Generated · Archived snapshot 11 findings · 4 CVEs
On this page

Exploitation Report

Executive Summary

Microsoft's September 2026 Patch Tuesday set a historic record with 974 vulnerabilities addressed, including two actively exploited Windows zero-days and over 110 critical-severity flaws. Simultaneously, Google patched its seventh Chrome zero-day of the year (CVE-2026-87491), an out-of-bounds write in the V8 engine actively exploited in the wild. These mass patching events coincide with the discovery of BlueMoon, a previously undocumented exploit kit chaining multiple Windows and Chrome vulnerabilities that has been deployed by four distinct espionage groups—including China-aligned APT31—within a single week.

Critical infrastructure remains under direct assault. CISA added CVE-2026-86218, a pre-authentication RCE in N-able N-central (CVSS 10.0), to its Known Exploited Vulnerabilities catalog with an immediate patch deadline for federal agencies. SAP disclosed CVE-2026-44756, a maximum-severity memory corruption flaw in Extended Passport Processing enabling unauthenticated remote code execution. Meanwhile, a Microsoft Defender zero-day dubbed ShieldCrash grants SYSTEM access and demonstrates that the prior ShieldBreak patch (CVE-2026-69414) was insufficient, with a public proof-of-concept now circulating.

Beyond traditional software exploits, adversaries are weaponizing AI supply chains and identity frameworks at scale. U.S. intelligence agencies accuse six Chinese AI firms of conducting industrial-scale distillation attacks since late 2024, systematically extracting billions of tokens from frontier models including GPT, Claude, Gemini, and Grok. Concurrently, infostealers such as Lumma Stealer and Vidar are harvesting replayable AI API tokens that bypass MFA, while attackers hijack workflow identities and abuse account recovery flows to compromise enterprise environments. Financial crime operations continue to evolve, with the Xinbi Guarantee scam marketplace disrupted after facilitating Chinese organized crime and the DoppelCart network operating 119,000 fake storefronts for credit card theft.

Active Exploitation Details

MediumActive exploitationPatchCVE-2026-87491#

  • Description: An out-of-bounds write vulnerability in V8, Google Chrome's JavaScript and WebAssembly engine, affecting versions prior to the September 2026 stable channel update. The flaw allows code execution within the Chrome sandbox.
  • Impact: Attackers can execute arbitrary code inside the sandboxed renderer process, providing a foothold for sandbox escape chains or data theft from compromised web sessions.
  • Status: Actively exploited in the wild; patch released as part of Google's September 2026 update addressing 230 total vulnerabilities.

Severity unknownObservedInvestigateCVE-2026-69414#

  • Description: A zero-day vulnerability in Microsoft Defender, codenamed ShieldCrash, that grants SYSTEM-level access. The flaw represents a patch bypass for CVE-2026-69414 (ShieldBreak, CVSS 7.8), which Microsoft attempted to address in a prior update.
  • Impact: Local privilege escalation to SYSTEM, enabling full control of the affected endpoint, tampering with Defender, and persistence.
  • Status: Public proof-of-concept exploit released by researcher Chaotic Eclipse immediately after September 2026 Patch Tuesday; the earlier ShieldBreak patch is confirmed insufficient.

CriticalNot observedPatchCVE-2026-44756#

  • Description: A memory corruption vulnerability in SAP Extended Passport (EPP) Processing, rated CVSS 10.0, allowing unauthenticated remote code execution. Discovered and reported internally by SAP.
  • Impact: Complete compromise of confidentiality, integrity, and availability of affected SAP applications without requiring authentication.
  • Status: Security updates released by SAP; no public exploitation reported at time of disclosure.

CriticalActive exploitationPatchCVE-2026-86218#

  • Description: A maximum-severity (CVSS 10.0) pre-authentication remote code execution flaw in N-able N-central remote monitoring and management software.
  • Impact: Unauthenticated attackers can achieve full remote code execution on the N-central server, potentially compromising all managed endpoints.
  • Status: Added to CISA KEV catalog on September 9, 2026; Federal Civilian Executive Branch agencies required to patch by September 11, 2026. Actively exploited in the wild.

CriticalActive exploitationInvestigate#

  • Description: A previously undocumented exploit kit chaining multiple vulnerabilities in Microsoft Windows and Google Chrome. First in-the-wild use attributed to APT31, with three additional espionage clusters deploying it within a week.
  • Impact: Full compromise of target systems through chained browser and OS exploits, enabling espionage, data exfiltration, and persistence.
  • Status: Actively deployed by at least four distinct threat activity clusters; specific CVE identifiers for chained vulnerabilities not publicly disclosed in reporting.

CriticalActive exploitationPatch#

  • Description: Two distinct Windows zero-day vulnerabilities actively exploited in the wild, addressed in Microsoft's record 974-fix Patch Tuesday release. Specific CVE identifiers not provided in source reporting.
  • Impact: Remote code execution and/or privilege escalation on affected Windows versions; exploitation confirmed by Microsoft.
  • Status: Patches available as of September 2026 Patch Tuesday; active exploitation confirmed prior to patch release.

CriticalPotentialPatch#

  • Description: An authenticated hosting account with mail-related privileges can create arbitrary files via EmailTrack and execute code as root, affecting every supported version of cPanel and WHM.
  • Impact: Complete server takeover from a single compromised hosting account; lateral movement to all hosted sites and data.
  • Status: Advisory published September 8, 2026; patches available for all supported versions.

HighPotentialInvestigate#

  • Description: A flaw in DeepSeek Harness, an open-source tool for running AI coding agents, allowing a sandboxed agent to disable its own file sandbox with a single command via the tool's web API.
  • Impact: AI agents operating on untrusted code can escape containment and write arbitrary files on the host developer machine.
  • Status: Flaw disclosed; patch status not specified in reporting.

CriticalPotentialMitigate#

  • Description: A critical flaw in Alby Hub (versions v1.7.0 through unspecified) allowing attackers to take over internet-exposed self-hosted Lightning wallets and transfer funds.
  • Impact: Full theft of bitcoin funds from wallets where the owner made the Hub reachable from the internet.
  • Status: Warning issued by Alby; affects only internet-exposed instances.

HighPotentialPatch#

  • Description: Over 36,000 internet-exposed Plex Media Server instances remain unpatched against multiple recently disclosed security vulnerabilities.
  • Impact: Remote compromise of media servers, potential lateral movement, data access, and use as pivot points in home/SMB networks.
  • Status: Patches available; large-scale exposure persists due to lack of administrator action.

HighObservedInvestigate#

  • Description: Malware targeting F5 BIG-IP Access Policy Manager appliances injects a PHP web shell into Apache memory rather than disk, evading file-based detection. The shell is added when Apache loads any of three specific appliance PHP scripts.
  • Impact: Persistent, stealthy remote access to compromised load balancers/APM devices; survives reboots if reinjection mechanism persists; evades standard forensic disk analysis.
  • Status: Active compromise campaign analyzed by Sophos (published September 7, 2026); initial access vector not specified in reporting.

Affected Systems and Products

Attack Vectors and Techniques

Threat Actor Activities