Generated · Archived snapshot 8 findings · 1 CVE
On this page

Exploitation Report

Executive Summary

Microsoft's September 2026 Patch Tuesday set a new record with 966 to 974 vulnerabilities addressed across Windows and associated products, including two actively exploited zero-day vulnerabilities.

While the volume of fixes creates significant deployment challenges for defenders, the most immediately critical issue is the active exploitation of CVE-2026-75650, a maximum-severity (CVSS 10.0) zero-day in Adobe Commerce and Magento Open Source dubbed "StyleSmuggler." Attackers have leveraged this flaw since at least September 4 to deploy a Rust-based backdoor and PHP web shells, achieving persistent server compromise.

Active Exploitation Details

CriticalActive exploitationPatchCVE-2026-75650#

  • Description: A critical zero-day vulnerability (CVE-2026-75650) in Adobe Commerce and Magento Open Source, codenamed StyleSmuggler, allows unauthenticated attackers to execute arbitrary code and achieve full server compromise. The flaw resides in the handling of style/layout XML processing and was discovered under active exploitation by Sansec on September 4, 2026.
  • Impact: Attackers gain remote code execution leading to full server takeover, deployment of persistent Rust-based backdoors and PHP web shells, and potential exfiltration of e-commerce data including payment information.
  • Status: Actively exploited in the wild since September 4, 2026. Adobe released emergency patches for affected versions of Adobe Commerce (2.4.7-p1, 2.4.6-p6, 2.4.5-p8, 2.4.4-p9) and Magento Open Source.

CriticalActive exploitationPatch#

  • Description: Microsoft's record-breaking September 2026 Patch Tuesday addressed 966 vulnerabilities (974 per some counts), including two actively exploited zero-day vulnerabilities. Specific CVE identifiers for the two zero-days were not disclosed in the reporting.
  • Impact: Active exploitation of two undisclosed zero-days affecting Windows operating systems and other Microsoft software, enabling potential remote code execution, privilege escalation, or security feature bypass.
  • Status: Patches released as part of September 2026 Patch Tuesday (KB5122878 for Windows 10, KB5124008/KB5122880 for Windows 11). 58 additional vulnerabilities assessed as "more likely to be exploited."

HighActive exploitationInvestigate#

  • Description: Threat actors are breaching F5 BIG-IP APM devices to deploy a sophisticated Linux rootkit that intercepts PHP file loading operations and injects a fileless web shell directly into memory, avoiding disk writes and traditional detection mechanisms.
  • Impact: Persistent, stealthy access to compromised F5 BIG-IP APM environments with the ability to execute arbitrary commands, intercept traffic, and maintain access across reboots without leaving forensic artifacts on disk.
  • Status: Active exploitation observed. No specific CVE identifier provided in reporting; mitigation guidance from F5 not detailed in source articles.

CriticalObservedPatch#

  • Description: Researchers at Calif demonstrated a zero-click worm that takes over WeChat accounts via incoming calls on both iPhone and Android. The victim does not need to answer or interact with the call; the attacker only needs to be in the victim's WeChat contacts list. The flaw was reported to Tencent in July 2026.
  • Impact: Full account takeover without user interaction, potential for worm-like propagation through contact lists, access to private messages, payments, and personal data.
  • Status: Proof-of-concept demonstrated by researchers; reported to vendor (Tencent) in July 2026. Tencent has reportedly addressed the issue. No CVE identifier provided.

CriticalPotentialInvestigate#

  • Description: A vulnerability chain in FreeIPA (the identity management system for Linux domains) and 389 Directory Server allows anonymous, unauthenticated clients to create a Kerberos identity of their choosing and add it to the administrators group, achieving full domain compromise.
  • Impact: Complete compromise of Linux domain identity infrastructure, enabling attackers to create persistent administrative accounts, access all domain resources, and maintain long-term access.
  • Status: Vulnerability disclosed by Red Hat; requires chaining two flaws (FreeIPA + 389 Directory Server). No CVE identifiers provided in reporting. Patch status not explicitly stated.

HighPotentialMonitor#

  • Description: Check Point Research demonstrated a flaw in ChatGPT where a single planted instruction in a conversation could cause the AI to silently exfiltrate data from a user's connected Gmail account and pass it to an attacker-controlled ChatGPT account through a hidden channel, while appearing to answer the user's question normally.
  • Impact: Covert exfiltration of email data and potentially other connected service data through AI prompt injection, bypassing user awareness and standard security controls.
  • Status: Proof-of-concept demonstrated by researchers. No CVE identifier provided. OpenAI response not detailed in reporting.

CriticalObservedMonitor#

  • Description: Attackers exploited a vulnerability in the Liquid Network's Elements sidechain software to steal nearly 4,000 BTC (approximately $47M at the time). The attackers returned 3,400 BTC the following day but continue to hold approximately 598.5 BTC. The network remains paused.
  • Impact: Theft of substantial cryptocurrency reserves from a Bitcoin sidechain, undermining trust in the federation model and causing service disruption.
  • Status: Active exploitation occurred September 6, 2026. Partial funds returned. Network paused. No CVE identifier provided for the "Elements Bug."

CriticalPotentialPatch#

  • Description: SAP addressed 20 vulnerabilities in its September 2026 security updates, including a maximum-severity memory corruption flaw in the SAP Kernel code, codenamed "OVERPASS." Specific CVE identifier not provided in reporting.
  • Impact: Memory corruption in the core SAP Kernel could allow remote code execution or denial of service in SAP enterprise systems.
  • Status: Patches released in September 2026 SAP Security Patch Day. Exploitation status not explicitly confirmed in reporting.

Affected Systems and Products

Attack Vectors and Techniques

Threat Actor Activities