Executive assessment
Today's brief leads with Adobe Commerce and Magento StyleSmuggler zero-day exploited for unauthenticated RCE. All 10 selected findings retain their own technical scope, action, observed status, and evidence limits.
Panel synthesis: Finding 01 should lead today over the first finding because it is an unauthenticated RCE under in-the-wild exploitation and has only a hotfix, with no full fixed release identified. Finding 02 is the other immediate lead candidate because it is also an unauthenticated RCE under active exploitation and has a fixed N-central release. Themes: Actively exploited unauthenticated RCE; Critical Microsoft RCE concentration; Patchable third-party exposure. Patch order: Finding 01 (Adobe Commerce and Magento unauthenticated RCE is being exploited in the wild; apply the VULN-39341 hotfix because no full fixed release is identified); Finding 02 (N-able N-central unauthenticated RCE is being exploited in the wild and is fixed in N-central 2026.3.1.14).
Finding 01 — Adobe Commerce and Magento StyleSmuggler zero-day exploited for unauthenticated RCE
What changed: Adobe confirms that CVE-2026-75650 is an unauthenticated template-injection vulnerability enabling arbitrary code execution in affected Adobe Commerce, Adobe Commerce B2B, and Magento Open Source versions. Exploitation began before disclosure and has deployed a Rust backdoor, PHP dropper, and web shell; Adobe released hotfix VULN-39341 and directs operators to rotate encryption keys and associated credentials.
Technical evidence: CVE-2026-75650; CVSS v3.1 10; weakness CWE-1336; technical confidence High.
Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.
Observed status: Observed in-the-wild exploitation is confirmed.
Analyst note: Block outbound traffic to 185.157.160.251. Monitor UDP/123 for bursts of nine 48-byte datagrams roughly every 60 seconds and for malicious background processes disguised as fc-cache or chronyd. Adobe reports exploitation in the wild targeting Adobe Commerce merchants. ([helpx.adobe.com](https://helpx.adobe.com/security/products/magento/apsb26-146.html), [experienceleague.adobe.com](https://experienceleague.adobe.com/en/docs/commerce-knowledge-base/kb/announcements/commerce-apsb26-146), [sansec.io](https://sansec.io/research/stylesmuggler-0day))
Affected: Adobe Commerce: 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug and 2.4.4-2026-aug and earlier; Adobe Commerce B2B: 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4 ([helpx.adobe.com](https://helpx.adobe.com/security/products/magento/apsb26-146.html))
Fix: VULN-39341 hotfix; no full fixed release is identified. ([sansec.io](https://sansec.io/research/stylesmuggler-0day))
Action: Map CVE-2026-75650 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: helpx.adobe.com](https://helpx.adobe.com/security/products/magento/apsb26-146.html)
Finding 02 — N-able N-central CVE-2026-86218 unauthenticated RCE under active exploitation
What changed: NHS England says CVE-2026-86218 is a CVSS 10.0 flaw permitting unauthenticated remote code execution in N-able N-central and assesses further exploitation as highly likely. N-able has issued Hotfix 4 for affected on-premises builds; administrators should patch, restrict exposure, and inspect for unexpected accounts.
Technical evidence: CVE-2026-86218; CVSS v4.0 10; weakness CWE-96; technical confidence High.
Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.
Observed status: Observed in-the-wild exploitation is confirmed.
Analyst note: Restrict all internet access to the N-central management console with firewall rules, allowing only trusted, specified IP addresses. Require a VPN with multi-factor authentication for all remote access to the console. ([f5.com](https://www.f5.com/labs/articles/weekly-threat-bulletin-september-9th-2026), [helpnetsecurity.com](https://www.helpnetsecurity.com/2026/09/07/n-able-n-central-hotfix-cve-2026-86218/), [me.n-able.com](https://me.n-able.com/s/security-advisory/aArVy0000002Ld3KAE/cve202686218-preauthentication-remote-code-execution))
Affected: N-central versions earlier than 2026.3.1.14. ([me.n-able.com](https://me.n-able.com/s/security-advisory/aArVy0000002Ld3KAE/cve202686218-preauthentication-remote-code-execution))
Fix: N-central 2026.3.1.14. ([me.n-able.com](https://me.n-able.com/s/security-advisory/aArVy0000002Ld3KAE/cve202686218-preauthentication-remote-code-execution))
Action: Map CVE-2026-86218 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
[Evidence source: cisa.gov](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?vulnId=CVE-2026-86218)
Finding 03 — Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connections
What changed: Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connections The cited source identifies the affected product and the available advisory or remediation status. CVE coverage: CVE-2026-84372.
