ZeroHour
Organization

Sansec

3 mentions in 7 days · 7 in 30 days · 8 total · first seen · last

Timeline

Top 10 Best Ransomware Protection Solutions in 2026

A 2026 buyer's guide ranks ten ransomware protection tools by kill-chain role as extortion shifts from encryption to data theft.

The roundup organizes defenses across the ransomware kill chain: prevention-grade EPP/EDR platforms, containment layers, rollback specialists, and immutable recovery. Recommended products include CrowdStrike, Microsoft Defender, Sophos, SentinelOne, Bitdefender, Trend Micro, Halcyon, Huntress, and Malwarebytes. It stresses that many crews now extort on stolen data without encrypting, making exfiltration detection and response speed as important as rollback.

Cyber Security News · 5d agoIndustry1

U.S. CISA adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalog

CISA added four actively exploited flaws to its KEV catalog: Magento StyleSmuggler RCE, two Windows privilege-escalation bugs, and N-able N-central RCE.

CISA added CVE-2026-75650 (Adobe Commerce/Magento, CVSS 10.0), CVE-2026-81963 and CVE-2026-85880 (Microsoft Windows local privilege escalation, CVSS 7.8 each), and CVE-2026-86218 (N-able N-central pre-auth RCE, CVSS 10.0) to its Known Exploited Vulnerabilities catalog. Sansec researchers report the StyleSmuggler Magento flaw, actively exploited since September 4, lets unauthenticated attackers run code on vulnerable online stores and deploy web shells and backdoors; Microsoft confirmed active exploitation of both Windows flaws, and N-able shipped an emergency hotfix. Federal civilian agencies must patch the Windows flaws by September 22, 2026, and the remaining entries by September 11, 2026 under BOD 22-01.

Security Affairsupdated · 1d agofirst · 5d agoExploit / PoC in the wild 5 sourcesCVE-2026-75650CVE-2026-81963CVE-2026-85880+1 CVEs1

Amasty patches dozens of Magento extensions, 2 critical

Amasty patched dozens of Magento/Adobe Commerce extensions, including two critical flaws allowing unauthenticated web shell upload and remote code execution.

Extension vendor Amasty released fixes for a large batch of Magento and Adobe Commerce modules, with critical unauthenticated file upload flaws in Advanced Product Reviews and Gift Card that allow attackers to plant web shells and take full control of stores. Dozens of additional high-, medium- and low-severity extensions were also patched. The vendor says the release affects almost every Magento and Adobe Commerce store. A related Order Attributes flaw was previously exploited heavily, with Sansec Shield blocking over 12,000 attempts against 25% of Magento stores in three days.

StyleSmuggler: The Magento Zero-Day Behind New Store Attacks

Sansec reports actively exploited Magento/Adobe Commerce zero-day StyleSmuggler enabling unauthenticated RCE and Rust backdoor installation on fully patched stores since September 4.

Sansec discovered StyleSmuggler, an unpatched zero-day in Magento Open Source and Adobe Commerce, affecting all current versions including 2.4.7, 2.4.8 and 2.4.9, with attacks observed since September 4. The two-stage attack poisons Magento's template system via the styles property and executes the injected PHP during 'Payment Transaction Failed Reminder' email rendering, working even when email delivery fails and when sessions are moved to Redis. Successful compromise installs a lightweight Rust backdoor disguised as fc-cache or chronyd that beacons every 60 seconds with 48-byte UDP packets to NTP port 123 at ntp.timesync.to. A second attacker deployed a PHP web shell in product-image cache directories, hidden behind 404 responses unless a correct X-Cache-Token header is present.

Security Affairs · 8d agoExploit / PoC in the wild

Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

StyleSmuggler zero-day in Magento and Adobe Commerce is actively exploited in the wild to deploy a Rust-based Linux backdoor; fix not yet released.

A zero-day dubbed StyleSmuggler affecting all versions of Magento and Adobe Commerce is being actively exploited, with the first observed incident on September 4 on a fully patched site. The exploit injects PHP code via Magento's template system through a fake 'failed-payment' email to achieve code execution, installing a Rust-based backdoor disguised as kworker/u:8:0 or fc-cache with a 30-minute cron job for persistence. The backdoor communicates via TLS/WebSockets or UDP port 123 masquerading as NTP traffic, checks TracerPid to detect tracing, and can receive remote commands. Adobe confirmed it is working on a fix with no timeline; Sansec recommends disabling GraphQL as mitigation and monitoring for suspicious cron entries and kworker or fc-cache processes. Magento is installed on more than 160,000 websites, including 14,000 of the top 1 million sites.

