September 8, 2026 | Jonathan Brown
Command View
Reporting cutoff: September 8, 2026, 14:06 UTC
Priority posture: RED
RED: active exploitation or an immediate critical-system risk requiring same-shift action.
AMBER: a material exposure or incident with a credible path to impact; prioritize in the current operating cycle.
WATCH: incomplete, conflicting, or pre-exploitation evidence; monitor and pre-stage controls.
CONTEXT: background that changes interpretation but does not independently require a new action.
Three independently substantiated exploitation streams set the posture: MikroTik RouterOS devices with public SSH are being taken over through the MikroTrick chain; N-able reports exploitation of a new pre-authentication N-central flaw while Huntress confirms compromise of a fully patched environment but cannot identify the entry CVE; and Adobe confirms CVE-2026-75650 exploitation against Commerce and Magento stores. SAP, Commvault, Siemens and ScreenConnect require urgent owner-led action even though public evidence at the cutoff did not establish exploitation of their newly disclosed flaws.
Today’s decisions
- RED — Network engineering / edge security: identify every MikroTik device, remove SSH, WWW/WWW-SSL and bandwidth-test exposure from untrusted networks, and move immediately to RouterOS 7.24.2 Stable, 7.23.4 Long-term or 6.49.21 Long-term as applicable. Use 7.25beta3 only where the beta channel is already operationally accepted. Hunt for the
opsuser, the published log patterns, source IPs 82.192.72.4 and 103.102.31.18, unfamiliar users, scripts, scheduler tasks, proxies and tunnels. A cleanFlaggedresult does not clear the device. - RED — MSP / RMM platform owners: upgrade every on-premises N-central server to 2026.3 HF4, build 2026.3.1.14; HF3 build 2026.3.1.13 is insufficient. Confirm hosted NCOD tenancy is vendor-patched, restrict console/API reachability to trusted administration paths, and audit accounts, roles, API requests, automation jobs and downstream remote-control activity. Treat unexplained
.invalidor lookalike accounts as an incident lead. - RED — E-commerce / incident response: apply Adobe hotfix VULN-39341 for CVE-2026-75650 now, verify its installed state, and run compromise assessment before returning the store to normal risk. Patching is not eradication. Where exposure existed since September 4, rotate the Commerce encryption key and every protected secret at its source, including administration, integration, payment, database, SSH/deployment and extension credentials.
- AMBER — SAP Basis / business application security: apply SAP Security Notes 3747649 and 3759472 as emergency changes. Inventory by kernel release and patch level rather than application label. Prioritize Internet-facing web tiers, then every system reachable through SAP GUI, RFC or the Message Server public port. For S4GET, the fixed floors are 9.16 PL 100, 9.18 PL 32, 9.19 PL 17 and 9.20 PL 7.
- AMBER — Remote-support owners: until ConnectWise publishes and deploys its promised ScreenConnect fix, disable
TransferFilesor legacyTransferFilesInSessionfor every applicable role and session group. HuntRunFilesandRanFilesaudit events for scripts launched fromProcess: Guest; reimage confirmed affected hosts from known-good media. - AMBER — Backup, recovery and OT owners: move supported Commvault estates to 11.46.20+, 11.44.20+, 11.40.72+ or 11.36.123+ and verify all relevant roles, not only Command Center. For Siemens Reyrolle 7SR5, plan a safety-controlled update to 2.70+ with protection redundancy and rollback readiness.
- AMBER — Healthcare resilience / procurement: Boston Scientific says product function is not impaired and cardiac-device communicator and ICM remote-monitoring activations are restored, but distribution and manufacturing recovery remains incomplete. Maintain backlog visibility, clinical prioritization, alternate-product mapping and emergency escalation for time-critical procedures.
Threat and Resilience Ledger
RED — MikroTrick is taking over Internet-reachable MikroTik routers
CERT Polska confirmed that attackers are chaining CVE-2026-67276, an SSH authentication bypass, with CVE-2026-86060, SSH-session privilege manipulation through a crafted username, to obtain full RouterOS administrative control. Confirmed successful activity began no later than September 2 from 82.192.72.4; 103.102.31.18 was used for attempts. Observed artifacts include a highly privileged ops account and SSH log entries showing a login failure for user -2 followed by user creation by ssh:-2. The fixes are RouterOS 7.24.2 Stable, 7.23.4 Long-term, 6.49.21 Long-term and 7.25beta3. CERT Polska confirmed that patched builds stop the observed attack.
