The Exploit Bulletin

Archives
Log in
Subscribe
September 25, 2026

The Exploit Bulletin — Friday, September 25, 2026: 3 issues require action

Friday, September 25, 2026 — 3 issues require action. If you run none of the software below, you are done.

Affects: Microsoft SharePoint · Adobe Commerce / Magento Open Source · Roundcube Webmail


1. Code injection in on-premises SharePoint Server gives remote code execution (CVE-2026-65660)

REMOTE CODE EXECUTION · CRITICAL · CVSS 8.8

The Canadian Centre for Cyber Security issued alert AL26-023 on 2026-09-24 stating it is aware of active exploitation of this CVE, and servers still on pre-August builds are exposed to server-side code execution.

A code-injection flaw in SharePoint Server lets an attacker with low-level access send a crafted request that executes code on the server; a Viettel write-up (not independently verified here) claims the required access can be reached from anonymous access, making the effective bar lower than the CVSS PR:L suggests. Patched in the August 2026 SharePoint security updates.

Affected: SharePoint Enterprise Server 2016 < 16.0.5565.1001; SharePoint Server 2019 < 16.0.10417.20198; SharePoint Server Subscription Edition < 16.0.19725.20522

How to Test: Check the farm build in Central Administration (Servers in Farm / Manage Patch Status): 2016 below 16.0.5565.1001, 2019 below 16.0.10417.20198, or Subscription Edition below 16.0.19725.20522 is vulnerable. Review IIS and ULS logs for unexpected crafted requests from anonymous or low-privilege accounts, and check for unfamiliar .aspx or other files dropped in the SharePoint web roots and layouts directories since August.

How to Patch: Install all August 2026 (or later) SharePoint security updates offered for your version so the build reaches 16.0.5565.1001 (2016), 16.0.10417.20198 (2019) or 16.0.19725.20522 (Subscription Edition); Microsoft notes multiple packages may apply and all must be installed. Where patching must wait, restrict internet access to the server and disable anonymous access.

Evidence: VulnCheck KEV · Canadian Centre for Cyber Security AL26-023: aware of active exploitation

Full entry with sources →


2. Unauthenticated incorrect-authorization flaw in Adobe Commerce and Magento Open Source exposes restricted resources (CVE-2026-71362)

CISA KEV (due 2026-09-27) · AUTHENTICATION BYPASS · CRITICAL · CVSS 9.1

CISA added this flaw to the KEV catalog on 2026-09-24 with a 2026-09-27 remediation deadline, VulnCheck lists a public exploit in XDB, and storefronts still on the July/August 2026 patch levels remain exposed to unauthenticated access to restricted data.

An incorrect authorization check in Adobe Commerce, Commerce B2B, and Magento Open Source lets a remote attacker with no credentials and no user interaction gain elevated access to sensitive resources over the network. The CVSS 9.1 vector rates confidentiality and integrity impact as high.

Affected: Adobe Commerce <= 2.4.9-2026-jul; Adobe Commerce <= 2.4.8-2026-aug; Adobe Commerce <= 2.4.7-2026-aug; Adobe Commerce <= 2.4.6-2026-aug; Adobe Commerce <= 2.4.5-2026-aug; Adobe Commerce <= 2.4.4-2026-aug; Adobe Commerce B2B <= 1.5.3-2026-jul; Adobe Commerce B2B <= 1.5.2-2026-jul; Adobe Commerce B2B <= 1.4.2-2026-jul; Adobe Commerce B2B <= 1.3.4-2026-jul; Adobe Commerce B2B <= 1.3.3-2026-jul; Adobe Magento Open Source <= 2.4.9-2026-jul; Adobe Magento Open Source <= 2.4.8-2026-jul; Adobe Magento Open Source <= 2.4.7-2026-jul; Adobe Magento Open Source <= 2.4.6-2026-jul

How to Test: Check the installed Adobe Commerce / Magento Open Source / Commerce B2B version and security-patch level against the affected list: anything at or before the 2026-jul (Magento Open Source, B2B, Commerce 2.4.9) or 2026-aug (Commerce 2.4.4–2.4.8) patch levels is vulnerable. Because exploitation requires no authentication, review web server access logs and Commerce admin/API logs for unauthenticated requests reaching restricted resources or admin functionality, and audit for unexpected admin accounts, API integrations, or configuration changes since the August 2026 disclosure.

How to Patch: Install the security update published in Adobe advisory APSB26-92 for your Adobe Commerce, Commerce B2B, or Magento Open Source release line; the 2026-jul and 2026-aug patch levels listed above remain vulnerable and must be superseded by the APSB26-92 release. If the update cannot be applied immediately, restrict network access to the storefront's admin and API paths until it is.

Evidence: CISA KEV · VulnCheck KEV · CISA SSVC: active · CISA alert: added based on evidence of active exploitation · Canadian Centre for Cyber Security AV26-808 Update 2 (2026-09-24) · Trellix Bug Report August 2026 (cited by VulnCheck KEV)

Full entry with sources →


3. Pre-authentication SQL injection in Roundcube Webmail virtuser_query plugin (CVE-2026-48842)

DATA EXPOSURE · HIGH · CVSS 8.1

The Canadian Centre for Cyber Security updated its advisory on 2026-09-21 to report exploitation, with BleepingComputer and SecurityWeek amplifying it this week; installations that skipped the May updates and use virtuser_query are exposed to unauthenticated database compromise.

A preg_replace() backslash escape bypass in Roundcube's virtuser_query plugin allows SQL injection before login, giving an unauthenticated attacker read/write access to the webmail database (accounts, identities, session data) on installations that use that plugin. Fixed in 1.6.16 and 1.7.1, released 2026-05-24.

Affected: Roundcube Webmail 1.6.0 through 1.6.15; Roundcube Webmail 1.7.0

How to Test: Confirm the installed Roundcube version is below 1.6.16 (1.6 LTS) or below 1.7.1 (1.7), and check whether the virtuser_query plugin is enabled in your configuration — only those deployments are reachable by this bug. Review webmail access logs and login records for pre-auth login attempts whose username/email fields contain backslashes or SQL syntax, and audit the users and identities tables for unexpected entries.

How to Patch: Upgrade to Roundcube 1.6.16 or 1.7.1 (or the current 1.6.19 / 1.7.4). If the upgrade must wait, disable the virtuser_query plugin until it is applied.

Evidence: VulnCheck KEV · Canadian Centre for Cyber Security AV26-503 Update 1 (2026-09-21) · BleepingComputer: exploitation reported per Cyber Centre

Full entry with sources →


Read on the web · Every past edition

The Exploit Bulletin is free and daily. It publishes only what security teams must act on today — nothing else. Forward it freely.

Spot an error, or an exploit we missed? Reply here or email [email protected].

Don't miss what's next. Subscribe to The Exploit Bulletin:
← Newer The Exploit Bulletin — Saturday, September 26, 2026: all clear Older → The Exploit Bulletin — Thursday, September 24, 2026: 6 issues require action
www.exploitbulletin.com
jbac.co
LinkedIn
Powered by Buttondown, the easiest way to start and grow your newsletter.