Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7

ConnectWise warns of an unpatched ScreenConnect flaw and urges interim mitigation

ConnectWise warned of a new vulnerability in ScreenConnect, its widely used remote-access platform, affecting both cloud and on-premises deployments, and issued temporary mitigations while it prepares a patch. The flaw involves file-transfer behavior in remote-access sessions and has not yet received a CVE identifier. As an interim measure, administrators are told to disable file-transfer permissions in the ScreenConnect console. ScreenConnect is a favorite tool of managed-service providers and IT teams, which also makes it a repeated target: three earlier ScreenConnect flaws are in the exploited-vulnerabilities catalog, two abused in ransomware, and nearly 6,000 instances are exposed online. There is a concurrent campaign spreading malware through rogue ScreenConnect clients.

Check
Apply ConnectWise's interim mitigation now by disabling file-transfer permissions in the ScreenConnect console, restrict access to the platform, and apply the official patch as soon as it ships this week.
Affected
Organizations and managed-service providers running ScreenConnect, cloud and on-premises; the unpatched file-transfer flaw could be abused for attacks, on a platform that grants powerful remote access and is frequently targeted by ransomware.
Fix
Disable file-transfer permissions until patched, limit and monitor who can reach the ScreenConnect console, watch for unauthorized clients and sessions, patch promptly on release, and treat this remote-access tooling as high-value infrastructure.

Public exploit chains a Telerik padding-oracle flaw into unauthenticated code execution

Tanto Security released a working exploit for flaws in Telerik UI for ASP.NET AJAX, a widely used web component set, that chains into unauthenticated remote code execution. The core issue is an AES-CBC padding oracle in the file-upload component: because the encryption does not authenticate the ciphertext, an attacker can tweak encrypted input and read the server's error responses to decrypt protected configuration one byte at a time without the key. That unlocks a .NET deserialization flaw that loads an attacker-supplied assembly and drops a web shell. Progress patched the flaws in July, but the published tool now puts a full attack path in public hands, though only non-default configurations are affected.

Check
Update Telerik UI for ASP.NET AJAX to the patched release, and review applications for the non-default upload configuration this attack requires, prioritizing internet-facing sites now that a working exploit is public.
Affected
Web applications using vulnerable Telerik UI for ASP.NET AJAX in a specific non-default upload configuration (CVE-2026-13181 and related); an unauthenticated attacker can chain the padding oracle and deserialization into remote code execution.
Fix
Patch to the fixed Telerik version, avoid the vulnerable upload configuration, add web application firewall rules for the exploit's request patterns, monitor for web shells and unexpected assembly loads, and rotate keys.

Unpatched Magento zero-day is being exploited to backdoor online stores

Attackers are actively exploiting an unpatched zero-day in Magento Open Source and Adobe Commerce to run code on stores' servers without logging in, according to e-commerce security firm Sansec, which named it StyleSmuggler. Exploitation began September 4, and every current version is affected, including the latest 2.4.9; Sansec even found a fully patched store already compromised. The attack manipulates a styles field in a GraphQL request to inject PHP into a file the platform generates normally, then installs a persistent backdoor. As of disclosure, Adobe had not issued an advisory, a CVE, or a fix, so exposed stores should be treated as at risk and watched for compromise.

Check
Since there is no patch, review logs for suspicious unauthenticated requests to Magento since September 4, especially style or template processing, and hunt for web shells and new admin accounts.
Affected
Any store on Magento Open Source or Adobe Commerce, including fully patched and latest 2.4.9 installs; an unauthenticated attacker can execute code and install a persistent backdoor, and exploitation is happening now.
Fix
Apply web application firewall rules against anomalous style and template requests, restrict and monitor admin and API endpoints, watch for skimmer injections and backdoors, and apply the vendor fix when it ships.

N-able ships fourth N-central hotfix in five weeks for exploited pre-auth flaw

N-able released its fourth hotfix in five weeks for its N-central remote monitoring and management platform, this time for a flaw that gives an unauthenticated attacker full "god-mode" access to the console. Tracked as CVE-2026-86218 and scored 10.0, the pre-authentication remote code execution zero-day is being exploited and supersedes all earlier hotfixes, so on-premises systems still on the third hotfix remain vulnerable and must apply the fourth. Hosted instances have already been patched. Researchers also disclosed a separate chain that lets attackers bypass access controls to create unauthorized administrator accounts. Because N-central manages many downstream endpoints, a compromise can cascade across every customer it serves.