The six-flaw disclosure also includes an unauthenticated bandwidth-test memory leak/reboot condition, TLS server impersonation, unauthenticated SSH-managed file creation or overwrite, and an unauthenticated WebFig file read that can expose root-owned configuration stores. Remove all management exposure, patch, and examine configuration as well as logs. If any indicator or unexplained change exists, isolate the router, preserve logs and configuration, factory-reset it, rebuild from a trusted configuration and rotate secrets. Do not blindly restore a full backup from a suspect device.
Evidence: Confirmed active exploitation of the CVE-2026-67276/CVE-2026-86060 chain; vendor fixes and observed attack prevention confirmed.
Attribution: Unknown. Published infrastructure identifies activity, not an actor.
Confidence: High.
Uncertainty: Public reporting does not establish victim count, objective, persistence beyond observed configuration changes or whether additional undisclosed flaws are in use. The Flagged mechanism detects only selected traces.
Sources: CERT Polska, “Critical vulnerabilities in MikroTik RouterOS are being actively exploited. Immediate update recommended,” September 5, 2026; CERT Polska, “Vulnerabilities in Mikrotik RouterOS software,” September 5, 2026; MikroTik, “September 2026 vulnerability,” September 3, 2026.
RED — N-central management-plane compromise is confirmed; the exploited CVE remains disputed
N-able’s September 6 security update says a third independent researcher disclosed CVE-2026-86218, an unrelated critical zero-day that had been exploited in the wild. Its HF4 release notes describe pre-authentication remote code execution and require 2026.3 HF4, build 2026.3.1.14, for on-premises deployments; NCOD instances were patched by N-able and no agent update is required for the server-side fix. Those same release notes say N-able had no confirmation that CVE-2026-86218 had been exploited in production. That contradiction is material and remains unresolved.
Separately, Huntress investigated the September 4 compromise of one N-central production environment running then-current build 2026.3.1.10 and reproduced an exploit chain involving CVE-2026-86206 and CVE-2026-86207. Appliance log rotation prevented Huntress from determining whether that chain, CVE-2026-86218 or another path produced the original compromise. The operational conclusion is firmer than the CVE attribution: a compromised RMM server can create administrators, manipulate APIs and push scripts or remote sessions to every managed customer endpoint. Apply HF4, restrict access and reconstruct both appliance and downstream endpoint activity.
Evidence: Vendor assertion of exploitation; independent confirmation of one compromised, then-current N-central environment and reproduction of a new access-control/authentication chain.
Attribution: Unknown.
Confidence: High that N-central exploitation and compromise occurred; moderate on which newly disclosed CVE was used in the September 4 intrusion.
Uncertainty: N-able’s blog and release notes conflict on production exploitation of CVE-2026-86218; the number of affected organizations and the precise initial access path are not public.
Sources: N-able, “N-central Security Update — Take Action to Apply 2026.3 HF4,” updated September 6, 2026; N-able, “2026.3 HF4 Release Notes,” last updated September 5, 2026; N-able Status, “N-central 2026.3 Hotfix 4 — CVE-2026-86218,” September 6, 2026; Huntress, “Critical N-able N-central Vulnerability and Active Exploitation,” updated September 6, 2026.
RED — StyleSmuggler exploits Adobe Commerce and Magento before authentication
Adobe confirms active exploitation of CVE-2026-75650, a CVSS 10.0 template-engine injection flaw allowing unauthenticated arbitrary code execution. Sansec observed attacks beginning September 4 and described a two-stage chain that first poisons template styles data and then causes server-side execution during failed-payment email rendering; the email recipient does not need to interact. Adobe published Priority 1 bulletin APSB26-146 and hotfix VULN-39341 on September 7.
Observed payloads include Rust backdoors using process names such as [kworker/u:8:0], fc-cache and chronyd, with 99.84.67.186 among published command-and-control infrastructure. Sansec also observed rapid payload iteration and a later PHP-shell pattern under pub/media/catalog/product/cache/. Its reporting had not established that the first backdoor was subsequently weaponized, so presence proves compromise but not every possible follow-on action. Apply and verify the hotfix, hunt from September 4 forward, and rotate secrets because the patch does not remove implants or invalidate credentials already read.