Technical evidence: CVE-2026-84372; CVSS v3.1 9.8; weakness CWE-93; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-84372 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: github.com](https://github.com/advisories/GHSA-w6f5-v2h6-g786)
Finding 04 — Microsoft Patch Tuesday, September 2026: 474 CVEs across 46 advisories
What changed: Microsoft's September 2026 security update fixes 474 CVEs across 46 advisories (22 critical, 302 high, 148 medium, 2 low CVEs). Products with the most fixes: SQL Server (62); Microsoft Office (51); Windows DHCP (38); Windows NTFS (29); Microsoft Excel (28); Microsoft Office Word (21).
Technical evidence: CVE-2026-65669; CVSS v3.1 9.6; weakness CWE-74; technical confidence High.
Why it matters: The Critical priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-65669 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: msrc.microsoft.com](https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-77482)
Finding 05 — Cesanta Mongoose Web Server v7.14: four parser and TLS memory-safety flaws
What changed: Cesanta Mongoose Web Server v7.14 contains four flaws involving unexpected TLS packets or certificate/input delimiters. The issues can trigger segmentation faults, an out-of-bounds memory write, or an infinite loop, creating denial-of-service and memory-corruption risk in embedded web applications.
Technical evidence: CVE-2024-42384; CVSS v3.1 7.5; weakness CWE-190; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2024-42384 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2024-42384)
Finding 06 — Multiple vulnerabilities in Secure Boot
What changed: CVE coverage: CVE-2026-20293, CVE-2026-69713. The cited advisories disclose: Bypass Vulnerability; Security Feature Bypass Vulnerability.
Technical evidence: CVE-2026-20293; CVSS v3.1 7.1; weakness CWE-749; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-20293 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: sec.cloudapps.cisco.com](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ucs-uefi-sb-bypass-eb6xC5GW?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20UCS%20and%20UCS-Based%20Appliances%20UEFI%20Shell%20Secure%20Boot%20Bypass%20Vulnerability%26vs_k=1)
Finding 07 — NLTK 3.9.3 security release: four downloader and corpus path-control flaws
What changed: NLTK before 3.9.3 contains four flaws: missing post-download integrity verification can admit substituted packages, while three corpus/path handling weaknesses allow local file reads outside intended roots. Upgrade to NLTK 3.9.3 and review any environments that download corpora across untrusted networks or shared filesystems.
Technical evidence: CVE-2026-63312; CVSS v4.0 8.7; weakness CWE-22; technical confidence High.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-63312 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: github.com](https://github.com/advisories/GHSA-x5ph-mj9p-rfr8)
Finding 08 — mongodb: Reject "." and NUL bytes in database and collection names
What changed: mongodb: Reject "." and NUL bytes in database and collection names The cited source identifies the affected product and the available advisory or remediation status. CVE coverage: CVE-2026-81525.
Technical evidence: CVE-2026-81525; CVSS v4.0 8.6; weakness CWE-943; technical confidence Medium.
Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2026-81525 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: github.com](https://github.com/advisories/GHSA-65fr-j4p9-vc33)
Finding 09 — Microsoft releases Windows 10 KB5122878 extended security update
What changed: Microsoft has released the Windows 10 KB5122878 extended security update, which includes this month's record-breaking September 2026 Patch Tuesday fixes, along with a few bug fixes. [...] The cited source identifies the affected product and the available advisory or remediation status.
Technical evidence: CVE-2026-81963; CVSS v3.1 7.8; weakness CWE-59, CWE-284; technical confidence High.
Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.
Observed status: Observed in-the-wild exploitation is confirmed.
Action: Map CVE-2026-81963 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: cisa.gov](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?vulnId=CVE-2026-81963)
Finding 10 — USN-8735-1: HSQLDB vulnerability
What changed: HSQLDB mishandles crafted database files, allowing an attacker to overwrite arbitrary files. Ubuntu published fixed packages for supported and ESM releases on 8 September 2026.
Technical evidence: CVE-2023-1183; CVSS v3.1 5; weakness CWE-20; technical confidence High.
Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.
Observed status: Observed in-the-wild exploitation status is unknown.
Action: Map CVE-2023-1183 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.
Evidence limits: fixed version or patch state unknown
[Evidence source: ubuntu.com](https://ubuntu.com/security/notices/USN-8735-1)