daily2026-09-17covers → generated glm-5.3-flash · https://zerohour.day/brief/2026-09-17
Top story
N-able's N-central MSP platform has a critical pre-authentication RCE, CVE-2026-86218, under active exploitation and now on CISA's KEV catalog. The static code injection flaw is scored CVSS 10.0 by N-able; hotfix 2026.3 Hotfix 4 (build 2026.3.1.14) shipped September 5, and hosted NCOD environments are already patched. Unpatched on-prem instances are the exposure: an MSP compromise cascades straight into customer networks.
Exploitation & threats
- ConnectWise ScreenConnect CVE-2026-84869 hit CISA's KEV on September 11: attackers can transfer and execute files during an active session without authorization; fixed in 26.6.5, the federal patch deadline was September 14.
- Cisco confirmed active exploitation of CVE-2026-76461 in Secure Email Gateway — SQL injection that can lead to OS command execution on affected appliances.
- WatchTowr honeypots caught the first exploitation of WSO2 CVE-2026-5430 (CVSS 10) on September 13 — a JWT authentication bypass via tokens signed with unsupported algorithms, two months after the April patch.
- Unauthenticated RCE in Issabel PBX (CVE-2026-89026) stems from a hard-coded HS256 JWT signing key; exploitation has been observed since September 9.
- Iranian state-linked hackers are deploying CHOSEN BRICK Windows spyware against dissidents and journalists in the US, UK and Netherlands via WhatsApp and Telegram lures impersonating trusted contacts or support; the NCSC, FBI and Dutch AIVD issued a joint advisory.
- Kaspersky details NightEagle (APT-Q-95), Hacking Cat, and Toy Ghouls targeting Russian enterprises with the GhostContainer Exchange backdoor, Gorilla RAT and destructive Monkey ransomware.
Patch priorities
- N-able N-central: apply 2026.3 Hotfix 4 (CVE-2026-86218) to on-prem deployments.
- ConnectWise ScreenConnect: upgrade to 26.6.5 (CVE-2026-84869).
- Cisco Secure Email Gateway: patch CVE-2026-76461 (CVSS 9.8) on internet-facing appliances.
- Cisco ISE: remediate CVE-2026-76460 (CVSS 10), an unauthenticated API authentication bypass.
- GitLab CE/EE: upgrade to 19.1.8, 19.2.6 or 19.3.2 for CVE-2026-85706 (CVSS 10, EPSS 12%, nine public PoCs).
- Google Pixel: install the September 2026 update for zero-click modem zero-day CVE-2026-58704 ahead of the September 19 KEV deadline.
- Check Point: fix CVE-2026-91843 (CVSS 9.8), an unauthenticated stack overflow yielding root RCE on Security Management and Log Servers (sk1000155).
- Apple platforms: September updates close 45+ flaws, including KEV-listed Screen Sharing auth bypass CVE-2026-65400 and Bluetooth RCE CVE-2026-65414 (both CVSS 9.8).
- WooCommerce Wholesale Lead Capture: update the plugin now; CVE-2026-27540 arbitrary file upload is under active exploitation.
Breaches & incidents
- CenterPoint Energy disclosed in an SEC 8-K that an unauthorized third party accessed customer data through an external-facing system; a threat actor claims 7.49 million records, including names, addresses, account numbers, billing data and partial SSNs.
- ShinyHunters published hundreds of thousands of files from Florida's DAVID motor vehicle database — vehicle ownership certificates with names, addresses and VINs, plus some SSNs and non-US passports — after an unpaid ransom; FLHSMV confirmed the breach.
- The **[US Coast Guard and FBI](https://zerohour.day/item/33bc03d89bfc37ea9d18