The Exploit Bulletin

Archives
Log in
Subscribe
September 9, 2026

The Exploit Bulletin — Wednesday, September 9, 2026: 4 issues require action

Wednesday, September 9, 2026 — 4 issues require action. If you run none of the software below, you are done.

Affects: FortiOS · FortiSwitchManager · Siemens RUGGEDCOM APE1808 with Fortinet NGFW · Adobe Commerce · Magento Open Source · ConnectWise ScreenConnect Support and Access sessions · Commvault Cloud


1. Heap-based buffer overflow in FortiOS and FortiSwitchManager allows unauthenticated code execution (CVE-2025-25249)

REMOTE CODE EXECUTION · CRITICAL · CVSS 7.4

The CVE was added to VulnCheck's known-exploited catalog on 2026-09-08 with a report of a purpose-built FortiGate RAT being planted on unpatched devices, so any FortiGate or FortiSwitchManager still on an affected build should be updated as an emergency change rather than in the next window.

A heap overflow reachable via specially crafted packets lets an attacker execute unauthorized code or commands on FortiOS and FortiSwitchManager devices without credentials. Reporting describes compromised devices being fitted with a Node.js post-exploitation RAT (PivotC2).

Affected: FortiOS 7.6.0–7.6.3; FortiOS 7.4.0–7.4.8; FortiOS 7.2.0–7.2.11; FortiOS 7.0.0–7.0.17; FortiOS 6.4 (all versions); FortiSwitchManager 7.2.0–7.2.6; FortiSwitchManager 7.0.0–7.0.5; Siemens RUGGEDCOM APE1808 with Fortinet NGFW < V7.4.9

How to Test: Not specified.

How to Patch: Upgrade FortiOS/FortiGate NGFW to a fixed build (Siemens directs RUGGEDCOM APE1808 users to Fortinet NGFW V7.4.9 or later) and FortiSwitchManager beyond the affected 7.0.x/7.2.x ranges, following FG-IR-25-084. Where an upgrade cannot be applied immediately, apply the per-interface configuration mitigation described in FG-IR-25-084 / Siemens SSA-864900 and remove management interfaces from untrusted networks.

After patching, treat previously exposed devices as potentially compromised: review admin accounts, VPN configuration and scheduled tasks for unauthorised changes and look for unexpected Node.js processes or outbound C2 connections.

Check the running version with get system status on FortiOS and compare against the affected ranges above.

Also audit device logs for unexplained crashes or restarts of the affected daemon, which reporting associates with exploitation attempts.

Finally, rotate device credentials and certificates on any appliance that ran an affected build while reachable from the internet.

See FG-IR-25-084 for the vendor's mitigation text.

(If you cannot upgrade, restrict packet-level access to the affected service to trusted management networks.)

Evidence: VulnCheck KEV

Full entry with sources →


2. Unauthenticated template-injection RCE in Adobe Commerce and Magento Open Source, dubbed StyleSmuggler

CISA KEV (due 2026-09-11) · REMOTE CODE EXECUTION · CRITICAL · CVSS 10.0

Adobe shipped the APSB26-146 fix on 2026-09-07 and CISA added the flaw to KEV on 2026-09-08 with a 2026-09-11 deadline after attackers were seen using it to drop a PHP web shell and Rust backdoor on unpatched stores, so any storefront still on a pre-fix build should be treated as reachable by unauthenticated attackers right now.

A template-engine injection flaw (improper neutralization of special elements) lets an unauthenticated remote attacker execute arbitrary code on an Adobe Commerce or Magento Open Source server with no user interaction. Reported attacks deployed a PHP web shell and a Rust backdoor on compromised stores.

Affected: Adobe Commerce < 2.4.4; Adobe Commerce 2.4.4, 2.4.5, 2.4.6, 2.4.7, 2.4.8, 2.4.9 (through the 2026-aug security patch level); Adobe Commerce B2B < 1.3.3, 1.3.3, 1.3.4; Magento Open Source (same 2.4.x lines)

How to Test: Confirm the installed Commerce/Magento version and security-patch level against the APSB26-146 advisory; any 2.4.4–2.4.9 install at or below the 2026-aug patch level without the CVE-2026-75650 hotfix is vulnerable. Because attacks predate the patch (reported from September 4), review the web root and pub/ directories for recently created or modified PHP files, check for unexpected running binaries or persistence consistent with the reported Rust backdoor, and review web server access logs for unusual POST requests to storefront endpoints around and after 2026-09-04.