Evidence: Adobe confirms exploitation in the wild; Sansec reproduced the chain and documented victims, payloads, indicators and the emergency hotfix.
Attribution: Unknown; at least two operational patterns were reported, but no reliable actor identity is public.
Confidence: High.
Uncertainty: Victim population, full post-compromise activity and the relationship between the observed operators remain unknown. Hotfix testing is strongest on the August 2026 release builds identified by Adobe/Sansec.
Sources: Adobe, “Security update available for Adobe Commerce | APSB26-146,” September 7, 2026; Adobe Experience League, “Security hotfix available for Adobe Commerce — APSB26-146,” September 7, 2026; Sansec, “StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack,” published September 5 and updated September 7, 2026.
AMBER — SAP patches two pre-authentication paths to system-level control
SAP’s September bulletin contains 19 new security notes and one update. The lead issue, OVERPASS (CVE-2026-44756, CVSS 10.0, Note 3747649), is memory corruption in shared Extended Passport processing. Onapsis confirmed that an unauthenticated crafted request can reach the flaw through HTTP(S) via ICM/Web Dispatcher, SAP GUI via the Dispatcher and RFC, enabling operating-system command execution as the SAP system account. Network restriction of one protocol reduces exposure but does not close every route; the applicable kernel patch under Note 3747649 is definitive.
S4GET (CVE-2026-58240, CVSS 9.8, Note 3759472) is a missing-authentication condition in the NetWeaver Message Server. An unauthenticated party with network access to the public Message Server port can cause an attacker address to be treated as trusted and then use legitimate Gateway/RFC functionality toward code execution as <sid>adm. Kernels 9.16 below PL 100, 9.18 below PL 32, 9.19 below PL 17 and 9.20 below PL 7 are vulnerable. Onapsis had not observed exploitation of either issue at publication, but the combination of pre-authentication reachability, core-business-system privilege and historically rapid SAP patch reverse engineering warrants emergency treatment.
Evidence: Confirmed vendor advisories and coordinated-disclosure research; fixes available. No confirmed exploitation at the cutoff.
Attribution: Not applicable; no malicious campaign has been established.
Confidence: High on vulnerability, impact and remediation; moderate on near-term exploitation likelihood.
Uncertainty: Exact fixed patch levels for each OVERPASS component are in authenticated SAP Note 3747649 rather than the public bulletin. Public indicators of compromise were not available at the cutoff.
Sources: SAP, “SAP Security Patch Day — September 2026,” September 8, 2026; Onapsis, “SAP Security Notes: September 2026 Patch Day,” September 8, 2026; Onapsis, “Mitigating OVERPASS (CVE-2026-44756),” September 8, 2026; Onapsis, “S4GET (CVE-2026-58240),” September 8, 2026.
AMBER — Modified ScreenConnect clients support worm-like lateral propagation
Huntress documented late-August incidents across unrelated organizations in which social engineering led victims to install rogue ScreenConnect clients. Modified clients automatically transferred and executed 1.vbs through 4.vbs on newly connected hosts, creating worm-like propagation. Common artifacts include repeated wscript.exe, a WindowsServiceHost user Run key pointing to WindowsServiceHost.vbs in the user’s AppData directory, and sometimes UltraViewer. The initial access in the known cases was social engineering; there is no evidence in these sources of a ConnectWise cloud compromise.
ConnectWise acknowledged an issue in guest file-transfer behavior affecting Remote Access Support and Access sessions in both cloud and on-premises deployments. As of the cutoff, its September 3 advisory still said the CVE and official fix would be issued within the week. Disable TransferFiles or TransferFilesInSession in every applicable role/session group now. Treat RunFiles or RanFiles entries for script execution from Process: Guest as high-priority evidence and reimage confirmed affected hosts.
Evidence: Multiple Huntress incident-response observations plus a vendor advisory and interim mitigation.
Attribution: Unknown; activity is consistent with financially motivated social-engineering/RMM abuse, but no actor is confirmed.
Confidence: High on the observed campaign and mitigation; moderate on the underlying product issue.
Uncertainty: No CVE, root-cause detail, affected-version boundary or fixed release was public at the cutoff. Total campaign scope is unknown.
Sources: Huntress, “Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity,” updated September 3, 2026; ConnectWise, “ScreenConnect Remote Access: Guest File Transfer Advisory,” September 3, 2026.
