Daily Security Intel

Archives
Log in
Subscribe
September 8, 2026

[SecurityIntel] 08 Sep | Active Zero-Day Exploitation of N-able and Adobe

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Tuesday, September 08, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

Active Zero-Day Exploitation of N-able and Adobe

CRITICAL

5

C2 IPs

40

OTX IOCs

27

ARTICLES

■ ANALYST TLDR

Today's threat landscape is dominated by critical zero-day exploits and active campaigns targeting remote management tools and e-commerce platforms. Most notably, N-able has rushed out its fourth hotfix in five weeks to patch an actively exploited unauthenticated RCE in N-central, while Adobe Commerce and Magento face active exploitation of the "StyleSmuggler" zero-day to deploy Linux backdoors. Additionally, a worm-like campaign is abusing modified ConnectWise ScreenConnect clients, and the "Nightmare Eclipse" exploit drop targets CrowdStrike, Nvidia, and Avast with local privilege escalation zero-days.

■ CRITICAL STORIES

INFO#1

N-able Issues Emergency Hotfix 4 for Actively Exploited N-central RCE

N-able has issued its fourth emergency hotfix in five weeks for a maximum-severity unauthenticated remote code execution (RCE) vulnerability in its N-central RMM platform. Because this flaw is reportedly being exploited in the wild, immediate patching to version 2026.3.1.14 or higher is critical for all on-premises deployments.

INFO#2

"StyleSmuggler" Zero-Day Exploited to Deploy Magento and Adobe Commerce Backdoors

Attackers are actively exploiting a zero-day vulnerability dubbed "StyleSmuggler" affecting all versions of Magento and Adobe Commerce. The exploit allows attackers to bypass security boundaries, execute arbitrary code, and deploy a stealthy Linux backdoor on online storefronts to steal sensitive customer and payment data.

INFO#3

Nightmare Eclipse Campaign Drops Zero-Day Exploits for CrowdStrike, Nvidia, and Avast

A sophisticated threat campaign named "Nightmare Eclipse" has released proof-of-concept exploits targeting previously undisclosed zero-day vulnerabilities in CrowdStrike, Nvidia, and Avast products. The exploits achieve local privilege escalation, spawning command shells with SYSTEM-level privileges on compromised endpoints.

INFO#4

Modified ScreenConnect Clients Abused in Worm-Like VBScript Campaign

Security researchers have observed a worm-like campaign abusing ConnectWise ScreenConnect. Attackers are using backdoored or modified ScreenConnect clients to automatically transfer and execute a four-stage malicious VBScript payload onto newly connected hosts, highlighting the risk of trusted remote access tools being weaponized.

■ CVEs IDENTIFIED

[CVE-TBD]

N-able N-central — Unauthenticated Remote Code Execution

Critical

[CVE-TBD]

Adobe Commerce and Magento — StyleSmuggler Zero-Day Remote Code Execution and Backdoor Deployment

Critical

[CVE-TBD]

CrowdStrike, Nvidia, Avast — Nightmare Eclipse Privilege Escalation to SYSTEM

Critical

[CVE-TBD]

ConnectWise ScreenConnect — Unpatched Remote Access Vulnerability

High

■ THREAT ACTORS

North Korean Hackers

State-sponsored

Deploying a stealthy Linux espionage toolkit that embeds a backdoor in HAProxy targeting automotive and media organizations.

Rhysida

Cybercrime / Ransomware

Linked to a new data leak publishing stolen login credentials from Berlin's government.

BigBear

Cybercrime / PhaaS

Operating the BigBear 2.0 phishing-as-a-service framework to bypass MFA and steal Microsoft 365 credentials.

■ ATT&CK TTPs

T1190
Exploit Public-Facing Application | Used to exploit Adobe Commerce "StyleSmuggler", N-able N-central, and Telerik UI vulnerabilities.
T1068
Exploitation for Privilege Escalation | Seen in the "Nightmare Eclipse" zero-day exploits targeting CrowdStrike, Nvidia, and Avast.
T1219
Remote Access Software | Modified ScreenConnect clients used to drop and execute payloads on newly connected hosts.
T1566.002
Phishing: Spearphishing Link | BigBear 2.0 MFA-bypass phishing and text-based QR code phishing.
T1539
Steal Web Session Cookie | JSCeal malware bypassing Google authentication using stolen session cookies.
T1176
Browser Extensions | PEEP post-compromise toolkit masquerading as a bookmarks extension to execute host commands.

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

N-able — N-central RCE flaw under active exploitation — THN

[P1 PATCH NOW]≤24h

Adobe — Commerce / Magento "StyleSmuggler" zero-day exploited in the wild — BC

[P1 PATCH NOW]≤24h

CrowdStrike — "Nightmare Eclipse" privilege escalation zero-day — SW

[P1 PATCH NOW]≤24h

Nvidia — "Nightmare Eclipse" privilege escalation zero-day — SW

■ RECOMMENDED ACTIONS TODAY

1[P1] Apply N-able N-central Hotfix 4 immediately to all on-premises servers below version 2026.3.1.14 to mitigate active unauthenticated RCE exploitation ([CVE-TBD]).
2[P1] Deploy security patches or server-side mitigations to Adobe Commerce and Magento installations to block the "StyleSmuggler" zero-day exploit ([CVE-TBD]).
3[P1] Implement the temporary mitigation measures provided by ConnectWise for the unpatched ScreenConnect Remote Access vulnerability ([CVE-TBD]).
4[P2] Restrict external SSH access to MikroTik RouterOS devices to prevent exploitation of the active router hijacking vulnerability chain ([CVE-TBD]).
5[P2] Audit enterprise endpoints for unauthorized browser extensions to detect and remove the PEEP post-compromise toolkit.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 09 Sep | Microsoft Patches Record 974 Flaws, Two Zero-Days Older → [SecurityIntel] 07 Sep | Active Unauthenticated SSH Hijacking of MikroTik Routers
Powered by Buttondown, the easiest way to start and grow your newsletter.