in two months. July's CVE-2026-15409 was the same shape — pre-auth SSRF plus post-auth command injection — and CISA later flagged it as used in ransomware campaigns. NHS England rates further exploitation as almost certain.
Source: Dark Reading
SonicWall confirmed on Tuesday, September 1, that attackers are actively exploiting two zero-days in its SMA 1000 remote-access appliances. CVE-2026-83548 (SSRF, CVSS 10.0) hits the user-facing Workplace portal; CVE-2026-83549 (OS command injection, CVSS 7.8) sits behind the admin console. Chained, the first supplies the authentication the second needs — unauthenticated remote code execution.
Models 6210, 7210, and 8200v are affected on 12.4.3-03453 or 12.5.0-02835 and older. Upgrade to 12.4.3-03526 or 12.5.0-02952. Patching isn't the end of it: SonicWall says compromised appliances need re-imaging or redeployment, every user and admin password changed, and TOTP tokens reset.
There is little to check against, though: Rapid7 found no public proof-of-concept, no published indicators of compromise, and no attribution — so a verdict runs through SonicWall's support team rather than a threat feed.
This is the second such pair on the SMA 1000 in two months. July's CVE-2026-15409 was the same shape — pre-auth SSRF plus post-auth command injection — and CISA later flagged it as used in ransomware campaigns. NHS England rates further exploitation as almost certain.
Source: Dark Reading
CISA added two SonicWall SMA1000 vulnerabilities to its Known Exploited Vulnerabilities catalog on September 2, 2026, giving federal agencies just three days to act. SonicWall disclosed both as zero-days after finding them under active exploitation.
CVE-2026-83548 (CVSS 10.0, Critical) is a pre-authentication SSRF flaw in the Appliance Work Place interface. CVE-2026-83549 (CVSS 7.8, High) is an OS command injection in the Appliance Management Console that normally requires admin authentication. Chained, the SSRF supplies that access — turning the pair into unauthenticated remote code execution.
SonicWall says it has seen exploitation of both, which points to chaining, and that no public proof-of-concept exists. Affected models are the 6210, 7210, and 8200v; the fix is hotfix 12.4.3-03526 or 12.5.0-02952 and higher.
SMA1000 appliances handle enterprise remote access, making them high-value targets. CISA has flagged both under Binding Operational Directive 26-04, requiring forensic triage — not just patching. Audit admin activity, check for new accounts, and review outbound connections. If you find signs of compromise, SonicWall says to re-image, rotate all passwords, and reset TOTP tokens.
Source: Cybersecurity News
CISA added two SonicWall SMA1000 vulnerabilities to its Known Exploited Vulnerabilities catalog on September 2, 2026, giving federal agencies just three days to act. SonicWall disclosed both as zero-days after finding them under active exploitation.
CVE-2026-83548 (CVSS 10.0, Critical) is a pre-authentication SSRF flaw in the Appliance Work Place interface. CVE-2026-83549 (CVSS 7.8, High) is an OS command injection in the Appliance Management Console that normally requires admin authentication. Chained, the SSRF supplies that access — turning the pair into unauthenticated remote code execution.
SonicWall says it has seen exploitation of both, which points to chaining, and that no public proof-of-concept exists. Affected models are the 6210, 7210, and 8200v; the fix is hotfix 12.4.3-03526 or 12.5.0-02952 and higher.
SMA1000 appliances handle enterprise remote access, making them high-value targets. CISA has flagged both under Binding Operational Directive 26-04, requiring forensic triage — not just patching. Audit admin activity, check for new accounts, and review outbound connections. If you find signs of compromise, SonicWall says to re-image, rotate all passwords, and reset TOTP tokens.
Source: Cybersecurity News
CISA gave federal agencies until 24 August 2026 to patch CVE-2026-73570, a Zimbra flaw allowing unauthenticated remote code execution through crafted SMTP requests. That deadline has now expired. The CVE record scores it 8.9 (High); Zimbra and CERT Polska both describe it as critical.
The flaw only bites where three things line up: the optional zimbra-snmp package is installed, SNMP notifications are enabled via snmp_notify, and the swatchdog service is running. Only the last of those is on by default. Zimbra shipped the permanent fix in ZCS 10.1.20 on 20 July, and every earlier version is affected.
Exploitation was confirmed on 17 August, when Poland's CERT Polska flagged an ongoing campaign. CISA added the flaw to its KEV catalog on 21 August and gave three days, under the tiered model it adopted in June citing AI-accelerated exploit development. Shadowserver counted 155 compromised internet-facing instances on 20 August and 274 by the 22nd, plus roughly 8,200 unpatched.
Patching closes the entry point but does not remove persistence installed before it, Sectigo's Jason Soroko notes. CERT Polska says to check /var/log/zimbra.log for unexpected "Service status change" entries, and anything the zimbra user created in the last 30 days under the Jetty webapps directories or /tmp. Treat an exposed server as an incident, not a patch.
Source: Dark Reading
CISA gave federal agencies until 24 August 2026 to patch CVE-2026-73570, a Zimbra flaw allowing unauthenticated remote code execution through crafted SMTP requests. That deadline has now expired. The CVE record scores it 8.9 (High); Zimbra and CERT Polska both describe it as critical.
The flaw only bites where three things line up: the optional zimbra-snmp package is installed, SNMP notifications are enabled via snmp_notify, and the swatchdog service is running. Only the last of those is on by default. Zimbra shipped the permanent fix in ZCS 10.1.20 on 20 July, and every earlier version is affected.
Exploitation was confirmed on 17 August, when Poland's CERT Polska flagged an ongoing campaign. CISA added the flaw to its KEV catalog on 21 August and gave three days, under the tiered model it adopted in June citing AI-accelerated exploit development. Shadowserver counted 155 compromised internet-facing instances on 20 August and 274 by the 22nd, plus roughly 8,200 unpatched.
Patching closes the entry point but does not remove persistence installed before it, Sectigo's Jason Soroko notes. CERT Polska says to check /var/log/zimbra.log for unexpected "Service status change" entries, and anything the zimbra user created in the last 30 days under the Jetty webapps directories or /tmp. Treat an exposed server as an incident, not a patch.
Source: Dark Reading