Daily Security Intel

Archives
Log in
Subscribe
September 9, 2026

[SecurityIntel] 09 Sep | Microsoft Patches Record 974 Flaws, Two Zero-Days

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Wednesday, September 09, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

Microsoft Patches Record 974 Flaws, Two Zero-Days

CRITICAL

5

C2 IPs

83

OTX IOCs

34

ARTICLES

■ ANALYST TLDR

Today's intelligence landscape is dominated by Microsoft's record-breaking September 2026 Patch Tuesday addressing over 970 vulnerabilities, including two actively exploited privilege-escalation zero-days. Concurrently, Adobe has patched a maximum-severity CVSS 10.0 zero-day (CVE-2026-75650) in Adobe Commerce and Magento that is actively exploited to deploy Rust backdoors. Additionally, critical infrastructure and networking devices face severe threats, with active exploitation of F5 BIG-IP APM devices to deploy fileless memory-resident Linux rootkits and a critical "MikroTrick" vulnerability chain allowing passwordless takeover of MikroTik routers.

■ CRITICAL STORIES

CRITICAL#1

Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor

Tracked as CVE-2026-75650, this maximum-severity CVSS 10.0 vulnerability allows unauthenticated attackers to execute arbitrary code and is actively being exploited in the wild to drop Rust-based backdoors and PHP web shells on e-commerce sites.

CRITICAL#2

Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit

Threat actors are compromising F5 BIG-IP APM environments to deploy a sophisticated Linux rootkit that intercepts PHP file loading and injects a fileless web shell directly into memory, evading traditional disk-based security controls.

CRITICAL#3

Microsoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploited

Microsoft released its largest security update ever, patching 973+ vulnerabilities including 113 critical bugs and two actively exploited privilege-escalation zero-days, placing an unprecedented patch-management burden on enterprise IT teams.

CRITICAL#4

MikroTik Patches Critical Flaws Chained to Hack Routers

Dubbed 'MikroTrick', these vulnerabilities allow unauthenticated attackers to bypass authentication, overwrite configuration files, and take full control of RouterOS devices with SSH exposed to the internet.

■ CVEs IDENTIFIED

CVE-2026-75650

Adobe Commerce and Magento Open Source — Unauthenticated arbitrary code execution exploited in the wild to deploy backdoors and web shells.

Critical (CVSS 10.0)

[CVE-TBD]

Microsoft Windows — Two actively exploited privilege-escalation zero-day vulnerabilities patched in September 2026.

Critical

[CVE-TBD]

F5 BIG-IP APM — Vulnerability allowing unauthenticated attackers to breach devices and deploy a memory-resident Linux rootkit.

Critical

[CVE-TBD]

SAP Kernel — Extended Passport Processing vulnerability allowing unauthenticated remote command execution and secret recovery.

Critical

■ THREAT ACTORS

Slim Spider

Financially Motivated Threat Actor

Targeting Brazilian financial institutions since March 2026 to steal cryptocurrency custody secrets.

DoppelCart

Cybercrime Group

Operating a massive fraud network of over 119,000 fake e-shops to harvest and steal credit card details.

ShinyHunters

Extortion Gang

Claimed a breach of the Florida DMV "DAVID" database, allegedly exfiltrating over 200,000 driver records.

■ ATT&CK TTPs

T1190
Exploit Public-Facing Application | Exploitation of Adobe Commerce (CVE-2026-75650), F5 BIG-IP APM, and SAP Kernel vulnerabilities.
T1068
Exploitation for Privilege Escalation | Exploitation of two Windows zero-days and the FreeIPA anonymous admin credential flaw chain.
T1014
Rootkit | Linux rootkit deployed on compromised F5 BIG-IP APM devices.
T1027.002
Software Packing | Injection of fileless web shells directly into memory to avoid disk-based detection.
T1566
Phishing | Use of credential harvesting frameworks and fake e-shop domains by DoppelCart to steal sensitive data.
T1203
Exploitation for Client Execution | WeChat zero-click incoming call exploit triggering remote code execution on mobile devices.

■ PATCH PRIORITY

[P3 PATCH NOW]≤1 week

CRITICAL | Adobe Commerce and Magento Open Source — CVE-2026-75650 CVSS 10.0 zero-day is actively exploited to deploy Rust backdoors — SecurityWeek

[P3 PATCH NOW]≤1 week

CRITICAL | Microsoft Windows 10 & 11 — Two actively exploited privilege-escalation zero-days patched in record-breaking release — Recorded Future

[P3 PATCH NOW]≤1 week

CRITICAL | F5 BIG-IP APM — Active exploitation deploying fileless web shells and memory-resident Linux rootkits — BleepingComputer

[P3 PATCH NOW]≤1 week

CRITICAL | MikroTik RouterOS — "MikroTrick" vulnerability chain allows full device takeover without a password via exposed SSH — SecurityWeek

■ RECOMMENDED ACTIONS TODAY

1[P1] Immediately patch CVE-2026-75650 on all Adobe Commerce and Magento Open Source installations to prevent unauthenticated remote code execution and Rust backdoor deployment.
2[P1] Deploy Microsoft September 2026 Patch Tuesday cumulative updates (KB5122878 for Windows 10; KB5124008 and KB5122880 for Windows 11) to mitigate two actively exploited privilege-escalation zero-days.
3[P1] Audit and apply security updates to all F5 BIG-IP APM devices to defend against active memory-resident Linux rootkit and web shell injections.
4[P1] Apply MikroTik RouterOS patches to resolve the "MikroTrick" vulnerability chain, and immediately restrict or disable SSH access exposed to the public internet.
5[P2] Apply SAP Kernel security patches to mitigate the critical Extended Passport Processing vulnerability.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 10 Sep | Cisco Secure FMC Auth Bypass Actively Exploited Older → [SecurityIntel] 08 Sep | Active Zero-Day Exploitation of N-able and Adobe
Powered by Buttondown, the easiest way to start and grow your newsletter.