Security news, decoded.
What happened, who is affected, and what to do next. Every story is linked to CVEs and enriched with product, exploitation, and patch context.
Adobe fixes critical Magento zero-day exploited to backdoor servers
7th September – Threat Intelligence Report
Attackers spread malware through ScreenConnect file transfers
N-able patches max severity N-central flaw amid ongoing attacks
Week in review: Claude accounts compromised through infostealer, Patch Tuesday forecast
Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted
Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities
In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation
Microsoft applied server-side patches to fix nine vulnerabilities affecting services including Entra ID, Azure Cosmos DB, Power Automate, and Copilot Studio. Meanwhile, public exploit code has emerged for CVE-2026-62911, a high-severity flaw in Microsoft Exchange Server that previously received an August patch but still affects more than 21,000 exposed systems.
HPE Patches Critical RCE Vulnerabilities in AOS-CX
Hewlett Packard Enterprise has deployed security updates for the Aruba Networking ArubaOS-CX platform, resolving 34 vulnerabilities including a critical remote code execution flaw identified as CVE-2026-73749. The advisory covers fixes for multiple software releases, specifically 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, and 10.10.1181, addressing issues ranging from denial-of-service attacks to authentication bypasses. This specific cluster of critical defects allows unauthenticated attackers to execute arbitrary commands with elevated privileges by sending malformed input to an internal service. While HPE reports that these flaws were found internally and there is no evidence of active exploitation yet, network administrators are advised to apply the latest patches and restrict management interface access.
Critical Citrix NetScaler auth bypass now leveraged in attacks
Security researchers at Previdian have observed active exploitation attempts against CVE-2026-19490, a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and Gateway appliances. This flaw enables unprivileged attackers to remotely circumvent authentication controls on devices configured as AAA virtual servers or Gateways (including SSL VPN and RDP proxies). While Citrix issued a patch in mid-August, recent data indicates that adversaries began targeting this weakness following the publication of a proof-of-concept exploit. Belgian cyber authorities have also warned organizations to prioritize upgrading vulnerable NetScaler instances to the recommended builds.
PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution
PostgreSQL has released security updates to address CVE-2026-6471, a high-severity vulnerability present since version 9.4 in 2014 that permits users with the REPLICATION attribute to execute arbitrary code as the database server's operating system user. The flaw arises because the logical decoding mechanism allows malicious specification of output plugin libraries, bypassing standard load restrictions. Affected versions include those prior to PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24; administrators must apply these updates and configure the new outputpluginlibraries parameter to whitelist permitted plugins, particularly if using third-party tools like wal2json.
Sangoma Switchvox Vulnerabilities Exploited in the Wild
Horizon3 has confirmed active exploitation of CVE-2026-9586, a critical-severity vulnerability in Sangoma Switchvox with a CVSS score of 9.3. This unauthenticated SQL injection flaw allows attackers to achieve remote code execution against the backend PostgreSQL database by sending crafted requests. In response to the ongoing attacks, CISA added this vulnerability to its Known Exploited Vulnerabilities catalog alongside five other issues affecting products such as JFrog Artifactory, SonicWall SMA1000, Starlette, Kestra, and LiteLLM. Federal agencies are directed to remediate the Switchvox flaw within three days, while patches for the associated Kestra and Starlette vulnerabilities must be applied within two weeks.
Google patches actively exploited Chrome zero-day (CVE-2026-85046)
Google has addressed twelve security flaws in its browser, including a high-severity vulnerability in the V8 engine known as CVE-2026-85046. This bug is currently being leveraged by attackers to run arbitrary code within the browser's sandbox through malicious web content. The patch has been distributed in Chrome version 152.0.7977.82 and 152.0.7977.83 for desktop platforms. Users should ensure their browsers are updated to mitigate the risk of remote exploitation.