BleepingComputer · 8d agoExploit / PoC in the wild

Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

Sansec reports active exploitation of an unpatched zero-day, dubbed StyleSmuggler, in Magento and Adobe Commerce, letting attackers backdoor online store servers without authentication.

Sansec disclosed on September 5 that attackers are exploiting an unpatched vulnerability, named StyleSmuggler, in Magento Open Source and Adobe Commerce to achieve unauthenticated remote code execution, with attacks observed starting September 4. All current versions including 2.4.9 are affected, and Adobe has published no advisory, CVE, patch, or workaround, with the next scheduled security release on September 8. Hosting firm Disrex Group independently confirmed two compromised stores (running 2.4.8 and 2.4.7-p2), both breached within the roughly eight-hour window before Sansec's blocking rules went live. The implant is a ~1.9 MB statically linked Rust binary disguised as a Linux kworker process, re-adding a cron entry every five minutes and in one case reading Magento sessions directly from Redis with no outbound traffic.

The Hacker News · 10d agoExploit / PoC in the wild

StyleSmuggler: Magento and Adobe Commerce 0-day RCE (CVE-2026-75650) under active attack

Sansec details actively exploited StyleSmuggler 0-day (CVE-2026-75650, CVSS 10.0) unauthenticated RCE in Magento and Adobe Commerce, patched by Adobe hotfix APSB26-146.

Sansec is investigating StyleSmuggler, an actively exploited unauthenticated remote code execution chain in Magento Open Source and Adobe Commerce, now tracked as CVE-2026-75650 with CVSS 10.0. Adobe released hotfix VULN-39341 via APSB26-146 (priority 1) on September 7 for versions 2.4.4 through 2.4.9, but stores were being exploited for roughly three days before the fix existed. The implant is a Rust backdoor that disguises itself as kworker, fc-cache, or chronyd processes and exfiltrates host data in MessagePack records sent as fake NTP replies over UDP port 123. Adobe advises rotating the encryption key and every credential it protected, and Sansec stresses patching does not clean already-compromised stores.

Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws

Adobe patches seven flaws in ColdFusion, Commerce, and Campaign Classic, including actively exploited CVE-2026-71362 enabling customer account takeover.

Adobe issued Priority 1 updates fixing CVSS 10.0 flaws in ColdFusion (CVE-2026-48362, OS command injection) and Campaign Classic (CVE-2026-71398, CVE-2026-27302, incorrect authorization), plus CVE-2026-71362 (CVSS 9.1) in Adobe Commerce and Magento Open Source. Sansec reports threat actors are actively exploiting CVE-2026-71362 to switch customer sessions to other accounts and access private customer data. Adobe-hosted Campaign Classic instances are already remediated, while on-premise deployments are urged to patch within 72 hours. ColdFusion fixes ship in versions 2025.0.12 and 2023.0.23, and Campaign Classic fixes in v7 7.4.4 build 9400.

The Hacker News · Aug 15, 2026Vulnerability in the wildCVE-2026-48362CVE-2026-48273CVE-2026-71384+5 CVEs