AMBER — Twelve Commvault advisories concentrate risk in the recovery plane
Commvault issued 12 advisories on September 8: 11 CVEs and one issue without a CVE. The set includes CVE-2026-77089, a Command Center API authentication bypass affecting privilege management (CVSS 9.3); DataCube and Content Extractor bypass/disclosure paths; Private Metrics denial-of-service and SQL injection; multiple CommServe memory, disclosure, traversal and privilege issues; and CVE-2026-77106, missing authorization in Cvlaunchd affecting command execution (CVSS 7.7). Commvault does not claim in-the-wild exploitation in the public advisories.
The published resolved floors are 11.46.20+, 11.44.20+, 11.40.72+ and 11.36.123+. Unsupported versions must be upgraded. The Cvlaunchd advisory explicitly directs customers to update all installations, including CommServe, Web Server, Command Center, Media Agents, clients and HyperScale X. Because the platform controls backups and recovery, prioritize management-plane exposure and confirm each role’s maintenance release rather than treating a patched console as estate-wide completion.
Evidence: Vendor-issued advisories, CVEs, CVSS scores and resolved maintenance releases.
Attribution: Not applicable; no exploitation is claimed.
Confidence: High on affected and resolved versions; moderate on practical exploitability because several public advisories provide limited prerequisite detail.
Uncertainty: Public pages do not describe exploitation status for each flaw beyond the absence of a claim, and do not fully document attack prerequisites or chaining potential.
Sources: Commvault, “Commvault Cloud Security Advisories” and advisories CV_2026_07_1, CV_2026_07_3, CV_2026_07_6, CV_2026_07_7 and CV_2026_08_1 through CV_2026_08_8, issued September 8, 2026.
AMBER — Siemens Reyrolle 7SR5 flaws affect substation protection and control
Siemens ProductCERT disclosed a group of vulnerabilities in Reyrolle 7SR5 devices used for protection, control, measurement and automation in electrical substations. All versions below 2.70 are affected; 2.70 or later is the remediation. The highest-risk issues allow unauthenticated session prediction or impersonation (including CVE-2026-62645, CVSS 9.8 under CVSS v3.1), while other flaws can reboot devices remotely, bypass role controls or—with physical access and special modes—enable unsigned-code or memory-corruption paths.
No exploitation is claimed in the advisory. The impact context nevertheless requires coordinated engineering: identify every relay and management path, restrict access, preserve redundant protection, schedule a controlled 2.70+ rollout, validate settings and protection logic after update, and keep recovery configurations offline and verified.
Evidence: Siemens ProductCERT advisory with CVEs, affected-version boundary and fixed version.
Attribution: Not applicable.
Confidence: High.
Uncertainty: Public evidence does not establish exploitation, exposed population or field reliability implications for every hardware/application combination. Physical-access CVEs do not share the remote risk of the session and HTTP issues.
Sources: Siemens ProductCERT, “Multiple Vulnerabilities in Reyrolle 7SR5 Devices,” SSA-142885, September 8, 2026.
AMBER — Boston Scientific restores key services while healthcare backlogs persist
Boston Scientific’s September 8 update says product-quality analysis indicates no impairment to product function and that remote-monitoring activation capability is restored for cardiac-device implant communicators and insertable cardiac monitors. Its September 5 update said no related unauthorized activity had been seen since August 25, the impact was isolated to selected internal infrastructure, major distribution centers were processing and shipping at or above normal levels, all sterilization facilities were operational, and manufacturing had resumed at most facilities. Backlogs and remaining manufacturing recovery work continue.
NHS Supply Chain reporting shows why operational vigilance remains necessary: UK orders had queued during the disruption, alternative-product information and clinical prioritization were being developed, and customers with an emergency product need for a procedure within 48 hours were given an escalation path. Keep local stock, delayed orders and clinical substitutions visible until normal fulfillment is independently sustained.
Evidence: Company operational updates, SEC disclosure and NHS Supply Chain continuity guidance.
Attribution: Unknown. The company has not publicly named an actor or initial-access method.
Confidence: High on reported service restoration and backlog conditions; moderate on incident scope pending investigation completion.
Uncertainty: Data-access scope, root cause, full restoration date and residual regional product availability are not public. Product function is reported unimpaired; that statement does not eliminate supply disruption.