How to Patch: Apply the Adobe security update or hotfix published in APSB26-146 (https://helpx.adobe.com/security/products/magento/apsb26-146.html) for your 2.4.x line and the B2B extension; Adobe Commerce cloud customers should confirm the fix is deployed on their environment. If you cannot patch immediately, restrict public access to the storefront (WAF or network controls) until the update is applied, and treat any host that was exposed unpatched since 2026-09-04 as potentially compromised pending forensic review.

Evidence: CISA KEV · VulnCheck KEV · CISA SSVC: active · CISA adds CVE-2026-75650 to KEV based on evidence of active exploitation · Tenable: StyleSmuggler exploited since September 4, before patch · The Hacker News: zero-day exploited to deploy Rust backdoor and PHP web shell

Full entry with sources →


3. ScreenConnect client transfers and executes files in an active session without authorization (CVE-2026-84869)

REMOTE CODE EXECUTION · CRITICAL · CVSS 9.9

ConnectWise shipped the 26.6.5 fix on 2026-09-08 and Huntress reports rogue ScreenConnect installations spreading across unrelated hosts, so unpatched clients can have files pushed and run on them during a session with no host prompt.

A missing-authorization condition in the ScreenConnect client lets file-transfer and file-execution actions be processed through an active remote session without Host confirmation, giving code execution on the endpoint. ScreenConnect servers themselves are not affected, but every client and access agent built from a pre-26.6.5 release is.

Affected: ConnectWise ScreenConnect (CW Remote Access) Support and Access sessions, all versions prior to 26.6.5 — cloud and on-premise

How to Test: Compare your ScreenConnect version against 26.6.5 and confirm that host clients and access agents have been reinstalled/updated after the upgrade; in Administration > Security > Roles, check which session groups still grant TransferFiles (TransferFIlesInSession on legacy versions). Hunt for unexpected or duplicate ScreenConnect client installations on unrelated hosts and for files written and executed during recent remote sessions, per the Huntress write-up.

How to Patch: On-premise: upgrade to ScreenConnect 26.6.5 from the vendor download page (a current maintenance licence is required). Cloud: no server action is needed, but reinstall host clients and update access agents so endpoints run the patched client. As an interim measure that needs no upgrade, edit each role under Administration > Security > Roles and deselect the TransferFiles permission (TransferFIlesInSession on legacy versions) for every session group that has it.

Evidence: VulnCheck KEV · Huntress: rogue ScreenConnect installations across unrelated hosts suggest worm-like activity (2026-09-08) · Vendor confirmed

Full entry with sources →


4. Command Center API authentication bypass, fixed builds available (Commvault Cloud)

UNVERIFIED PUBLIC REPORT · NO CVE · AUTHENTICATION BYPASS · CRITICAL

The Cyber Centre published AV26-895 on 2026-09-08 pointing at Commvault bulletin CV_2026_07_1, a Command Center API authentication bypass with fixed builds already available; backup platforms are a prime ransomware precursor target, so an unauthenticated bypass on the management API warrants same-day patching.

Commvault's bulletin CV_2026_07_1, relayed by the Canadian Centre for Cyber Security as AV26-895, describes an authentication bypass in the Command Center API of Commvault Cloud 11.36, 11.40, 11.44 and 11.46 feature releases prior to the listed maintenance builds. An attacker who can reach the Command Center API could act without valid credentials on the backup control plane. No CVE, CVSS score or statement about exploitation appears in the advisory text, and the bulletin's technical details were not retrieved in this pass.

Affected: Commvault Cloud 11.36.0 prior to 11.36.123, 11.40.0 prior to 11.40.72, 11.44.0 prior to 11.44.20, 11.46.0 prior to 11.46.20

How to Test: In Command Center, check the installed version (About / CommServe version). Any 11.36.x below 11.36.123, 11.40.x below 11.40.72, 11.44.x below 11.44.20 or 11.46.x below 11.46.20 is affected. Confirm from the network whether the Command Center web/API ports are reachable from untrusted segments or the internet.

How to Patch: Apply the maintenance release for your feature release: 11.36.123, 11.40.72, 11.44.20 or 11.46.20 or later, as listed in Commvault's CV_2026_07_1. If you cannot update today, place the Command Center API behind a VPN or allowlist and audit recent API activity for sessions from unexpected sources.

Evidence: Canadian Centre for Cyber Security advisory AV26-895

Full entry with sources →


Read on the web · Every past edition

The Exploit Bulletin is free and daily. It publishes only what security teams must act on today — nothing else. Forward it freely.

Spot an error, or an exploit we missed? Reply here or email [email protected].

Don't miss what's next. Subscribe to The Exploit Bulletin:
Older → The Exploit Bulletin — Tuesday, September 8, 2026: all clear
www.exploitbulletin.com
jbac.co
LinkedIn
Powered by Buttondown, the easiest way to start and grow your newsletter.