Check
Apply N-central hotfix 4 immediately on any on-premises server, since prior hotfixes do not cover this flaw, then audit the console's user list for unauthorized administrator accounts.
Affected
Organizations and managed-service providers running on-premises N-able N-central (CVE-2026-86218); an unauthenticated attacker can execute code and gain full control of the console, and from there potentially reach every managed endpoint.
Fix
Patch to the latest hotfix, strictly limit inbound access to the N-central console, audit for rogue admin accounts and recent changes, monitor managed endpoints, and treat any exposed unpatched server as compromised.

Exploited MikroTik flaw chain gives full router control over exposed SSH

Poland's CERT warned that attackers are exploiting a chain of MikroTik RouterOS flaws, dubbed MikroTrick, to take full administrative control of internet-exposed routers over SSH without valid credentials. The key flaw, CVE-2026-67276 and scored 9.2, is an authentication bypass in how RouterOS checks RSA public keys: an attacker who knows a valid username and the public key can forge a key and log in without the private one. A second flaw then escalates the session to full administrator. MikroTik shipped fixes on September 3, but exploitation began around September 2, and roughly 300,000 devices remain exposed. Compromised edge routers make ideal footholds, so exposed devices should be treated as breached.

Check
Update RouterOS to a fixed release now, take SSH off the internet by restricting it to a management network or VPN, and hunt exposed devices for a rogue user named dash-two.
Affected
Internet-exposed MikroTik RouterOS devices with SSH enabled (CVE-2026-67276); an unauthenticated attacker can bypass SSH authentication and escalate to full administrator, and about 300,000 devices are still exposed and being targeted.
Fix
Patch RouterOS, keep SSH and management interfaces off the public internet, rotate all router and downstream credentials and SSH keys, disable unused services, and rebuild any device confirmed compromised.

Critical Cisco Nexus switch flaw lets unauthenticated attackers run code as root

Cisco patched a critical flaw in its Nexus 9000 data-center switches that lets an unauthenticated, remote attacker execute code as root. Tracked as CVE-2026-20212 and scored 9.8, the bug affects Nexus 9000 models built on Cisco's Silicon One chips and stems from a service that binds to an unrestricted address, leaving TCP ports 43210 and 43211 reachable in the default routing configuration. An attacker who can reach either port sends crafted input that runs with root privileges, and can also crash and reload the device. Cisco reported no known exploitation at disclosure and shipped fixed software, with an access-list workaround for those who cannot patch immediately.

Check
Identify Nexus 9000 switches using Silicon One chips, upgrade to fixed NX-OS releases, and until then apply the access-control-list workaround that blocks TCP ports 43210 and 43211 to the device.
Affected
Organizations running affected Cisco Nexus 9000 switches with Silicon One chips (CVE-2026-20212); a remote, unauthenticated attacker reaching the exposed ports can execute code as root or crash the device, no credentials needed.
Fix
Patch to fixed NX-OS software, apply the access-list workaround and temporary shield until then, restrict management-plane reachability to the switches, and monitor for unexpected connections to the affected ports.

Attackers chain two SonicWall VPN zero-days for unauthenticated remote code execution

SonicWall warned that attackers are actively exploiting two zero-day flaws in its SMA 1000 series remote-access VPN appliances, which can be chained for unauthenticated remote code execution. The first, CVE-2026-83548, scored 10.0, is a pre-authentication server-side request forgery flaw in the user-facing portal that lets an unauthenticated attacker abuse the appliance as a proxy and reach sensitive functions. The second, CVE-2026-83549, is a command-injection flaw in the admin console. SonicWall confirmed active exploitation and shipped hotfixes with no workarounds. Because these gateways aggregate remote users' credentials and tie into directory services, compromising one means compromising the authentication system itself. It is the third SMA 1000 zero-day campaign in under a year.

