Summary: N-able released N-central 2026.3 Hotfix 4 (build 2026.3.1.14) addressing CVE-2026-86218, a pre-authentication remote code execution vulnerability scored CVSS 10.0 (static code injection, CWE-96). It affects every on-premises build before this release, including systems already updated to Hotfix 3 (2026.3.1.13) issued only hours earlier for two unrelated high-severity flaws (CVE-2026-86206 and CVE-2026-86207). Hosted NCOD instances were auto-patched; on-prem customers must upgrade immediately. N-able’s communications conflict on whether the new flaw has been exploited in production, while Huntress continues investigating recent customer compromises and urges IP allowlisting or isolation of exposed consoles. Shadowserver tracks nearly 1,500 internet-exposed N-central servers.
Key takeaway / Actionable note: Apply Hotfix 4 at once on all on-prem N-central instances, audit admin accounts for unexpected users, and restrict console access to VPN or allow-listed IPs.
Summary: CERT Polska confirmed active exploitation of a critical chain dubbed MikroTrick that combines CVE-2026-67276 (SSH authentication bypass via incomplete RSA public-key validation) and CVE-2026-86060 (SSH privilege escalation via crafted usernames) to gain full administrative control of internet-exposed RouterOS devices without valid credentials. Attacks have been observed since at least September 2. A third flaw, CVE-2026-67277, affects the bandwidth-test service and can leak kernel memory or crash the device. MikroTik issued fixes in 7.25beta3, 7.24.2, 7.23.4/7.23.5 and 6.49.21; Shadowserver reports more than 122,500 MikroTik devices with SSH reachable from the internet. Indicators include log entries for failed logins by user “-2” and creation of a privileged “ops” account.
Key takeaway / Actionable note: Upgrade RouterOS immediately, disable or restrict public SSH/WWW/bandwidth-test services, and inspect logs and configuration for the published IoCs before and after patching.
Summary: ConnectWise disclosed an issue affecting file-transfer behavior in ScreenConnect Remote Access Support and Access sessions that impacts both cloud and on-premises deployments. No CVE has been assigned yet; a permanent fix is expected later this week. Huntress documented worm-like activity in which rogue ScreenConnect clients repeatedly execute a four-stage VBScript chain (1.vbs–4.vbs) against newly connected hosts, leading to additional backdoors, UAC bypass tooling, tunneling utilities, or cryptocurrency miners. Temporary mitigation is to disable the TransferFiles (or TransferFilesInSession) permission for all roles and session groups.
Key takeaway / Actionable note: Disable file-transfer permissions on every ScreenConnect role immediately and scrutinize any on-premises instances for unexpected client connections or Run-key persistence.
Summary: Sansec disclosed StyleSmuggler, an unauthenticated remote-code-execution zero-day in Magento Open Source and Adobe Commerce that abuses the template system and “styles” properties. Attacks began September 4; Sansec reproduced the full chain on clean 2.4.7, 2.4.8 and 2.4.9 installs and observed victims already running July/August 2026 patches. Successful exploitation installs persistent backdoors (observed as kworker/u:8:0 or fc-cache). Adobe has not yet released a patch; the next scheduled security bulletin is September 8.
Key takeaway / Actionable note: Deploy temporary WAF/GraphQL blocks or Sansec Shield rules, scan for the known implant indicators, and prepare for the forthcoming Adobe update.
Summary: Hardware-wallet maker Trezor confirmed that a breach at shipping partner ShipMonk exposed an additional ~67,000 U.S. customers whose order data (name, email, phone, shipping address, order number) from November 2019–August 2021 was never deleted despite contractual assurances. Combined with the earlier disclosure of ~14,000 more recent customers, the total stands at approximately 81,000. Trezor’s own systems and devices remain uncompromised; the attackers reportedly exploited a Metabase SQL-injection zero-day at ShipMonk.
Key takeaway / Actionable note: Affected customers should treat any unsolicited contact requesting seed phrases or personal details as phishing and monitor for physical-security risks tied to exposed home addresses.
Summary: Huntress detailed three separate August 2026 incidents in which social-engineering lures (Quick Assist scam, phishing MSI, fake Geek Squad form) installed rogue ScreenConnect clients that then propagated a four-stage VBScript payload to every new host connection, creating worm-like behavior. Payloads branch according to environment checks and can deliver backdoors, privilege-escalation tools, or miners while establishing Run-key persistence.
Key takeaway / Actionable note: Treat any unexpected ScreenConnect client as potentially malicious; re-image affected hosts from known-good media and enforce the file-transfer mitigation above.
Summary: Threat actors are inserting invisible Unicode characters (ASCII smuggling) into phishing emails and lures to evade security filters that rely on plain-text pattern matching while still rendering readable content to recipients.
Key takeaway / Actionable note: Update email-security rules and user training to detect or flag messages containing unexpected zero-width or non-printing characters.
Summary: Additional reporting confirms the urgency of CVE-2026-86218 and notes that Huntress cannot yet determine whether the newest flaw or the prior Hotfix-3 pair was used in the customer compromise observed on September 4. The product has now seen three distinct critical vulnerability waves since early August.
Key takeaway / Actionable note: Prioritize on-prem N-central patching and console isolation ahead of other RMM maintenance windows.
Also Noted:
Bottom line: The past 24 hours underscored the continuing risk of internet-exposed management planes—N-central, MikroTik RouterOS, and ScreenConnect all saw active or newly disclosed exploitation paths that grant rapid administrative control. Patch the confirmed criticals today, disable unnecessary public services and file-transfer features, and assume any unpatched e-commerce or RMM instance is already under scrutiny.

