Magento “StyleSmuggler” Unpatched RCE, MikroTik “MikroTrick” SSH Takeover Chain, and N-able N-central CVSS 10.0 Pre-Auth RCE

This brief covers the trailing ~48 hours (September 5–7, 2026). Every item below was verified against its primary source (vendor advisory, national CERT, or original researcher) and dated from that source. Three unauthenticated remote-takeover bugs dominate the window: an unpatched Magento/Adobe Commerce zero-day, an actively exploited MikroTik RouterOS SSH chain, and a maximum-severity N-able N-central RCE.

Magento and Adobe Commerce: unpatched “StyleSmuggler” zero-day gives unauthenticated RCE, actively exploited

Sansec · September 5, 2026

Sansec disclosed StyleSmuggler, an unauthenticated remote code execution flaw in Magento Open Source and Adobe Commerce, after observing live attacks that began September 4. No CVE ID, CVSS score, Adobe advisory, or patch exists as of this writing, and the bug is not in CISA KEV. Sansec reproduced the full unauthenticated chain on clean 2.4.7, 2.4.8, and 2.4.9 installs; the first known victim was running 2.4.6-p15 with the July and August 2026 security updates applied. The attack poisons a file Magento writes itself (such as a failure report or log), then triggers execution via the platform’s “Payment Transaction Failed Reminder” email, ultimately dropping a persistent Rust implant disguised as a kernel thread ([kworker/u:8:0]) under ~/.local/share/.gvfsd/. Sansec’s interim advice for stores not behind its WAF is to temporarily disable GraphQL; Adobe’s next scheduled security release is September 8.

“Sansec is publishing early because stores are being compromised right now.”
— Sansec, StyleSmuggler advisory (as quoted by The Hacker News)

Source: Sansec advisory · The Hacker News

MikroTik RouterOS: CERT Polska confirms “MikroTrick” SSH auth-bypass + privilege-escalation chain exploited in the wild

CERT Polska / MikroTik · September 5, 2026

CERT Polska published details of six RouterOS vulnerabilities it discovered and coordinated, warning that two of them are being chained (“MikroTrick”) to take full control of routers with SSH reachable from the internet. CVE-2026-67276 (CVSS 9.2) is an SSH authentication bypass: RouterOS compared only the RSA key type and modulus, not the full public key, so an attacker who knows a user’s modulus can forge a key and log in without the private key. CVE-2026-86060 (CVSS 9.2) is an SSH privilege-escalation flaw triggered by a username beginning with a disallowed character, yielding a session with full admin rights. A third bug, CVE-2026-67277 (CVSS 8.8), in the bandwidth-test service allows unauthenticated kernel memory disclosure or a remote crash. MikroTik shipped fixes on September 3 in RouterOS 7.25beta3, 7.24.2, 7.23.4, and 6.49.21 and added a startup “Flagged” compromise-detection check. CERT Polska says successful attacks from 82.192.72.4 date to at least September 2 and that the patches stop the observed attacks. None of the CVEs are in CISA KEV yet.

“We have obtained confirmation that the attackers are exploiting this combination of vulnerabilities to take full control of devices whose SSH service is accessible from public networks.”
— CERT Polska

Source: CERT Polska advisory · MikroTik security bulletin · BleepingComputer

N-able N-central: emergency Hotfix 4 for CVE-2026-86218, CVSS 10.0 pre-authentication RCE

N-able · September 5–6, 2026

N-able released N-central 2026.3 Hotfix 4 (build 2026.3.1.14) on September 5 to fix CVE-2026-86218, a pre-authentication remote code execution vulnerability in the RMM platform’s server, rated CVSS 10.0 per Huntress. The hotfix supersedes HF3, which was issued a day earlier for two authentication-bypass bugs (CVE-2026-86206 and CVE-2026-86207); systems on HF3 remain vulnerable to the new flaw. N-able’s public advisory says it has no confirmation of exploitation in production, but Huntress and Help Net Security report a separate customer notice from N-able describing the bug as observed exploited in the wild, and Huntress had earlier found a compromised, patched N-central server whose logs had rotated. Hosted (NCOD) instances are already patched; on-premises customers must upgrade. Not in CISA KEV. Shadowserver counts nearly 1,500 internet-exposed N-central servers.

“At this time, we have no confirmations that this vulnerability has been exploited in production environments, but unpatched systems remain at risk.”
— N-able, N-central 2026.3 Hotfix 4 release notes

Source: N-able status notice · HF4 release notes · Huntress · BleepingComputer

Still developing

Google Chrome: CVE-2026-85046 V8 type confusion exploited in the wild, now in CISA KEV

Google / CISA · September 3–4, 2026

Google shipped Chrome 152.0.7977.82/.83 (Windows, macOS) and 152.0.7977.82 (Linux) on September 3 with 12 security fixes, including CVE-2026-85046, a High-severity type confusion in the V8 JavaScript engine reported by Salvatore Gulizia (“Serotav”). Google confirmed an exploit exists in the wild; it is the sixth Chrome zero-day patched this year. CISA added it to the KEV catalog on September 4 with a federal remediation deadline of September 18. Chromium-based browsers (Edge, Brave, Opera, Vivaldi) will pick up the fix on their own schedules.

“Google is aware that an exploit for CVE-2026-85046 exists in the wild.”
— Google Chrome Releases

Source: Chrome Releases · CISA KEV alert · BleepingComputer

ConnectWise ScreenConnect: file-transfer flaw with mitigation only, patch expected this week

ConnectWise · September 3, 2026

ConnectWise disclosed an issue “affecting file transfer behavior” in ScreenConnect Remote Access Support and Access sessions, impacting both cloud and on-premises deployments. No CVE has been assigned and no patch is available yet; the vendor’s interim mitigation is to remove the TransferFiles (or legacy TransferFilesInSession) scoped permission from every role’s session groups. Shadowserver tracks nearly 6,000 exposed ScreenConnect instances. Not in CISA KEV.

Source: ConnectWise security advisories · BleepingComputer


This brief covers the trailing ~48 hours (September 5–7, 2026).

Primary sources:

Leave a Reply