Check
Apply the SonicWall SMA 1000 hotfixes immediately since there are no workarounds and exploitation is active, then hunt the appliance for compromise, including rogue sessions, credential theft, and unexpected outbound requests.
Affected
Organizations running SonicWall SMA 1000 models 6210, 7210, or 8200v on affected versions (CVE-2026-83548, CVE-2026-83549); the flaws chain to unauthenticated remote code execution on an appliance that holds credentials and session state.
Fix
Patch to the fixed hotfix releases now, treat any exposed unpatched appliance as compromised, rotate credentials and session secrets it handled, review logs for exploitation, and limit portal exposure to the internet.

Exploited Sangoma Switchvox flaw gives unauthenticated attackers reverse shells

Attackers are exploiting a critical flaw in Sangoma Switchvox, a widely used enterprise VoIP phone-system platform, to run code on servers without any credentials. Tracked as CVE-2026-9586 and scored 9.3, it is an unauthenticated SQL injection in an internet-facing endpoint that concatenates user-controlled input directly into database queries, letting an attacker execute commands as the database superuser and drop a reverse shell. Researchers at Horizon3 saw exploitation begin on August 30 and warn that most of the roughly 4,000 internet-exposed Switchvox systems may already have been targeted. Sangoma patched the flaw in version 8.4.0.2 back in July, but many systems remain unpatched and reachable.

Check
Update Sangoma Switchvox to 8.4.0.2 or later immediately, and because exploitation is active, review logs for the published indicators, reverse-shell activity, and process-enumeration commands on exposed systems.
Affected
Organizations running internet-exposed Sangoma Switchvox before 8.4.0.2 (CVE-2026-9586); an unauthenticated attacker can inject SQL, execute commands as the database superuser, gain a reverse shell, and take over the phone system.
Fix
Patch to 8.4.0.2, take the management interface off the public internet, hunt for reverse shells and unauthorized database changes, rotate credentials, and treat any exposed unpatched instance as potentially already compromised.

WordPress backup plugin flaw lets attackers hijack sites through a poisoned import

A flaw in All-in-One WP Migration and Backup, a WordPress plugin installed on millions of sites, can let an unauthenticated attacker take over a site. Tracked as CVE-2026-19949, it is a second-order SQL injection caused by incorrect handling of escaped characters when the plugin rewrites database content during a restore. An attacker plants crafted data through WordPress trackbacks, which triggers when an administrator exports and imports the site, both routine plugin operations. The injection can leak the plugin's secret import key through a public comment, letting the attacker import a malicious backup archive containing executable code and seize full control. ServMask fixed it in version 7.110, but many sites remain unpatched.

Check
Update All-in-One WP Migration and Backup to 7.110 or later across all WordPress sites, and review sites for suspicious trackback comments, unexpected admin accounts, and unfamiliar files.
Affected
WordPress sites running All-in-One WP Migration and Backup through 7.109 (CVE-2026-19949); an unauthenticated attacker can plant SQL injection that leaks the plugin's secret key, enabling a malicious archive import and site takeover.
Fix
Patch the plugin, scan for web shells and unexpected files, audit administrator accounts, rotate WordPress secrets, disable trackbacks if not needed, and put a web application firewall in front of the site.

Attackers probe LiteLLM AI gateways to steal cloud and model provider secrets

Attackers are actively probing LiteLLM deployments for an authorization flaw that turns a low-privilege account into full control of the AI gateway. Tracked as CVE-2026-35029 and affecting versions before 1.83.0, the flaw is a missing permission check on the configuration-update endpoint, so a read-only user can change settings reserved for administrators. LiteLLM sits between applications and model providers and stores provider API keys, database details, and admin credentials, making it a rich target. By abusing configuration writes, an attacker can extract secrets from server environment files and even reset the dashboard login to seize admin access. Researchers recorded thousands of probing requests, some directly attempting to read known secret files.

Check
Upgrade LiteLLM to 1.83.0 or later, restrict access to its control plane and configuration endpoints, and rotate any provider, cloud, or database secrets the gateway could expose.
Affected
Organizations running LiteLLM before 1.83.0 as an AI gateway (CVE-2026-35029); a low-privilege authenticated user can modify configuration, read environment secrets, and escalate to administrator, exposing stored model provider and cloud credentials.
Fix
Patch, segment and firewall the LiteLLM control plane away from untrusted users, enforce least privilege, store secrets outside reachable environment files, rotate exposed keys, and monitor configuration endpoints for unauthorized changes.