Two Exploited Windows Zero-Days, Magento “StyleSmuggler” RCE and N-central Pre-Auth RCE Hit CISA KEV; Chrome V8 Zero-Day Patched

This brief covers the trailing ~48 hours (September 7–9, 2026). Every item below was verified against its primary source — vendor advisory, CISA KEV entry, CVE record, or original researcher publication — before inclusion.

Microsoft patches two exploited Windows privilege-escalation zero-days in record Patch Tuesday

Microsoft MSRC · September 8, 2026

September’s Patch Tuesday fixed roughly 970 vulnerabilities, including two elevation-of-privilege flaws Microsoft confirms are exploited in the wild. CVE-2026-81963 (CVSS 3.1: 7.8, Important) is a link-following bug in the Windows Update Stack affecting Windows 11 and Windows Server 2025, reported by MSTIC. CVE-2026-85880 (CVSS 3.1: 7.8, Important) is a heap-based buffer overflow in Windows ALPC affecting Windows 10 and Windows Server 2012–2022, credited to Volexity and Proofpoint; Microsoft notes it lets code in a low-privilege AppContainer escape the sandbox. Both grant SYSTEM, both are patched, and CISA added both to KEV on September 8. Also worth prioritizing: CVE-2026-69730, a critical (CVSS 9.8) unauthenticated use-after-free RCE in Windows DNS Server — not exploited, but rated “Exploitation More Likely.”

“An attacker who can execute code in a low-privilege AppContainer could exploit this vulnerability locally to escape the sandbox and elevate privileges on the affected system. No additional user interaction is required.” — Microsoft Security Response Center, CVE-2026-85880

Source: MSRC CVE-2026-81963 · MSRC CVE-2026-85880 · MSRC CVE-2026-69730 · BleepingComputer

Adobe ships emergency fix for actively exploited Magento / Adobe Commerce “StyleSmuggler” RCE

Adobe PSIRT · September 7, 2026

Adobe published out-of-band bulletin APSB26-146 for CVE-2026-75650 (CVSS 3.1: 10.0, Critical), a template-injection flaw (CWE-1336) enabling unauthenticated arbitrary code execution in Adobe Commerce, Adobe Commerce B2B, and Magento Open Source — all supported branches through the 2026-aug releases (2.4.4 through 2.4.9). Sansec, which discovered the bug, reports in-the-wild attacks beginning September 4, three days before the patch. Adobe confirms exploitation; a Composer hotfix (VULN-39341) is available, and CISA added the CVE to KEV on September 8.

“Adobe is aware of CVE-2026-75650 being exploited in the wild.” — Adobe Security Bulletin APSB26-146

Source: Adobe APSB26-146 · Sansec research · BleepingComputer

N-able N-central pre-auth RCE (CVSS 10.0) lands in CISA KEV

N-able / CISA · September 8, 2026

CVE-2026-86218 (CVSS 4.0: 10.0, Critical; CWE-96 static code injection) allows pre-authenticated remote code execution on the N-central RMM server in all builds before 2026.3.1.14. N-able’s public release notes for Hotfix 4 (posted September 6) said it had no confirmed production exploitation, but CISA’s September 8 KEV addition is based on evidence of active exploitation, and Help Net Security reports a separate customer notice from N-able describing the flaw as exploited in the wild. Hosted (NCOD) instances are already patched; self-hosted deployments must upgrade to 2026.3 HF4. This follows the HF3 authentication-bypass fixes for CVE-2026-86206 and CVE-2026-86207 released days earlier.

“Customers running on-premises N-central deployments should upgrade to N-central 2026.3 HF4 immediately to protect their environment.” — N-able, N-central 2026.3 Hotfix 4 release notes

Source: N-able Hotfix 4 notes · CVE.org record · CISA KEV alert · Help Net Security

Chrome 153 fixes 230 flaws including a V8 zero-day exploited in the wild

Google Chrome · September 8, 2026

Chrome 153.0.8010.36/.37 (Windows/Mac) and 153.0.8010.36 (Linux) addresses 230 security bugs. CVE-2026-87491, an out-of-bounds write in the V8 JavaScript engine rated Medium, is confirmed exploited in the wild; it was reported by Jihyeon Jeong (Compsec Lab, Seoul National University) on August 6. The release also includes five Critical fixes, four of them memory-safety bugs in WebGL. This is the seventh Chrome zero-day patched in 2026. Not yet in CISA KEV as of this writing.

“Google is aware that an exploit for CVE-2026-87491 exists in the wild.” — Chrome Releases blog, Stable Channel Update for Desktop

Source: Chrome Releases · BleepingComputer

“ShieldCrash” PoC claims bypass of Microsoft’s Defender ShieldBreak patch — no fix available

BleepingComputer · September 9, 2026

Hours after Patch Tuesday, the anonymous researcher Nightmare Eclipse published a proof-of-concept called ShieldCrash, described as a bypass of Microsoft’s fix for CVE-2026-69414 (ShieldBreak, CVSS 7.8), a Microsoft Defender / Malware Protection Engine privilege-escalation flaw patched last week. The current PoC demonstrates arbitrary file read as SYSTEM on fully patched Windows 10, 11, and Server, without write access. No CVE has been assigned to the bypass, no patch exists, and it is not in KEV. Microsoft had not commented at publication time.

“While Microsoft fixed several things to prevent re-exploiting the issue, they missed a spot where ShieldBreak can still be exploited.” — Nightmare Eclipse, as quoted by BleepingComputer

Source: BleepingComputer · MSRC CVE-2026-69414

Calif demonstrates “WeWorm,” an AI-found zero-click WeChat worm spreading via voice calls

Calif Research · September 8, 2026

Security firm Calif disclosed WeWorm, a self-propagating exploit for a memory-corruption bug in WeChat’s VoIP stack on both iOS and Android. Simply placing a call — answered or not — is enough to take over the recipient’s WeChat account, which then calls its own contacts. The attacker must be on the victim’s friend list. Calif says AI found the bug and produced the first RCE exploit in about two days. Tencent shipped mitigations in WeChat Android 8.0.77 and iOS 8.0.76 on August 21 and blocked the exploit server-side by August 28; no CVE is listed and technical details are withheld pending a conference talk.

“The victim does not need to answer the call, or interact with their phone at all. Even if they do answer, they hear nothing, and the exploit still succeeds.” — Calif Research, WeWorm disclosure

Source: Calif Research · The Hacker News

Still developing

“MikroTrick”: CERT Polska confirms active exploitation of MikroTik RouterOS SSH auth-bypass chain

CERT Polska · September 5, 2026

CERT Polska disclosed six RouterOS vulnerabilities and confirmed attackers are chaining two of them to take full control of devices with SSH exposed to the internet. CVE-2026-67276 (CVSS 9.2) is an SSH authentication bypass — RouterOS compared only the RSA public modulus rather than the full key — and CVE-2026-86060 (CVSS 9.2) elevates a crafted-username SSH session to full admin. CVE-2026-67277 (CVSS 8.8) in the bandwidth-test service enables kernel memory disclosure or DoS. MikroTik patched in RouterOS 7.25beta3, 7.24.2, 7.23.4, and 6.49.21; patched builds flag known malicious config changes at boot. Indicators include an unexpected privileged user named “ops.” None of the CVEs are in CISA KEV yet.

“We have obtained confirmation that the attackers are exploiting this combination of vulnerabilities to take full control of devices whose SSH service is accessible from public networks.” — CERT Polska

Source: CERT Polska advisory · Help Net Security


This brief covers the trailing ~48 hours (September 7–9, 2026).

Primary sources:

Leave a Reply