Related CVEs

  • Unauthenticated Template Injection RCE in Adobe Commerce and Magento (CVE-2026-75650)
    Adobe Commerce and Magento (including Adobe Commerce B2B) contain an improper neutralization of special elements used in a template engine (CWE-1336), a template-injection flaw that permits arbitrary code execution in the context of the current user. The flaw is reachable over the network by unauthenticated attackers, requires no user interaction, and its changed scope (CVSS 3.1 S:C) means injected code executes beyond the vulnerable component, producing a maximum-severity (CVSS 10.0) remote code execution condition. A successful attacker gains arbitrary code execution on the storefront server; in the observed campaign, intruders installed a Rust backdoor and a PHP web shell (dubbed 'StyleSmuggler') on compromised servers. Any organization running an Adobe Commerce, Adobe Commerce B2B, or Magento storefront is in scope, with internet-facing e-commerce deployments most exposed. Exploitation is confirmed in the wild: the bug was abused as a zero-day before patching and was added to CISA's Known Exploited Vulnerabilities catalog on 2026-09-08.
    · Adobe Commerce · Adobe Commerce B2B KEV PoC mass
  • Pre-Auth Static Code Injection RCE in N-able N-central (Exploited in the Wild)
    CVE-2026-86218 is a static code injection flaw (CWE-96) in N-able's N-central on-premises remote monitoring and management (RMM) platform, carrying a maximum CVSS 4.0 score of 10.0. An unauthenticated, remote attacker triggers it by sending crafted network input to the N-central server that is improperly neutralized and persisted into application-managed code, which the server then executes — no privileges (PR:N) or user interaction (UI:N) are required. Successful exploitation yields full server compromise with high impact on confidentiality, integrity, and availability, and because N-central acts as the management hub for downstream customer endpoints, compromise can expose the entire managed estate. Any organization running an affected N-central release (before 2026.3.1.14) — primarily MSPs and corporate IT departments using N-able RMM — is affected. The flaw is confirmed exploited in the wild: N-able patched it as a zero-day, CISA added it to the KEV catalog on 2026-09-08, and it is the fourth N-central hotfix in five weeks, though no public PoC is known and ransomware use is unknown.
    · N-able N-central before 2026.3.1.14 KEV PoC large
  • Heap-Based Buffer Overflow in Windows ALPC Enables Local Privilege Escalation
    CVE-2026-85880 is a heap-based buffer overflow in Windows Advanced Local Procedure Call (ALPC), the Windows mechanism for local inter-process communication. An authorized local attacker can trigger the overflow by submitting crafted input over ALPC, corrupting heap memory in the component that handles the request. Successful exploitation allows the attacker to execute code with elevated privileges, typically gaining SYSTEM-level control of the local host, which is especially valuable as a post-exploitation or sandbox-escape step. Affected products include Windows 10 (1607, 1809, 21H2, 22H2) and Windows Server 2012, 2016, 2019, and 2022, meaning most on-premises Windows estates are in scope. The flaw was fixed in Microsoft's record 974-CVE September 2026 Patch Tuesday and was added to CISA's KEV on 2026-09-08, confirming exploitation in the wild; press reports describe Windows zero-days being chained with a Chrome zero-day in 'BlueMoon' kit attacks, though the data does not explicitly confirm this CVE is the Windows flaw in that chain.
    · Microsoft Windows 10 1607, 1809, 21H2, 22H2 · Microsoft Windows Server 2012, 2016, 2019, 2022 KEVmass
  • Local Privilege Escalation via Link Following in Windows Update Stack
    CVE-2026-81963 is a link-following flaw (CWE-59, improper link resolution before file access) in the Microsoft Windows Update Stack, in which the component fails to correctly resolve file links before opening them. A local attacker with low privileges can plant or manipulate a link (symlink/junction) that the privileged update stack follows during operation, redirecting its file access to an attacker-controlled target. The result is local privilege escalation — CVSS 3.1 rates this 7.8 (high) with high confidentiality, integrity, and availability impact — allowing an authorized local user or malware already on the machine to gain elevated rights. Affected products are Windows 11 23H2, 24H2, 25H2, and 26H1 and Windows Server 2025; any unpatched system on those versions is exposed to any local account holder. The flaw was fixed in Microsoft's record September 2026 Patch Tuesday (974 CVEs), was added to CISA's KEV on 2026-09-08 as one of two Windows zero-days reported as exploited in the wild, and has no known public PoC or confirmed ransomware use.
    · Microsoft Windows 11 23H2, 24H2, 25H2, 26H1 · Microsoft Windows Server 2025 KEVmass
  • Unauthenticated RCE in Adobe Campaign Classic via Incorrect Authorization
    Adobe Campaign Classic contains an incorrect authorization flaw (CWE-863) that allows an unauthenticated remote attacker to execute arbitrary code in the context of the current user. The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:C) indicates the flaw is reachable over the network with no privileges and no user interaction, and the changed scope shows the executed code crosses a security boundary, meaning a request to a vulnerable Campaign Classic instance can lead to code running beyond the application layer. A successful attacker gains code execution with high impact to confidentiality, integrity, and availability on the affected server. Organizations running Adobe Campaign Classic — typically large enterprises operating on-premises or hybrid marketing infrastructure — are affected; the available data does not specify affected version ranges, so defenders should consult the Adobe security bulletin for exact builds. There is currently no evidence of in-the-wild exploitation, no known public proof-of-concept, and the flaw is not in CISA's KEV; EPSS assigns a 0.8% probability of exploitation within 30 days (54th percentile).