Sources: Boston Scientific, “Update on recent cybersecurity incident,” updated September 8, 2026; Boston Scientific, Form 8-K dated September 7, 2026; NHS Supply Chain, “Supplier Update Boston Scientific Cyber Attack,” updated September 7, 2026; Reuters, “Boston Scientific says cyberattack likely to hurt 2026 sales, profit,” September 8, 2026.
WATCH — DPRK-linked Linux implants hide inside HAProxy and core daemons
Rapid7 analyzed a previously undocumented Linux espionage toolkit on two South Korean victims in the media and automotive sectors. The ted backdoor was compiled into HAProxy 2.8.12 and operated alongside trojanized crond, agetty, atd, sshd and polkitd, an SSH keylogger, a stager and curlRAT. Capabilities include remote command execution, selective web-script injection and redirects, session-cookie or credential theft, and traffic/statistics manipulation intended to hide activity while load balancing continues.
Rapid7 attributes the toolkit to DPRK-aligned actors with medium confidence, citing targeting and overlaps with APT37-associated infrastructure and tradecraft. It explicitly does not know the initial-access path or associated CVE, and evidence is insufficient to establish a precise timeline; activity likely dates to early 2025. Operators of exposed Linux proxies and groupware gateways should attest binaries against trusted packages/build provenance, compare service binaries and package metadata, and not rely on configuration or application logs alone.
Evidence: Detailed malware analysis from two victims and published indicators.
Attribution: DPRK-aligned actor, medium confidence; exact cluster unconfirmed.
Confidence: High on the artifacts and capabilities; moderate on attribution; low on initial access.
Uncertainty: Victim count, delivery mechanism, CVE, campaign timeline and whether APT37, Kimsuky, Lazarus or another DPRK cluster operated the toolkit remain unresolved.
Sources: Rapid7 Labs, “DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors,” September 7, 2026.
Defensive Posture Changes
- Treat edge and management appliances as rebuildable systems. External logging, signed configuration baselines and tested clean-rebuild procedures are required for routers, RMM servers, commerce platforms and recovery controllers. Local logs may rotate or be altered before attribution is possible.
- Remove direct administration exposure. Put RouterOS, N-central, ScreenConnect, Commvault and OT administration behind dedicated management networks, VPNs or allowlisted jump paths. This reduces exposure but does not replace a vendor fix.
- After patching, verify control-plane integrity. Audit users, roles, scheduled jobs, API activity, remote sessions, scripts, tunnels and configuration deltas. Patch compliance is not compromise clearance for MikroTik, N-central or Adobe Commerce.
- Separate credential rotation from encryption-key rotation. For Adobe Commerce, rotate each protected credential at the system that accepts it. Changing only the Commerce encryption key does not revoke a secret already copied.
- Patch OT under safety governance. Reyrolle and other substation updates require redundant protection, approved outage windows, configuration validation and rehearsed rollback—not an unsupervised fleet push.
- Attest binaries on high-trust Linux gateways. The HAProxy case shows that a service can operate normally while its binary is the implant. Validate hashes, package signatures and build provenance for proxies and core daemons.
- Test recovery-plane independence. Commvault’s advisory cluster reinforces the need for segmented administration, immutable/offline recovery copies, separate privileged identities and restoration tests that do not depend on one management server.
Regional and Sector Pulse
- Global Internet edge — RED: MikroTik exploitation is confirmed against devices exposing SSH publicly. The observed IPs are hunting pivots, not durable blocks or attribution.
- MSP and outsourced IT — RED: N-central and ScreenConnect demonstrate two different management-plane risks: vulnerability exploitation against the server and social-engineering delivery of modified clients. Both can amplify one foothold across many endpoints.
- Retail and digital commerce — RED: StyleSmuggler moved from exploitation to an Adobe emergency hotfix after a three-day pre-patch window. Payment and integration secrets expand the consequence beyond the web server.
- Enterprise ERP and industrial operations — AMBER: OVERPASS and S4GET place SAP kernel and Message Server patching ahead of routine monthly cadence. Commvault flaws affect recovery assurance, while Siemens 7SR5 and related advisories require operationally controlled remediation.
- Healthcare supply chain — AMBER: Boston Scientific reports meaningful recovery and restored monitoring activations, but order backlogs and substitution planning remain operational concerns for providers.