12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover
Cyera researchers disclosed a high-severity flaw, tracked as CVE-2026-6471 (CVSS 7.2) and dubbed "PostGREShell," affecting all PostgreSQL releases from 2014 onward. This unauthorized access issue exists within the logical decoding mechanism, allowing an attacker holding specific Replication privileges to execute arbitrary code on the server operating system. By exploiting the defect, threat actors can escalate permissions to full superuser status, extract sensitive data, and establish persistent backdoors. The PostgreSQL Global Development Group has resolved the vulnerability in recent point releases, specifically versions 18.6, 17.11, 16.15, 15.19, and 14.24.
Google warns of new Chrome zero-day flaw exploited in attacks
Google has released updates for Chrome, upgrading desktop versions to 152.0.7977.82 and .83 on Windows/macOS and 152.0.7977.82 on Linux, to remediate an actively exploited high-severity zero-day vulnerability in the V8 engine. The flaw, identified as CVE-2026-85046, is a type confusion issue reported by researcher Salvatore Gulizia that could potentially lead to remote code execution via malicious JavaScript. This marks the sixth time Google has patched an in-the-wild Chrome exploit in 2026; users are advised to update promptly to protect their systems.
VMware Workstation and Fusion Updates Patch Critical Vulnerability
Broadcom has released updates for VMware Workstation and VMware Fusion to address two security flaws affecting versions 25H2 and 26H1. The most severe issue, identified as CVE-2026-59346 with a CVSS score of 9.3, allows an attacker with local administrator access on a guest VM equipped with a VMXNET3 adapter to execute code on the host via an integer overflow. A second vulnerability, CVE-2026-59347 (CVSS 8.1), is a stack-based buffer overflow that similarly permits code execution within the host's VMX process under specific privilege conditions. No workarounds are available for these defects, so Broadcom strongly advises users to update to version 26H1u1 immediately. While there is no current evidence of active exploitation and both bugs were reported privately, the frequent targeting of VMware products by threat actors underscores the urgency of applying this patch.
Google Patches 6th Chrome Zero-Day of 2026
Google has released security updates for Chrome 152 to address twelve vulnerabilities, most notably an actively exploited zero-day tracked as CVE-2026-85046. This high-severity flaw is a type confusion bug within the V8 JavaScript and WebAssembly engine, which attackers can leverage via crafted HTML pages to execute remote code. This marks the sixth zero-day patched in Chrome during 2026, following previous fixes in earlier releases. Users are advised to update immediately to version 152.0.7977.82 or 152.0.7977.83 depending on their operating system.
Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
Wordfence has reported active exploitation of two critical remote code execution vulnerabilities affecting the WordPress plugins Super Forms and Elementor Pro, with over 440,000 attempted attacks recorded so far. CVE-2026-14894 (CVSS 9.8) in Super Forms – Drag & Drop Form Builder enables unauthenticated users to upload arbitrary PHP files due to missing file type validation, a flaw fixed in version 6.3.314. Similarly, CVE-2026-32475 (CVSS 9.0/9.8) in Elementor Pro allows unrestricted file uploads through form widgets, leading to code execution on systems patched in version 4.2.2. Attackers are using these flaws to deploy web shells, such as "Mushr00wupl.php," to gain full control of compromised sites. Site administrators should update both plugins immediately and scan for unauthorized modifications to mitigate this ongoing threat.
Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws
Plex has released version 1.43.3 of Plex Media Server and version 1.115.0 of Plex Desktop to remediate multiple undisclosed security vulnerabilities, with CVE identifiers currently pending assignment. The company advises all administrators and users to apply these updates as soon as possible, noting that NAS installations may require manual package installation until local repositories update. Although specific details remain private, this release follows previous incidents involving high-severity authentication flaws and infrastructure exposure risks affecting the platform.
Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day
Google has released an emergency update for Chrome to address CVE-2026-85046, a high-severity type confusion vulnerability in the V8 engine that is currently being exploited in the wild. The flaw allows remote attackers to execute arbitrary code within the browser sandbox via crafted web content. Users are urged to upgrade immediately to version 152.0.7977.82 on Windows and macOS, or 152.0.7977.82 on Linux, to mitigate this active threat.
