Generated · Archived snapshot 10 findings · 5 CVEs
On this page

Exploitation Report

Executive Summary

Active exploitation campaigns are targeting a diverse range of enterprise infrastructure, from network edge devices and remote management platforms to e-commerce systems and developer tools. Attackers are chaining vulnerabilities for unauthenticated remote code execution, leveraging zero-days in widely deployed software, and adopting novel evasion techniques such as invisible Unicode characters in phishing and blockchain-hosted payloads. The education sector, managed service providers, and organizations with internet-exposed administrative interfaces face immediate risk.

Multiple vendors have released emergency patches for vulnerabilities already exploited in the wild, including N-able N-central, PaperCut, Citrix NetScaler, and VMware Workstation/Fusion. However, critical gaps remain: Magento and Adobe Commerce stores face an unpatched zero-day (StyleSmuggler), ConnectWise ScreenConnect users must apply mitigations ahead of a pending patch, and a CrowdStrike Falcon zero-day exploit (FalconFlank) has been publicly released. Threat actors are also abusing legitimate features—such as session cookies and AI agents—to bypass authentication and establish covert coordination channels.

Active Exploitation Details

Severity unknownActive exploitationPatch#

  • Description: Attackers are exploiting a chain of two recently disclosed vulnerabilities in MikroTik RouterOS to take full administrative control of devices with SSH services exposed to the internet. No authentication is required for successful compromise.
  • Impact: Complete router hijacking, enabling traffic interception, lateral movement, and persistent network access.
  • Status: Actively exploited since at least September 2; CERT Polska has issued an attack warning.

Severity unknownPotentialMitigate#

  • Description: A newly disclosed vulnerability in ConnectWise ScreenConnect Remote Access software. ConnectWise has published temporary mitigation measures and plans to release a patch.
  • Impact: Potential remote access compromise; details limited in public reporting.
  • Status: No patch available at time of reporting; mitigations published.

CriticalObservedPatch#

  • Description: An unauthenticated remote code execution flaw in the N-central remote monitoring and management (RMM) platform. N-able has released four hotfixes in five weeks; the incident notice states the flaw has been exploited in the wild, though release notes mark this as unconfirmed.
  • Impact: Unauthenticated attackers can achieve remote code execution on on-premises N-central servers.
  • Status: Hotfix 4 (build 2026.3.1.14) released; prior hotfixed builds remain vulnerable.

CriticalActive exploitationMitigate#

  • Description: An unpatched zero-day vulnerability (named StyleSmuggler by Sansec) in Magento Open Source and Adobe Commerce allows unauthenticated attackers to execute malicious code on the store server. Attacks began on September 4.
  • Impact: Full server compromise, backdoor deployment, and potential payment data theft on e-commerce platforms.
  • Status: Actively exploited; no vendor patch available at time of reporting.

CriticalActive exploitationPatch#

  • Description: Unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach JetBrains' own Cadence environment, extracting AWS credentials and secrets used in Cadence executions.
  • Impact: Supply chain compromise risk; credential theft enabling further cloud infrastructure access.
  • Status: Exploited in a confirmed breach; JetBrains urges immediate credential rotation.

CriticalActive exploitationPatchCVE-2026-81578CVE-2026-82078#

  • Description: Threat actors are chaining CVE-2026-81578 (authentication bypass) and CVE-2026-82078 (remote code execution) in PaperCut to conduct command execution, reconnaissance, and credential theft targeting educational institutions in the U.S. and Europe.
  • Impact: Credential theft, system compromise, and potential lateral movement in school and university networks.
  • Status: Actively exploited; Arctic Wolf Adversary Research Team has observed attacks.

CriticalActive exploitationPatchCVE-2026-19490#

  • Description: Attackers are actively exploiting CVE-2026-19490, a critical-severity authentication bypass in Citrix NetScaler, according to vulnerability intelligence firm Previdian.
  • Impact: Unauthenticated administrative access to NetScaler appliances, enabling full control of traffic management and VPN infrastructure.
  • Status: Exploitation confirmed in the wild.

CriticalObservedMitigate#

  • Description: An anonymous researcher ("Nightmare Eclipse") publicly released a zero-day exploit named FalconFlank for CrowdStrike Falcon, granting SYSTEM privileges on up-to-date Windows systems.
  • Impact: Local privilege escalation to SYSTEM, bypassing endpoint protection and enabling kernel-level persistence.
  • Status: Exploit code publicly released; active exploitation scope unclear.

CriticalPotentialPatchCVE-2026-59346#

  • Description: CVE-2026-59346 (CVSS 9.3) is a critical integer-overflow vulnerability in VMware Workstation and Fusion. A local attacker with elevated privileges inside a virtual machine can exploit it to execute arbitrary code on the host.
  • Impact: VM escape leading to host code execution.
  • Status: Security updates released by Broadcom; no active exploitation reported.

HighNot observedPatchCVE-2026-6471#

  • Description: CVE-2026-6471 (CVSS 7.2) is a 12-year-old flaw in PostgreSQL's logical decoding feature that allows an account with the REPLICATION attribute to execute arbitrary code as the database server's operating-system user. Present since PostgreSQL 9.4 (2014).
  • Impact: Database server compromise via replication role escalation.
  • Status: Fixed in PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24; no exploitation reported.

Affected Systems and Products

Attack Vectors and Techniques

Threat Actor Activities