ZeroHour

Daily brief

AI-written briefings built from the classified stories, KEV additions, high-risk CVEs, incidents and model releases. Daily every morning; weekly recap on Mondays.

daily2026-09-17covers generated glm-5.3-flash

Top story

N-able's N-central MSP platform has a critical pre-authentication RCE, CVE-2026-86218, under active exploitation and now on CISA's KEV catalog. The static code injection flaw is scored CVSS 10.0 by N-able; hotfix 2026.3 Hotfix 4 (build 2026.3.1.14) shipped September 5, and hosted NCOD environments are already patched. Unpatched on-prem instances are the exposure: an MSP compromise cascades straight into customer networks.

Exploitation & threats

  • ConnectWise ScreenConnect CVE-2026-84869 hit CISA's KEV on September 11: attackers can transfer and execute files during an active session without authorization; fixed in 26.6.5, the federal patch deadline was September 14.
  • Cisco confirmed active exploitation of CVE-2026-76461 in Secure Email Gateway — SQL injection that can lead to OS command execution on affected appliances.
  • WatchTowr honeypots caught the first exploitation of WSO2 CVE-2026-5430 (CVSS 10) on September 13 — a JWT authentication bypass via tokens signed with unsupported algorithms, two months after the April patch.
  • Unauthenticated RCE in Issabel PBX (CVE-2026-89026) stems from a hard-coded HS256 JWT signing key; exploitation has been observed since September 9.
  • Iranian state-linked hackers are deploying CHOSEN BRICK Windows spyware against dissidents and journalists in the US, UK and Netherlands via WhatsApp and Telegram lures impersonating trusted contacts or support; the NCSC, FBI and Dutch AIVD issued a joint advisory.
  • Kaspersky details NightEagle (APT-Q-95), Hacking Cat, and Toy Ghouls targeting Russian enterprises with the GhostContainer Exchange backdoor, Gorilla RAT and destructive Monkey ransomware.

Patch priorities

  • N-able N-central: apply 2026.3 Hotfix 4 (CVE-2026-86218) to on-prem deployments.
  • ConnectWise ScreenConnect: upgrade to 26.6.5 (CVE-2026-84869).
  • Cisco Secure Email Gateway: patch CVE-2026-76461 (CVSS 9.8) on internet-facing appliances.
  • Cisco ISE: remediate CVE-2026-76460 (CVSS 10), an unauthenticated API authentication bypass.
  • GitLab CE/EE: upgrade to 19.1.8, 19.2.6 or 19.3.2 for CVE-2026-85706 (CVSS 10, EPSS 12%, nine public PoCs).
  • Google Pixel: install the September 2026 update for zero-click modem zero-day CVE-2026-58704 ahead of the September 19 KEV deadline.
  • Check Point: fix CVE-2026-91843 (CVSS 9.8), an unauthenticated stack overflow yielding root RCE on Security Management and Log Servers (sk1000155).
  • Apple platforms: September updates close 45+ flaws, including KEV-listed Screen Sharing auth bypass CVE-2026-65400 and Bluetooth RCE CVE-2026-65414 (both CVSS 9.8).
  • WooCommerce Wholesale Lead Capture: update the plugin now; CVE-2026-27540 arbitrary file upload is under active exploitation.

Breaches & incidents

  • CenterPoint Energy disclosed in an SEC 8-K that an unauthorized third party accessed customer data through an external-facing system; a threat actor claims 7.49 million records, including names, addresses, account numbers, billing data and partial SSNs.
  • ShinyHunters published hundreds of thousands of files from Florida's DAVID motor vehicle database — vehicle ownership certificates with names, addresses and VINs, plus some SSNs and non-US passports — after an unpaid ransom; FLHSMV confirmed the breach.
  • The **[US Coast Guard and FBI](https://zerohour.day/item/33bc03d89bfc37ea9d18

Stories in this brief