Week in Review: Sep 1-6, 2026
Seven days, two dozen disclosures, multiple confirmed exploitations. N-central, MikroTik, Chrome zero-day, and five more KEV additions. Here's the triage.
- N-central CVE-2026-86218 (CVSS 10.0, pre-auth RCE): exploited within 24 hours of disclosure. Patch to 2026.3.1.14. No workarounds.
- MikroTik SSH auth bypass confirmed exploited since September 2. Patch RouterOS 6.49.21, 7.23.4, or 7.24.2 for your branch.
- Chrome V8 CVE-2026-85046: zero-day actively exploited, patched September 4. Check your enterprise rollout lag.
- CISA added seven flaws to KEV on September 3 and four more across the week. AutoAgent, PaperCut, and Citrix NetScaler all confirmed exploited.
- IDScan breach: 153 million driver license records. JetBrains TeamCity CVE-2026-63077 breach confirmed.
N-central is under active attack. MikroTik is being hijacked. Chrome’s zero-day is actively exploited. This was not a quiet week. Here is the triage.
Management platforms: two dozen client networks at a time
MSP operators had the roughest week of the bunch.
CVE-2026-86218: CVSS 10.0, pre-authentication RCE in N-able N-central. N-able disclosed it September 6. Exploitation confirmed September 7. That is 24 hours from advisory to confirmed attacks. The original writeup has the full technical detail; the short version is: no credentials, no interaction, fully network-accessible static code injection. N-central manages script execution and patch scheduling across every managed client simultaneously, which is the threat model ransomware operators have been chasing in RMM platforms for years. Patch to 2026.3.1.14, System > Updates.
AutoAgent CVE-2026-86124: unauthenticated root RCE, CISA KEV-listed. Same class of problem, different product.
PaperCut: KEV-listed with confirmed active intrusions. Attackers used it to move into education networks and steal credentials from schools. If PaperCut is in your environment and you haven’t patched, assume it’s already been through.
Network edge: a rough week for perimeter devices
MikroTik SSH auth bypass: attacks confirmed since September 2. Unauthenticated full admin access over SSH. CERT Polska calls the flaw chain “MikroTrick.” No CVE assigned yet. Exploitation confirmed. Patch targets: RouterOS 6.49.21, 7.23.4, or 7.24.2 for your branch.
Cisco Nexus 9000 CVE-2026-20212: critical RCE in the switches that run most large datacenter fabrics. HPE ArubaOS-CX CVE-2026-73749: CVSS 9.8 RCE, same general concern. SonicWall SMA1000: two simultaneous zero-days with confirmed exploitation.
Citrix NetScaler CVE-2026-19490 landed on CISA KEV. The time from Citrix advisory to KEV listing has gotten short. Check your Citrix patching cadence accordingly.
Browser and endpoint
Chrome V8 CVE-2026-85046: zero-day, actively exploited, Google patched it September 4. If your enterprise Chrome rollout has any lag, pull that update now. Browser zero-days get used fast.
VMware Workstation and Fusion: critical RCE at the hypervisor layer, patched September 6. Developer workstations running VMware need this one.
Breaches
IDScan breach: 153 million driver license records. Government-issued ID data at that scale doesn’t expire as a risk. Fraud and impersonation vectors from this will surface well past the news cycle.
JetBrains TeamCity CVE-2026-63077: confirmed breach. CI/CD pipelines carry build secrets, signing keys, and deploy credentials. Attackers know this.
CISA KEV: September 3 batch and rolling additions
CISA added seven exploited flaws in a single batch on September 3, with more throughout the week. Confirmed among the September 3 additions: Sangoma Switchvox unauthenticated SQL injection CVE-2026-9586 (CVSS 9.8), with attackers deploying reverse shells against enterprise VoIP. Full list at cisa.gov/known-exploited-vulnerabilities-catalog.
Patch priority call
This week’s disclosures, ordered by urgency:
- N-central to 2026.3.1.14: confirmed exploitation, MSP-scope blast radius.
- MikroTik RouterOS to 6.49.21 / 7.23.4 / 7.24.2: confirmed exploitation since September 2.
- Chrome to current: zero-day in active use since at least September 4.
- SonicWall SMA1000, Citrix NetScaler CVE-2026-19490, AutoAgent CVE-2026-86124: all KEV-listed, all confirmed exploited.
- VMware Workstation/Fusion, Cisco Nexus 9000, HPE ArubaOS-CX: critical CVSS scores without confirmed exploitation in the wild as of Friday, but the week’s tempo argues against waiting.
Also noted
- Magento/Adobe Commerce unpatched zero-day: attackers are backdooring online stores. No vendor patch available as of Friday. Sansec reporting; temporary mitigations documented in their advisory.
- Sality botnet DOJ takedown: law enforcement action, September 2. The infrastructure is gone; the malware on already-infected machines is not.
- Nutex Health ransomware breach: healthcare, confirmed breach, September 2.
- OpenAI Astra critical cybersecurity threshold: analysis of the policy implications.