- South Korea / media and automotive — WATCH: Rapid7’s DPRK-linked toolkit targets Linux gateways and embeds into trusted service binaries, supporting long-duration espionage rather than visible disruption.
Vulnerability and Supplier Watchlist
- MikroTik RouterOS: CVE-2026-67276 affects RouterOS 7.9 to below 7.23.4 and 7.24 to below 7.24.2. CVE-2026-67277, CVE-2026-67279 and CVE-2026-86060 affect 6.0.0 to below 6.49.21, 7.0.0 to below 7.23.4, and 7.24 to below 7.24.2. CVE-2026-67278 affects 7.0.0 to below 7.23.4 and 7.24 to below 7.24.2. CVE-2026-67281 affects 7.20 to below 7.23.4 and 7.24 to below 7.24.2. Fixed production releases are 6.49.21 Long-term, 7.23.4 Long-term and 7.24.2 Stable; 7.25beta3 contains the beta-channel fix.
- N-able N-central: CVE-2026-86218 is pre-authentication RCE rated CVSS 10.0 and affects versions before 2026.3 HF4, build 2026.3.1.14. HF4 supersedes HF3 build 2026.3.1.13, which addressed CVE-2026-86206 and CVE-2026-86207 but does not address CVE-2026-86218. Follow the vendor’s supported upgrade path for legacy builds.
- Adobe Commerce / Magento: CVE-2026-75650 is unauthenticated arbitrary code execution, CVSS 10.0. APSB26-146 lists Adobe Commerce branches 2.4.4 through 2.4.9, Magento Open Source branches 2.4.6 through 2.4.9, and Adobe Commerce B2B branches 1.3.3 through 1.5.3 at each specified
2026-aug and earlierlevel. The remedy is hotfix VULN-39341, not a newly numbered product release. Adobe/Sansec report hotfix testing on August 2026 releases across Commerce and Magento 2.4.4–2.4.9 and B2B 1.3.3–1.5.3; coordinate vendor support for older branch builds where validation is unclear. - SAP: OVERPASS CVE-2026-44756 affects KRNL64NUC 7.22 and 7.22EXT; KRNL64UC 7.22, 7.22EXT, 7.53 and 8.04; WEBDISP 9.16, 9.18, 9.19 and 9.20; and KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19 and 9.20. Apply the exact fixed patch level in authenticated Note 3747649. S4GET CVE-2026-58240 affects KERNEL 9.16/9.18/9.19/9.20 below PL 100/32/17/7 respectively. Also prioritize CVE-2026-76969 in
@sap/cds-mtxsversions at or below 1.18.3, 2.7.6, 3.9.6 and 4.0.2, and CVE-2026-66768 in SAP GUI for Java BC-FES-JAV 8.10. - Commvault: September 8 advisories cover CVE-2026-77089, CVE-2026-77091, CVE-2026-77092, a Content Extractor disclosure issue without a CVE, CVE-2026-77097, CVE-2026-77098 and CVE-2026-77101 through CVE-2026-77106. Affected/resolved boundaries are 11.46.0–11.46.19 / 11.46.20+, 11.44.0–11.44.19 / 11.44.20+, 11.40.0–11.40.71 / 11.40.72+, and 11.36.0–11.36.122 / 11.36.123+.
- Siemens Reyrolle 7SR5: all versions below 2.70 are affected by CVE-2026-62645 through CVE-2026-62650, CVE-2026-62653, CVE-2026-62654 and inherited Mongoose issues identified in SSA-142885. Update to 2.70+ with substation safety/change controls.
- Siemens Siveillance Control: CVE-2026-50093 is an adjacent-network, low-privilege arbitrary-file-upload path that can write as root; it is not an unauthenticated Internet vector. Fixed floors are Control 3.0.22.2177, Control 4.0.11.2177, Control Pro 3.0.12.2173 and Control Pro 4.0.9.2178.
- Siemens SIMOVE / SIPLANT: CVE-2026-67367 is an unauthenticated remote path traversal in the embedded HTTP server that can disclose operating-system files, credentials, private keys and configuration. Fixed floors are SIMOVE 3.1.13, 3.2.4, 3.3.2 and 4.0.1, and SIPLANT 3.1.4. SIPLANT 1.7, 2.2 and 3.0 remain affected; contact Siemens support.
