Published: 09/17/26
Thursday’s brief is a blast-radius day: a CVSS 10 pre-auth hit on N-able N-central (the MSP brain), JFrog Artifactory admin chains dropping Rust backdoors, Citrix NetScaler gateway bypass already in the wild, and a brand-new Google Pixel KEV with a September 19 federal clock.
Lead Story
N-able N-central: Pre-Auth RCE on the MSP Brain
Unauthenticated code execution on on-prem N-central (fixed in Hotfix 4 / 2026.3.1.14) can be chained with earlier auth bypasses to mint admin accounts. Exploitation predated disclosure; CISA put it on KEV September 8.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Why it matters: One console foothold becomes every managed customer endpoint. Patch, then hunt stranger admins — especially .invalid emails.
Read more on CyberExperts: Read the analysis
Also Worth Your Attention
JFrog Artifactory: Unauth → Admin → Backdoor
Wiz saw attackers chain token flaws into administrator scope in under five minutes, then drop Groovy plugins and a Rust C2. Patch does not revoke minted tokens or join keys.
Why it matters: Your artifact server is the trust root for build pipelines.
Read more on CyberExperts: Read more
Citrix NetScaler: Gateway Bypass in the Wild
Critical auth bypass on gateway/AAA profiles, patched August 19, exploited from ~September 3 after a public PoC, and added to KEV September 10.
Why it matters: Edge VPN and AAA are where “unauth” becomes “inside.”
Read more on CyberExperts: Read more
Google Pixel: Fresh KEV, Due September 19
CISA added a Pixel cellular-modem improper-authorization bug on September 16. Verify MDM security patch levels; quarantine stale devices from SSO and VPN.
Why it matters: Phones carry MFA and mail sessions — modem privilege bugs are enterprise problems.
Read more on CyberExperts: Read the analysis
Go deeper: Identity & Access Management · Cybersecurity Tools · Get the Daily Brief
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.