Daily Security Intel

Archives
Log in
Subscribe
September 5, 2026

[SecurityIntel] 05 Sep | Critical RCEs Actively Exploited

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Saturday, September 05, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

Critical RCEs Actively Exploited

CRITICAL

5

C2 IPs

89

OTX IOCs

33

ARTICLES

■ ANALYST TLDR

Multiple critical vulnerabilities are under active exploitation, including RCE flaws in HPE AOS-CX, Citrix NetScaler, Sangoma Switchvox, and WordPress plugins, alongside a Google Chrome zero-day. Organizations face significant risk from these exploited flaws, large-scale data breaches affecting identity verification services, and sophisticated phishing campaigns leveraging unicode evasion. Proactive patching and enhanced detection are paramount.

■ CRITICAL STORIES

CRITICAL#1

HPE, Citrix, Sangoma, WordPress RCEs Exploited In The Wild

Multiple critical RCE and authentication bypass vulnerabilities across HPE AOS-CX (CVE-2026-73749), Citrix NetScaler (CVE-2026-19490), Sangoma Switchvox (CVE-2026-9586), and WordPress plugins Super Forms (CVE-2026-14894) and Elementor Pro are being actively exploited. These flaws allow for remote code execution or authentication bypass, posing an immediate and severe threat to affected systems.

INFO#2

Google Chrome Zero-Day Actively Exploited (CVE-2026-85046)

Google has patched a high-severity zero-day vulnerability (CVE-2026-85046) in the Chrome V8 engine that is under active exploitation. This marks the 6th Chrome zero-day patched this year, highlighting the persistent threat of browser-based attacks.

INFO#3

IDScan Sued Over Alleged Data Breach Affecting 153 Million Drivers

Identity verification company IDScan is facing lawsuits following an alleged data breach that compromised over 153 million driver's licenses. This incident underscores the severe impact of breaches on identity-related services and the vast amount of sensitive data at risk.

INFO#4

Phishing Campaign Uses Invisible Unicode to Evade Filters

A high-volume phishing campaign is leveraging invisible Unicode tag characters to bypass Microsoft email filters. This sophisticated evasion technique allows malicious emails to reach inboxes, increasing the risk of credential theft and malware delivery.

■ CVEs IDENTIFIED

CVE-2026-73749

HPE AOS-CX — RCE Vulnerabilities

Critical (9.8)

CVE-2026-19490

Citrix NetScaler — Authentication Bypass (exploited in the wild)

Critical

CVE-2026-6471

PostgreSQL — Logical Decoding Flaw, Replication-Role Code Execution

High (7.2)

CVE-2026-9586

Sangoma Switchvox — Unauthenticated SQL Injection, RCE (exploited in the wild)

Critical

■ THREAT ACTORS

Nightmare Eclipse

Security Researcher

Released CrowdStrike Falcon zero-day exploit

Amir Yaryab

Iranian Cyber Unit Leader

Oversees IRGC's cyber unit and CyberAv3ngers

IRGC's cyber unit

State-Sponsored

Cyberattacks on critical infrastructure

■ ATT&CK TTPs

T1566.001
Spearphishing Attachment | Phishing campaign using invisible Unicode to evade filters
T1036.002
Masquerading: Spoofing Name/Location | Invisible Unicode characters in phishing emails
T1190
Exploit Public-Facing Application | Exploitation of HPE AOS-CX, Citrix NetScaler, Sangoma Switchvox, WordPress Super Forms/Elementor Pro RCEs
T1078
Valid Accounts | Citrix NetScaler auth bypass, Dropbox account compromises, X password reset attacks, IDScan data breach
T1068
Exploitation for Privilege Escalation | CrowdStrike Falcon zero-day, PostgreSQL RCE, VMware Workstation/Fusion RCE
T1203
Exploitation for Client Execution | Google Chrome zero-day (V8 engine)

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

HPE AOS-CX — RCE, actively exploited — SW

[P1 PATCH NOW]≤24h

Citrix NetScaler — Auth Bypass, actively exploited — BC

[P1 PATCH NOW]≤24h

Sangoma Switchvox — RCE, actively exploited — SW

[P1 PATCH NOW]≤24h

WordPress Super Forms — RCE, actively exploited — THN

■ RECOMMENDED ACTIONS TODAY

1[P1] Immediately patch HPE AOS-CX to address CVE-2026-73749, Citrix NetScaler for CVE-2026-19490, Sangoma Switchvox for CVE-2026-9586, and WordPress plugins Super Forms (CVE-2026-14894) and Elementor Pro due to active exploitation.
2[P1] Update Google Chrome to the latest version to mitigate CVE-2026-85046 and other critical vulnerabilities, ensuring browser security against active zero-day exploits.
3[P2] Apply updates for PostgreSQL (CVE-2026-6471) and VMware Workstation/Fusion to prevent privilege escalation and host compromise from virtual machines.
4[P2] Review and strengthen email security configurations to detect and block sophisticated phishing campaigns, specifically those leveraging Unicode character evasion as reported by Microsoft.
5[P3] Audit and secure all systems handling sensitive identity data, such as IDScan, to prevent large-scale data breaches, focusing on robust access controls, encryption, and continuous monitoring.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 06 Sep | Active Zero-Day Exploits Target Adobe Commerce and Magento Older → [SecurityIntel] 04 Sep | Critical Cisco Nexus Root RCE Flaw Actively Threatens
Powered by Buttondown, the easiest way to start and grow your newsletter.