    · Adobe Campaign Classicniche
  • Unauthenticated OS Command Injection RCE in Adobe ColdFusion
    Adobe ColdFusion is affected by an OS command injection vulnerability (CWE-78, Improper Neutralization of Special Elements used in an OS Command) rated critical at CVSS 10.0. It is triggered over the network with no authentication and no user interaction (AV:N/AC:L/PR:N/UI:N), so any network-accessible ColdFusion server is directly reachable by an unauthenticated attacker. Successful exploitation yields arbitrary code execution in the context of the current user, and the changed scope (S:C) indicates the injected commands can impact resources beyond the vulnerable ColdFusion component itself, such as other services or systems reachable from it. All ColdFusion deployments are plausibly affected; the data does not specify affected or fixed version ranges, so administrators should check Adobe's security bulletin (the related coverage notes Adobe patched this flaw alongside Campaign Classic issues). Exploitation has not been confirmed: it is not in CISA KEV and no public proof-of-concept is known, though EPSS assigns a 4.3% probability of exploitation within 30 days (91st percentile), warranting prompt patching.
    · Adobe ColdFusionlarge
  • Unauthenticated Arbitrary Code Execution via Authorization Flaw in Adobe Campaign Classic
    CVE-2026-27302 is an incorrect authorization flaw (CWE-863) in Adobe Campaign Classic (ACC) in which access controls are not properly enforced, allowing an attacker to trigger arbitrary code execution in the context of the application's user. Per the CVSS 3.1 vector, it is exploitable over a network with no privileges required and no user interaction, and the 'scope changed' designation means the code execution escapes the vulnerable component, extending impact beyond the application itself. A successful attacker gains arbitrary code execution on the affected server with high impact to confidentiality, integrity, and availability, reflected in the maximum 10.0 base score. Any organization running an affected version of Campaign Classic — an enterprise marketing campaign management platform — is exposed; exact affected version ranges are not included in the available data and must be confirmed in Adobe's advisory. There is no known public exploit or PoC, the flaw is not in CISA KEV, EPSS estimates a roughly 0.7% probability of exploitation within 30 days (51st percentile), and Adobe shipped the fix in a batch release that also addressed two other CVSS 10.0 flaws in ColdFusion and Campaign Classic.
    · Adobe Campaign Classic (ACC)large
  • Eval Injection RCE in Adobe ColdFusion (CVSS 9.9, low-privileged attacker)
    CVE-2026-48273 is a critical (CVSS 9.9) eval injection flaw (CWE-95) in Adobe ColdFusion in which untrusted input is not properly neutralized before it is placed into dynamically evaluated code. A remote attacker who has only low-privileged access to a vulnerable ColdFusion server can trigger the flaw over the network, with no user interaction required. Successful exploitation yields arbitrary code execution in the context of the current user, and the changed CVSS scope (S:C) indicates the impact can extend beyond the directly vulnerable component, a pattern typical of ColdFusion flaws that enable broader system-level code execution. All Adobe ColdFusion deployments are potentially affected; the source data does not specify affected version ranges, so admins should consult Adobe's bulletin for the exact versions fixed. As of this writing there is no known public proof-of-concept and the flaw is not in CISA KEV, though EPSS assigns a 1.7% probability of exploitation within 30 days; the fix shipped in Adobe's large recent patch batch, which also addressed three CVSS 10.0 ColdFusion and Campaign Classic flaws.
    · Adobe ColdFusionlarge
  • Unauthenticated Privilege Escalation Flaw in Adobe Commerce (Magento)
    CVE-2026-71362 is an incorrect-authorization flaw (CWE-863) in Adobe Commerce, the e-commerce platform formerly known as Magento, in which authorization checks are applied incorrectly and can be bypassed. It is triggered over the network without authentication or user interaction, per the CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N). A successful attacker gains elevated access to sensitive resources — a privilege-escalation condition that Adobe's APSB26-92 advisory and press coverage describe as an account-takeover risk. Any organization running an unpatched Adobe Commerce/Magento deployment is affected; exact version ranges are listed in Adobe security bulletin APSB26-92. The flaw came under active attack shortly after public disclosure, and its EPSS score of 25.1% (98th percentile) signals a high likelihood of continued near-term exploitation.
    · Adobe Commerce (Magento)mass
  • Unauthenticated SQL Injection Leading to RCE in Adobe Campaign Classic
    Adobe Campaign Classic contains an SQL injection flaw (CWE-89) that an attacker can leverage to execute arbitrary code in the context of the current user, with high confidentiality, integrity, and availability impact per Adobe's scoring. The flaw is reachable over the network without credentials (AV:N/PR:N) and requires no user interaction, but exploitation depends on conditions beyond the attacker's control (AC:H), and the changed scope (S:C) indicates the injected commands can affect resources beyond the vulnerable component. It affects organizations running Adobe Campaign Classic, Adobe's enterprise campaign-management platform, whose instances are typically deployed on-premises or in hybrid cloud setups. There is currently no public proof of concept, the flaw is not in CISA's KEV catalog, and EPSS estimates roughly a 0.6% probability of exploitation within 30 days. Adobe has published a fix in its security bulletin, and the disclosure arrives alongside Adobe's recent batch of critical ColdFusion and Campaign Classic patches.
    · Adobe Campaign Classic (ACC)moderate

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.