- Siemens Desigo CC: CVE-2026-34223 can execute code when a local attacker supplies a malicious graphics document that a user opens. Installed and ClickOnce Desigo CC V6 and V7 have no fix listed; V8 and V9 are not affected. Desigo CC Flex V6 and V7 are not affected.
- ScreenConnect: no CVE, affected-version boundary or fixed release was public at the cutoff. Apply the vendor’s file-transfer-permission mitigation and monitor the advisory for the promised release.
No new item in this edition is assigned a CISA Known Exploited Vulnerabilities status without item-specific confirmation. The generic CISA and KEV landing pages are therefore not used as sources or forwarding targets.
Outlook and Uncertainty
The next 24 hours are likely to be defined by attacker adaptation and post-disclosure scanning. Monitor for broader MikroTik compromise, new StyleSmuggler payloads, N-able clarification of the CVE-2026-86218 exploitation contradiction, a ConnectWise CVE and fixed release, and exploit research against SAP, Commvault and Siemens updates. Microsoft’s September monthly security release had not appeared in the official Update Guide by the 14:06 UTC cutoff and requires a separate assessment after publication; no CVE count or severity total is inferred here.
The most consequential intelligence gaps are the entry vulnerability and victim population for the September N-central compromise; the number, objectives and persistence of MikroTik intrusions; the full StyleSmuggler victim set and follow-on use; whether SAP exploit development becomes public or operational; the ScreenConnect product root cause and version boundary; the Boston Scientific access/data scope and full recovery date; and the exact DPRK cluster and initial vector behind the Linux toolkit.
The posture should remain RED until the three active-exploitation populations are either proved absent or patched and assessed for compromise. AMBER systems should remain on emergency change governance, not routine monthly cadence.
Jonathan Brown writes independent, decision-focused analysis on cybersecurity, infrastructure resilience, and operational risk, with an emphasis on primary-source verification and explicit uncertainty.
Support this work by sharing the briefing with operators who can act on it. Corrections supported by primary evidence are welcomed; material errors should be amended transparently. Feel free to subscribe, comment, or buy us a coffee! Thanks.
© 2026 Border Cyber Group. All rights reserved.
Source Register — September 8, 2026
URLs are grouped by story and shown in full. This register deliberately omits generic CISA and KEV landing pages; no new KEV designation is asserted in the briefing without item-specific confirmation.
MikroTik RouterOS / MikroTrick
- CERT Polska — active exploitation warning: https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/
- CERT Polska — CVE and affected-version detail: https://cert.pl/en/posts/2026/09/mikrotik-routeros-cve/
- MikroTik — September 2026 security bulletin: https://mikrotik.com/supportsec/september-2026-vulnerability
- SecurityWeek — contemporaneous reporting: https://www.securityweek.com/mikrotik-patches-critical-flaws-chained-to-hack-routers/
N-able N-central
- N-able — HF4 action notice: https://www.n-able.com/blog/n-central-security-hotfix-september-5-2026
- N-able — 2026.3 HF4 release notes: https://documentation.n-able.com/N-central/Release_Notes/GA/Content/N-central_2026.3_HF4_Release_Notes.htm
- N-able Status — CVE-2026-86218 and upgrade guidance: https://status.n-able.com/2026/09/06/n-central-2026-3-hotfix-4-cve-2026-86218/
- Huntress — compromise, exploit-chain validation and vendor contradiction: https://www.huntress.com/blog/n-able-vulnerability-exploitation
- NIST NVD — CVE-2026-86218 record: https://nvd.nist.gov/vuln/detail/CVE-2026-86218
- SecurityWeek — contemporaneous reporting: https://www.securityweek.com/n-able-patches-critical-zero-day-in-n-central/
Adobe Commerce / Magento StyleSmuggler
- Adobe — APSB26-146: https://helpx.adobe.com/security/products/magento/apsb26-146.html
- Adobe Experience League — CVE-2026-75650 hotfix guidance: https://experienceleague.adobe.com/en/docs/commerce-operations/implementation-playbook/best-practices/maintenance/cve-2026-75650
- Sansec — StyleSmuggler investigation and indicators: https://sansec.io/research/stylesmuggler-0day
