Sep 7: N-central Exploited, MikroTik Hijacked
N-central CVE-2026-86218 under active attack. MikroTik SSH bypass exploited since September 2. JSCeal steals session cookies. WordPress auth bypass CVSS 9.8.
- N-central CVE-2026-86218 (CVSS 10.0, pre-auth RCE) is under active attack. Exploitation confirmed within 24 hours of N-able's disclosure. Patch to version 2026.3.1.14.
- MikroTik SSH auth bypass: CERT Polska confirms router hijacking attacks since September 2. Patch RouterOS to 6.49.21, 7.23.4, or 7.24.2 for your branch.
- JSCeal: compiled V8 malware with confirmed credential theft and Google session cookie bypass. Distribution vector unconfirmed. No CVE assigned.
- CVE-2026-75816 (WordPress Frontend Admin, CVSS 9.8): unauthenticated account takeover on all versions through 3.29.12. No confirmed exploitation in the wild.
Exploitation confirmed on two fronts. Multiple critical patches are pending across network edge devices and management platforms.
N-central CVE-2026-86218: active exploitation, 24 hours after disclosure
CVE-2026-86218 is under active attack. BleepingComputer confirmed attacks on September 7. The flaw is a pre-authentication remote code execution in N-able N-central: CWE-96 static code injection, CVSS 4.0: 10.0, no credentials required, no user interaction, fully network-accessible. N-able disclosed it September 6.
Time from disclosure to confirmed exploitation: one day.
N-central manages the operational layer of MSP infrastructure. Script execution, patch scheduling, and remote control of every managed endpoint run through it. Attacker access to N-central means attacker access across every client simultaneously. This is the threat model ransomware operators have been targeting in RMM platforms for years. N-able saw this pattern in August with CVE-2026-18577, an earlier N-central auth bypass added to CISA KEV after confirmed exploitation. That is two critical pre-auth vulnerabilities in eight weeks.
No workarounds exist. Patch to version 2026.3.1.14 (System > Updates). Full details: N-central Under Active Attack: Patch CVE-2026-86218 Now.
MikroTik SSH auth bypass: router hijacking confirmed since September 2
CERT Polska confirmed that attackers have been hijacking MikroTik routers since at least September 2 via a two-flaw chain, nicknamed “MikroTrick,” that allows unauthenticated full administrative access over SSH. A patch has been available since late August. No CVE assigned. Exploitation confirmed regardless.
Patch targets: RouterOS 6.49.21 (6.x branch), 7.23.4 or 7.23.5 (7.x long-term branch), 7.24.2 (7.24.x branch). RouterOS runs a compromise check automatically after patching. If the device flags itself, audit for unknown users and configuration changes before returning it to service. Patch steps and post-compromise guidance.
JSCeal: compiled V8 bytecode, session cookie replay confirmed
JSCeal is a credential-harvesting malware compiled as V8 JavaScript bytecode (.jsc format). Researchers confirmed: credential theft, traffic interception, and Google Authentication bypass via session cookie replay. That bypass is not a flaw in Google’s systems. It is the same technique all session-cookie-issuing services face: exfiltrate the cookie before it expires and the attacker holds a valid authenticated session, with MFA already past.
Distribution vector: unconfirmed. Sector or geographic targeting: unconfirmed. No CVE. No CISA advisory as of this briefing. Confidence on capabilities: high, per researcher reporting. Full writeup.
Also noted
- CVE-2026-75816 (WordPress Frontend Admin by DynamiApps, CVSS 9.8): unauthenticated account takeover, all versions through 3.29.12. Update the plugin. No confirmed exploitation in the wild. Details.
- VMware Workstation and Fusion (September 6): critical RCE patched. Coverage.
- AutoAgent CVE-2026-86124: unauthenticated root RCE, CISA KEV-listed. Coverage.
- JetBrains TeamCity CVE-2026-63077: breach confirmed. Coverage.
- Magento/Adobe Commerce: unpatched zero-day used to backdoor online stores, Dutch e-commerce security firm Sansec reporting. Coverage.