The CyberSec Intelligence team (csint.ro) presents the daily cyber threat analysis for September 9, 2026. This bulletin covers vulnerabilities recently added to the CISA KEV catalog as being actively exploited in real-world attacks, critical security updates from NVD, and the most important news from the specialized press.
n
Actively exploited vulnerabilities
n
The following security breaches are being used in ongoing attacks and require the immediate application of security patches:
n
- n
- CVE-2026-75650 (Adobe Commerce and Magento): Improper neutralization of special elements in the template engine allows an attacker to execute arbitrary code. NVD Source.
- CVE-2026-81963 (Microsoft Windows): A link following vulnerability in the Windows Update Stack allows a local attacker to elevate their privileges to the SYSTEM level. NVD Source.
- CVE-2026-86218 (N-able N-central): Static code injection allowing remote code execution (RCE) before authentication. NVD Source.
- CVE-2026-85880 (Microsoft Windows): Heap-based buffer overflow in Advanced Local Procedure Call, allowing local privilege escalation. NVD Source.
- CVE-2026-85046 (Google Chromium V8): Type confusion vulnerability allowing a remote attacker to execute arbitrary code in the sandbox via a compromised HTML page. Affects Chromium-based browsers, including Google Chrome, Microsoft Edge, and Opera. NVD Source.
- CVE-2026-59822 (BerriAI LiteLLM): Improper authentication in the HTTP MCP Streamable endpoint, allowing an unauthenticated attacker to create a valid session using an arbitrary Bearer token. NVD Source.
- CVE-2026-48710 (Kludex Starlette): Request/response smuggling vulnerability allowing the injection of network paths in the host, facilitating authentication bypass; can be chained with CVE-2026-42271. NVD Source.
- CVE-2026-49869 (Kestra Kestra OSS): OS command injection allowing remote unauthenticated attackers to create and execute arbitrary workflows without credentials. NVD Source.
- CVE-2026-82329 (JFrog Artifactory): The default configuration exhibits a faulty authentication vulnerability, allowing unauthenticated network users to obtain administrative rights. NVD Source.
- CVE-2026-9586 (Sangoma Switchvox): SQL injection allowing an unauthenticated remote attacker to execute arbitrary SQL commands on the associated PostgreSQL database, also allowing remote code execution. NVD Source.
- CVE-2026-83548 (SonicWall SMA1000): Server-Side Request Forgery (SSRF) allowing remote unauthenticated attackers to obtain unauthorized access to sensitive system functions. NVD Source.
- CVE-2026-83549 (SonicWall SMA1000): Command injection in the operating system, allowing an administrator-authenticated user to execute remote code. NVD Source.
n
n
n
n
n
n
n
n
n
n
n
n
n
New critical vulnerabilities
n
The following breaches have been recently identified and classified with a critical severity level by NVD, presenting high risks for the affected infrastructures:
n
- n
- CVE-2026-79698 (Advantech WISE-6610 series): Command injection vulnerability in the Node-RED Library component (nodered_lib_apply function) via the “act” argument. Remote exploitation is possible, and the exploit is public. Updating to version 1.2.4_20260821 is recommended. NVD Source.
- CVE-2026-86299 (Linksys RE7000): OS command injection in the PingTest Handler component of json.cgi by manipulating ping test arguments. The attack can be launched remotely, and the exploit is public. NVD Source.
- CVE-2026-86543 (knowns): Versions prior to 0.30.0 expose the administration API without authentication on all network interfaces by default. Attackers can access an unauthenticated endpoint to publicly expose the API. NVD Source.
- CVE-2026-86509 (D-Link DIR-895L): Stack-based buffer overflow in the udhcpcd component allowing local network attacks. Public exploit available. NVD Source.
- CVE-2026-61516 (Netis NX10): Information disclosure in the firmware web administration interface (versions V4.0.1.5808 and V3.0.0.4142) allowing the retrieval of the administrator password without a valid session. NVD Source.
- CVE-2026-68839 (Windows USB Mass Storage): Heap-based buffer overflow in the Windows USB Mass Storage driver, allowing an unauthorized attacker to execute remote code over the network. NVD Source.
- CVE-2026-69356 (Microsoft Exchange Server): Improper neutralization of input during web page generation (Cross-Site Scripting – XSS) allowing remote attackers to perform spoofing activities. NVD Source.
- CVE-2026-69408 (Microsoft Windows Media Foundation): Integer overflow within the Media Foundation component, allowing network code execution by an unauthorized attacker. NVD Source.
- CVE-2026-69431 (Windows Telnet Client): Heap-based buffer overflow allowing remote code execution over the network by an unauthorized attacker. NVD Source.
- CVE-2026-69525 (Windows Remote Desktop Services): Use after free vulnerability that can allow an unauthorized attacker to execute remote code. NVD Source.
- CVE-2026-69579 (Windows Message Queuing): Use after free error usable by unauthorized attackers to run remote code over the network. NVD Source.
- CVE-2026-69586 (Microsoft Windows PDF): Integer overflow error in processing PDF files, facilitating remote code execution. NVD Source.
n
n
n
n
n
n
n
n
n
n
n
n
n
From the security press
n
Public exploit released for a Padding-Oracle vulnerability in Telerik UI
n
An analysis published by security firm TantoSec demonstrates how a padding oracle vulnerability (AES-CBC) in Telerik UI for ASP.NET AJAX can be chained to achieve remote code execution without authentication. The attack exclusively targets applications in a specific, non-default configuration. Although the exploit was made public, Progress released the corresponding patch in July, with no reports of active exploitation in the wild to date. Source The Hacker News.
n
N-able issues fourth hotfix in five weeks for the N-central platform
n
The manufacturer N-able has released a new emergency update (Hotfix 4) for its remote monitoring and management (RMM) platform N-central, amid the risk of an unauthenticated RCE vulnerability. All on-premises versions prior to 2026.3.1.14 are affected. Although suspicions of exploitation in the wild have not been officially confirmed in the release notes, applying the remedies is considered critical. Source The Hacker News.
n
What we recommend
n
To ensure the protection of the IT infrastructure against these threats, we recommend implementing the following measures:
n
- n
- Patch Management: Immediately apply updates for Microsoft Windows operating systems, Microsoft Exchange Server, and active network components. Prioritize patches for externally exposed web tools (Adobe Commerce, N-able N-central, SonicWall).
- Asset Inventory: Maintain an updated registry of all network equipment (including Advantech IoT devices and Linksys/D-Link routers) to ensure prompt identification of vulnerable products.
- Monitoring and limiting network access: Restrict access to the management interfaces of APIs and operating systems. Implement strict firewall rules and monitor connection logs to detect any unauthorized connections or tunneling-type attacks.
n
n
n
“}
Security News, in your inbox
New News articles, with their full text and a link to the website. One daily email at 09:00 Romania time. No new articles in your chosen language, no email.




