Generated · Archived snapshot 8 findings · 5 CVEs
On this page

Exploitation Report

Executive Summary

Multiple critical vulnerabilities are under active exploitation across diverse technology stacks, ranging from e-commerce platforms and printing infrastructure to browser engines and network appliances. Attackers are leveraging both zero-day flaws and recently disclosed vulnerabilities within days of public availability, demonstrating rapid weaponization capabilities. The education sector faces targeted credential theft via PaperCut exploitation, while e-commerce sites suffer from an unpatched Magento/Adobe Commerce zero-day. Browser users remain at risk from an actively exploited Chrome V8 zero-day, and Citrix NetScaler appliances face authentication bypass attacks in the wild.

Threat actors are combining traditional vulnerability exploitation with novel evasion techniques, including ASCII smuggling using invisible Unicode characters to bypass email filters at massive scale. Compromised infrastructure is being repurposed for payload delivery through blockchain-hosted ClickFix campaigns affecting over 5,400 websites. Simultaneously, supply chain incidents like the ShipMonk breach and the JetBrains TeamCity compromise highlight the cascading impact of vulnerable third-party software. Privilege escalation capabilities continue to expand with a publicly released CrowdStrike Falcon zero-day and a stealthy Linux backdoor embedded in trojanized HAProxy builds.

Active Exploitation Details

CriticalActive exploitationPatchCVE-2026-81578CVE-2026-82078#

  • Description: Attackers are exploiting a vulnerability chain in PaperCut print management software comprising an authentication bypass (CVE-2026-81578) and a remote code execution flaw (CVE-2026-82078). The Arctic Wolf Adversary Research Team observed threat actors using this chain for command execution and reconnaissance.
  • Impact: Full command execution on PaperCut servers, credential theft, and network reconnaissance capabilities. Attacks specifically target the education sector in the U.S. and Europe.
  • Status: Actively exploited in the wild since public disclosure. Patches available from PaperCut.

CriticalActive exploitationPatchCVE-2026-19490#

  • Description: A critical-severity authentication bypass vulnerability in Citrix NetScaler (formerly NetScaler ADC and Gateway) allows unauthenticated attackers to bypass authentication mechanisms. Previdian vulnerability intelligence confirms active targeting in the wild.
  • Impact: Unauthenticated access to NetScaler management interfaces, potential full appliance compromise, and lateral movement into internal networks.
  • Status: Active exploitation confirmed by Previdian. Citrix has released security updates.

CriticalActive exploitationPatchCVE-2026-14894#

  • Description: A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder WordPress plugin allows unauthenticated attackers to upload arbitrary files, including PHP webshells, leading to remote code execution. Wordfence observed over 440,000 exploit attempts targeting this flaw alongside Elementor Pro vulnerabilities.
  • Impact: Complete compromise of WordPress sites, webshell deployment, data theft, and use as pivot points for further attacks.
  • Status: Mass exploitation ongoing with 440,000+ attempts observed. Patch available in Super Forms update.

HighActive exploitationPatchCVE-2026-85046#

  • Description: A high-severity type confusion vulnerability in the V8 JavaScript and WebAssembly engine of Google Chrome. Google confirmed active exploitation in the wild and released an emergency update addressing this flaw along with 11 other vulnerabilities.
  • Impact: Remote code execution via crafted web pages, browser sandbox escape potential, and full system compromise when chained with additional exploits.
  • Status: Actively exploited zero-day. Patched in Chrome 152.0.7977.82 and later versions.

CriticalActive exploitationMitigate#

  • Description: An unpatched zero-day vulnerability in Magento Open Source and Adobe Commerce, dubbed "StyleSmuggler" by Sansec, allows unauthenticated attackers to execute malicious code on online store servers. Attacks began on September 4, 2026, before any patch was available.
  • Impact: Full server compromise, payment skimmer injection, customer data theft, and persistent backdoor installation on e-commerce platforms.
  • Status: Active zero-day exploitation with no vendor patch available as of September 5. Sansec advisory published with mitigation guidance.

HighActive exploitationMitigate#

  • Description: Attackers are hijacking MikroTik routers with internet-exposed SSH services to gain full administrative control without authentication. CERT Polska issued a warning on September 5 confirming successful attacks dating to at least September 2.
  • Impact: Complete router compromise, traffic interception, network pivoting, DDoS botnet recruitment, and persistent access via modified configurations.
  • Status: Active exploitation confirmed. No authentication bypass vulnerability—exploitation leverages misconfigured internet-exposed SSH with weak/default credentials.

CriticalActive exploitationPatch#

  • Description: Unidentified threat actors exploited a recently disclosed critical vulnerability in JetBrains TeamCity to breach the JetBrains Cadence environment and extract AWS credentials. JetBrains urged all Cadence users to immediately revoke and rotate credentials.
  • Impact: Supply chain compromise, AWS credential theft, potential access to customer CI/CD pipelines and cloud resources.
  • Status: Confirmed breach via active exploitation of a recently disclosed TeamCity vulnerability. JetBrains has patched TeamCity.

HighObservedInvestigate#

  • Description: An anonymous researcher ("Nightmare Eclipse") publicly released a zero-day exploit named "FalconFlank" targeting CrowdStrike Falcon sensor on Windows, granting SYSTEM privileges on fully patched systems. The exploit demonstrates privilege escalation from standard user to SYSTEM.
  • Impact: Local privilege escalation to SYSTEM, security product tampering, defense evasion, and persistence establishment on endpoints running CrowdStrike Falcon.
  • Status: Public exploit code released. Active exploitation status unknown; defenders should investigate for signs of compromise.

Affected Systems and Products

Attack Vectors and Techniques

Threat Actor Activities