- SecurityWeek — contemporaneous reporting: https://www.securityweek.com/adobe-commerce-zero-day-exploited-to-backdoor-online-stores/
SAP September Patch Day
- SAP — September 2026 Security Patch Day bulletin: https://support.sap.com/en/my-support/knowledge-base/security-notes-news/september-2026.html
- Onapsis — September Patch Day analysis: https://onapsis.com/blog/sap-security-patch-day-september-2026/
- Onapsis — OVERPASS remediation: https://onapsis.com/blog/sap-overpass-remediation/
- Onapsis — S4GET advisory and exact fixed kernel patch levels: https://onapsis.com/blog/s4get-cve-2026-58240-sap-message-server-threat-advisory/
ScreenConnect guest file transfer / worm-like campaign
- ConnectWise — Trust Center advisory, September 3 entry: https://www.connectwise.com/company/trust/advisories
- Huntress — rogue ScreenConnect installations and indicators: https://www.huntress.com/blog/rogue-screenconnect-installations
- SecurityWeek — contemporaneous reporting: https://www.securityweek.com/modified-screenconnect-clients-used-in-worm-like-campaign/
Commvault September 8 advisories
- Commvault — advisory index: https://documentation.commvault.com/securityadvisories/
- Command Center API authentication bypass, CVE-2026-77089: https://documentation.commvault.com/securityadvisories/CV_2026_07_1.html
- DataCube security feature bypass, CVE-2026-77091: https://documentation.commvault.com/securityadvisories/CV_2026_07_3.html
- Content Extractor privilege escalation, CVE-2026-77092: https://documentation.commvault.com/securityadvisories/CV_2026_07_6.html
- Content Extractor information disclosure, no CVE: https://documentation.commvault.com/securityadvisories/CV_2026_07_7.html
- Private Metrics denial of service, CVE-2026-77097: https://documentation.commvault.com/securityadvisories/CV_2026_08_1.html
- Private Metrics SQL injection, CVE-2026-77098: https://documentation.commvault.com/securityadvisories/CV_2026_08_2.html
- CommServe stack-based buffer overflow, CVE-2026-77101: https://documentation.commvault.com/securityadvisories/CV_2026_08_3.html
- CommServe denial of service, CVE-2026-77102: https://documentation.commvault.com/securityadvisories/CV_2026_08_4.html
- CommServe information disclosure, CVE-2026-77103: https://documentation.commvault.com/securityadvisories/CV_2026_08_5.html
- CommServe path traversal, CVE-2026-77104: https://documentation.commvault.com/securityadvisories/CV_2026_08_6.html
- CommServe privilege escalation, CVE-2026-77105: https://documentation.commvault.com/securityadvisories/CV_2026_08_7.html
- Cvlaunchd code execution, CVE-2026-77106: https://documentation.commvault.com/securityadvisories/CV_2026_08_8.html
Siemens ProductCERT / OT and physical-security products
- Reyrolle 7SR5, SSA-142885: https://cert-portal.siemens.com/productcert/html/ssa-142885.html
- Siveillance Control, SSA-254516: https://cert-portal.siemens.com/productcert/html/ssa-254516.html
- SIMOVE and SIPLANT fleet management, SSA-517424: https://cert-portal.siemens.com/productcert/html/ssa-517424.html
- Desigo CC, SSA-330084: https://cert-portal.siemens.com/productcert/html/ssa-330084.html
Boston Scientific incident and healthcare supply continuity
- Boston Scientific — incident and recovery updates: https://news.bostonscientific.com/update-on-recent-cybersecurity-incident
- Boston Scientific — September 7 Form 8-K: https://www.sec.gov/Archives/edgar/data/885725/000088572526000059/bsx-20260907.htm
- NHS Supply Chain — supplier and clinical-continuity updates: https://www.supplychain.nhs.uk/icn/supplier-update-boston-scientific-cyber-attack/
- Reuters — September 8 operational and financial impact reporting: https://www.reuters.com/technology/boston-scientific-says-cyberattack-likely-hurt-2026-sales-profit-2026-09-08/
DPRK-linked Linux / HAProxy toolkit
- Rapid7 Labs — primary technical research, attribution and indicators: https://www.rapid7.com/blog/post/tr-dprk-apts-ted-backdoor-curlrat-target-south-korean-media-automotive-sectors/
- SecurityWeek — contemporaneous reporting: https://www.securityweek.com/north-korean-hackers-deploy-new-linux-espionage-toolkit/
Cutoff-specific Microsoft release check
- Microsoft Security Response Center — Security Update Guide: https://msrc.microsoft.com/update-guide/
Member discussion: