The useful pattern today is shared blast radius: commerce platforms that hold payment and customer data, MSP toolchains that administer many environments, and edge routers that control traffic into the network. Each story starts as a product flaw. The operational question is how much trust that product already carries when an attacker reaches it.
Lead Story
StyleSmuggler Gives Magento and Adobe Commerce Unauthenticated CVSS 10.0 RCE
Sansec says attackers have been exploiting StyleSmuggler since September 4, using Magento’s template system and a failed-payment email render path to execute code without authentication. Adobe assigned CVE-2026-75650, rated it CVSS 10.0, and published emergency bulletin APSB26-146 with hotfix VULN-39341 on September 7. The affected range covers Magento and Adobe Commerce 2.4.4 through 2.4.9, including builds that already carry recent security updates.
The observed follow-on is not limited to one malware process. A Rust backdoor has appeared as kworker/u:8:0, fc-cache, and chronyd, with cron persistence and NTP-shaped command-and-control. Sansec also found a separate PHP webshell under pub/media. Patching closes the vulnerable path; it does not establish that an exploited store is clean.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Why it matters: An e-commerce host may be able to reach payment gateways, customer records, deployment keys, databases, and extension integrations. Apply the hotfix, then verify the host, webroot, cron state, outbound traffic, and credential use during the September 4–7 exposure window. Adobe’s encryption-key and credential-rotation guidance should be treated as incident response, not routine post-patch housekeeping.
Read more on CyberExperts: Read the analysis
Also Worth Your Attention
N-able N-central Pre-Auth RCE Puts MSP Customer Environments in Scope
N-able released Hotfix 4 for N-central 2026.3, bringing it to 2026.3.1.14, to address CVE-2026-86218, a pre-authenticated RCE in the RMM platform. N-able’s public advisory says it has no confirmed production exploitation, while an urgent customer notice said the issue had been observed exploited in the wild and called it a zero-day. Huntress also flagged related CVE-2026-86206 and CVE-2026-86207, which can bypass authentication and provide unrestricted access. Because N-central can run scripts and administer many customers, a console incident must be evaluated across tenants, not only on the appliance.
Why it matters: Log rotation and conflicting disclosures can leave an MSP without a tidy answer. Patch every hosted and on-premises deployment, export logs before they roll over, audit users and API identities, and review mass changes, scripts, remote sessions, and customer notifications against the suspected window.
Read more on CyberExperts: Read more
MikroTrick Is Taking Over Internet-Exposed MikroTik Routers
CERT.PL says attackers are exploiting a chain of CVE-2026-67276 and CVE-2026-86060 against RouterOS devices with public SSH. The first bypasses SSH authentication through incomplete RSA-key validation; the second uses a crafted username to elevate the session to full administration. CVE-2026-67277 separately affects the bandwidth-test service. Fixed releases include RouterOS 7.24.2, 7.23.4, and 6.49.21, among others. Shadowserver counted about 122,500 MikroTik devices with exposed SSH as of September 5.
Why it matters: Router administration changes the path, DNS, VPN, firewall, and visibility for the network behind the device. Search for user -2 SSH failures, user added by ssh:-2@ , an unexpected privileged ops account, and the reported IPs 82.192.72.4 and 103.102.31.18. If unauthorized changes appear, isolate, preserve logs and configuration, factory-reset, rebuild from trusted material, and rotate keys and secrets.
Read more on CyberExperts: Read more
Go Deeper
Editorial Promise
CyberExperts should help you turn headlines into decisions. The value is in pulling the operational facts forward before the day turns them into background noise.
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
Get the Brief
Free. Weekday mornings. Unsubscribe anytime. Built from 100+ trusted cybersecurity sources.
#### OC
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.