Microsoft Patch Tuesday: Record-Breaking Vulnerability Volume and Active Exploitation
The September 2026 Microsoft Patch Tuesday release addresses a historic 974 CVEs, including over 100 critical vulnerabilities. Of significant concern are two actively exploited zero-day vulnerabilities: CVE-2026-81963 (improper link resolution in the Windows Update Stack) and CVE-2026-85880 (Windows ALPC heap-based buffer overflow), both enabling elevation of privilege and sandbox escapes. Additionally, a CVSS 9.8 RCE in the Windows DNS Server presents a high risk of wormable, infrastructure-wide compromise, reminiscent of the SigRed vulnerability. With 723 vulnerabilities affecting the Windows core and high-severity RCEs in Remote Desktop Services, immediate remediation is critical to prevent lateral movement and widespread perimeter breach.
PEEP Post-Exploitation Toolkit Targets Google Chrome and Microsoft Edge
PEEP is a specialized post-exploitation toolkit targeting Chromium-based browsers, specifically Google Chrome and Microsoft Edge. Deployed as a secondary-stage payload following initial administrative compromise or arbitrary code execution (ACE), PEEP achieves persistence by injecting malicious extensions directly into browser profile directories. The toolkit bypasses Web Store validation and suppresses installation prompts by forging "Secure Preferences" integrity values. By leveraging the Native Messaging API, PEEP establishes a communication bridge between the browser environment and the host operating system, enabling arbitrary shell command execution, credential exfiltration, and session hijacking, effectively transforming the browser into a stealthy command-and-control node.
OpenAI ChatGPT Sandbox Flaw Enables Cross-Account Gmail Data Exfiltration
Researchers at Check Point discovered a critical sandbox escape vulnerability in OpenAI's ChatGPT execution environment that permits cross-account data exfiltration. By leveraging indirect prompt injection, an attacker can deploy malicious instructions that transform the LLM into a stealthy agent. This agent exploits a shared clipboard mechanism—acting as a hidden communication channel within the sandbox—to facilitate unauthorized data transfer. The vulnerability targets Gmail API integrations, allowing attackers to retrieve private email content and exfiltrate it to an attacker-controlled account. The risk is amplified by the "Deep Research" agent, which introduces a zero-click vector by autonomously triggering the exfiltration during standard, unprompted research operations.
Factoring Legacy RSA Public Keys of a 1990s Certificate Authority
Researcher M. Pherrin has successfully executed the factorization of the RSA public keys belonging to a legacy Certificate Authority (CA) operating in the 1990s. By utilizing the General Number Field Sieve (GNFS) algorithm—likely via the CADO-NFS implementation—the researcher recovered the private prime factors (p, q) from the CA's public modulus (n). This achievement demonstrates that legacy RSA bit-lengths, previously considered computationally secure, are now susceptible to modern distributed computing resources. The successful factorization highlights a critical risk in Public Key Infrastructure (PKI) environments where antiquated root certificates or legacy-supported domains may still reside in trust stores, potentially allowing for the unauthorized issuance of forged X.509 certificates.
Vietnam-linked Advance Passenger Information System APIS Database Exposure
An unprotected, internet-facing Advance Passenger Information System (APIS) database, reportedly managed by Vietnam-linked entities, has exposed approximately 220.8 million records. The breach encompasses highly sensitive datasets including full legal identities, passport numbers, flight itineraries, and crew records spanning from January 2017 to April 2026. The lack of access controls allowed unauthorized access to a centralized repository of international travel data. This exposure presents critical risks of large-scale identity theft, passport forgery, and targeted espionage via the physical tracking of high-value passengers and aviation personnel.
Critical Unauthenticated RCE "StyleSmuggler" in Adobe Commerce and Magento
Sansec has identified "StyleSmuggler," a critical zero-day vulnerability enabling unauthenticated remote code execution (RCE) within Adobe Commerce and Magento Open Source. Exploitation, detected in the wild on September 4, 2026, utilizes injection via CSS and style-related parameters to bypass existing security filters. Attackers leverage this vector to deploy sophisticated web shells and persistent backdoors capable of surviving subsequent security patches. This flaw grants complete server-level control, facilitating the theft of customer PII and payment data. Organizations must prioritize immediate file integrity monitoring and credential rotation to mitigate the risk of deep-seated persistence.
MikroTik RouterOS: Critical "MikroTrick" Authentication Bypass Exploitation
A critical exploit chain, dubbed "MikroTrick," targets MikroTik RouterOS by combining an SSH authentication bypass (CVE-2026-67276) with an unauthenticated file-read vulnerability via the WebFig interface (CVE-2026-67281). This chain allows remote attackers to achieve full administrative takeover of internet-exposed devices without possessing legitimate RSA private keys. Despite MikroTik attempting a "silent" security patch on September 3, 2026, intelligence from CERT Polska confirms active exploitation was detected as early as September 2, 2026. This 24-hour discrepancy indicates that threat actors successfully bypassed authentication and gained control of target infrastructure prior to the availability of any vendor mitigation.
OpenAI Daybreak AI Cybersecurity Initiative
OpenAI has launched the Daybreak initiative, committing $1 billion in product credits to provide specialized AI-driven defensive tools to under-resourced critical infrastructure operators. The framework focuses on securing Industrial Control Systems (ICS) and SCADA environments by deploying AI models trained on domain-specific cybersecurity telemetry. By providing subsidized API integrations for legacy operational technology (OT) and advanced anomaly detection, the initiative aims to quantitatively reduce Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR) for sectors currently vulnerable to advanced persistent threats (APTs).
N-able N-central CVSS 10.0 Pre-Authentication Remote Code Execution and Supply Chain Exploitation
A critical pre-authentication remote code execution (RCE) vulnerability (CVSS 10.0) in the N-able N-central RMM platform has enabled threat actors to gain unauthorized initial access to management interfaces. Exploitation occurs via authentication bypasses and insufficient input validation, allowing arbitrary code execution with elevated system privileges. This flaw represents the third exploitation wave within a six-week window, facilitating systemic supply chain attacks where compromised Managed Service Providers (MSPs) serve as high-leverage vectors for deploying ransomware and info-stealers across downstream managed customer endpoints. Immediate remediation requires the application of official security patches and strict egress filtering to block identified C2 communications.
N-able N-central: Critical Pre-Authentication RCE CVE-2026-86218
CVE-2026-86218 is a critical pre-authentication remote code execution (RCE) vulnerability in the N-able N-central management platform. The flaw stems from a static code injection vulnerability (CWE-94 and CWE-95) located within specific HTTP endpoints, allowing unauthenticated attackers to execute arbitrary code on the host system. Because N-central serves as a centralized management hub for Managed Service Providers (MSPs), this vulnerability introduces extreme supply chain risk. Successful exploitation allows attackers to bypass authentication to gain initial access, facilitating lateral movement and the potential mass compromise of hundreds of downstream managed client environments through a single N-central instance.