Weekly review

ThreatNoir Afternoon Brief — September 8

2026-09-08Afternoon4 articles
Audio
Listen to the episode

Afternoon Review in IT Security — September 8, 2026

The cybersecurity landscape on September 8, 2026 presents a critical convergence of zero-day exploitations and infrastructure vulnerabilities affecting widely deployed platforms. Organizations managing routers, remote administration tools, e-commerce systems, and identity management infrastructure face immediate patching demands as attackers actively exploit newly discovered flaws.

MikroTik Patches Critical Flaws Chained to Hack Routers

MikroTik has released patches addressing a chain of critical vulnerabilities collectively dubbed MikroTrick that enable complete device compromise. The vulnerability chain allows attackers to bypass authentication, overwrite configuration files, and seize control of affected routers. The flaws represent a significant threat to network infrastructure globally, as MikroTik devices are widely deployed in enterprise and service provider environments. Source: MikroTik Patches Critical Flaws Chained to Hack Routers

N-able Patches Critical Zero-Day in N-central

N-able has released patches for a critical zero-day vulnerability in N-central, its remote management and monitoring platform. The flaw carries maximum severity and poses significant risk to managed service providers and their customers. Administrators are strongly advised to audit their deployments for any newly created user accounts that lack authorization, as this may indicate exploitation activity. The vulnerability affects a widely used management tool that controls critical infrastructure across numerous organizations. Source: N-able Patches Critical Zero-Day in N-central

Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell

Adobe released emergency security patches to address a maximum-severity vulnerability in Adobe Commerce and Magento Open Source that has been actively exploited in the wild since September 4, 2026. The vulnerability, tracked as CVE-2026-75650 with a perfect CVSS score of 10.0, was identified and named StyleSmuggler by security researchers at Sansec. Active exploitation has already resulted in deployment of both Rust backdoors and PHP web shells on compromised systems, indicating attackers are establishing persistent access to e-commerce infrastructure. Source: Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell

FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials

Red Hat has disclosed a critical vulnerability chain in FreeIPA that permits unauthenticated clients to create Kerberos identities of their choosing and gain membership in the administrators group. FreeIPA serves as the identity and authentication system for Linux domain environments, managing access control across organizational networks through a 389 Directory Server database accessed via LDAP. The attack exploits a flaw in FreeIPA combined with a second vulnerability in the underlying directory server software, allowing anonymous users to establish persistent administrative access without legitimate credentials. Source: FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials

Organizations must prioritize immediate patching of these critical vulnerabilities across their infrastructure. The combination of active exploitation, maximum severity ratings, and broad deployment of affected products creates an urgent security posture requiring rapid response and comprehensive asset inventory verification.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).