September 2026 Patch Tuesday forecast: All we need is more time
Security professionals face a continued surge in vulnerabilities heading into the September 2026 Patch Tuesday, driven by AI-assisted discovery techniques that have expanded the patch backlog significantly. While the previous update cycle resolved nearly four hundred issues, urgent attention is required for specific threats where exploitation has already begun or proof-of-concept code is available. Notably, threat actors are chaining CVE-2026-55040 and CVE-2026-63520 to achieve authentication bypass and remote code execution on SharePoint servers, while Exchange Server faces pressure from CVE-2026-62911, a high-severity elevation of privilege flaw. Additionally, Microsoft Defender is under scrutiny due to CVE-2026-69414, nicknamed 'ShieldBreak,' which grants system privileges through the malware engine and currently has public exploit code, though a fix is pending. Administrators must also prepare for several products reaching end of life this month, including specific Windows 11 editions and older Exchange Server versions, necessitating immediate upgrade planning. As the monthly cadence approaches, similar updates are expected from Adobe, Apple, and Mozilla, with recent Chrome releases already addressing actively exploited bugs.
HPE patches critical ArubaOS-CX remote code execution flaw
Hewlett Packard Enterprise has released security updates for ArubaOS-CX to address CVE-2026-73749, a critical buffer overflow vulnerability that permits unauthenticated remote attackers to execute code with elevated privileges. By sending specially crafted packets to an affected daemon process, malicious actors can compromise enterprise network switches running the operating system. The vendor advises administrators to upgrade affected devices to specific fixed releases, such as version 10.18.1002 or higher, depending on their current branch. While no active exploitation or public proof-of-concept tools have been identified yet, the bulletin also details 23 additional high-severity flaws affecting various components of the platform.
Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root
Cisco has issued updates for a critical vulnerability, identified as CVE-2026-20212 with a CVSS score of 9.8, affecting ten models of Silicon One-based Nexus 9000 switches. This defect allows unauthenticated remote attackers to achieve root-level code execution by sending crafted input to exposed TCP ports 43210 and 43211 within the default Layer 3 VRF instance. Alongside this specific fix, Cisco released an IOS XR hardening update addressing seven umbrella CVEs, two of which carry a maximum severity rating of 9.8, impacting all versions without available workarounds.
Critical Elementor Pro flaw exploited to take over WordPress sites
Attackers are actively exploiting a critical vulnerability in the Elementor Pro WordPress plugin, identified as CVE-2026-32475, to gain remote command execution on affected servers. The flaw, which affects versions 4.2.1 and earlier, permits malicious PHP uploads by bypassing file-validation checks in form elements, resulting in webshell installation. Wordfence reports blocking approximately 200,000 related attack attempts since the fix was released on August 19. Site administrators should immediately update to Elementor Pro 4.2.2 or later and audit the /wp-content/uploads/elementor/forms/ directory for unauthorized files.
Signature Optional - Analysis of CVE-2026-28323
Bishop Fox researchers have disclosed CVE-2026-28323, a critical unauthenticated SAML authentication bypass affecting SolarWinds Web Help Desk versions 2026.1 and earlier, with a proof-of-concept exploit now available. The flaw permits attackers to forge a SAML Response and bypass signature verification entirely if no certificate is configured or if the assertion lacks a valid signature, enabling them to assume the identity of any known user. SolarWinds released version 2026.2.1 to address this issue by replacing the legacy SAML stack with Spring Security’s enforced validation mechanisms.
Plex warns users to patch security vulnerabilities immediately
Plex has issued an urgent advisory urging users to immediately upgrade their installations to remediate several newly identified security vulnerabilities. These flaws, which have not yet been assigned official CVE identifiers, affect Plex Media Server versions up to and including v1.43.2, prompting the vendor to send direct email notifications to affected customers. The company recommends deploying Plex Media Server 1.43.3 and Plex Desktop 1.115.0 as soon as possible to mitigate potential risks, particularly for those using NAS devices who may need to install the updates manually.