Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
On September 7, 2026, four active attack campaigns converge on widely deployed infrastructure, exposing a recurring deficit: patch availability does not guarantee actual protection. Google, CERT Polska, N-able, and Sansec have documented in-the-wild exploits against browsers, network appliances, IT management platforms, and e-commerce systems, with CVSS scores ranging from 8.8 to 10.0.
- Google patched CVE-2026-85046, a V8 type confusion with active exploitation, discovered on August 4 by Salvatore Gulizia: the sixth Chrome zero-day of 2026.
- CERT Polska detected the "MikroTrick" chain against RouterOS: authentication bypass and privilege escalation via CVE-2026-67276 and CVE-2026-86060, CVSS 9.2, originating from IP 82.192.72.4 since September 2.
- N-able released hotfixes for three CVEs in N-central, but Huntress documented compromise of a "fully patched" system on September 4, with unquantifiable impact.
- "StyleSmuggler" attacks on Magento/Adobe Commerce from September 4: injection via style properties, Rust backdoor with C2 99.84.67[.]186.
The Sixth Chrome Zero-Day of 2026: V8 Under Pressure
Google released Chrome 152.0.7977.82 fixing CVE-2026-85046, a type confusion vulnerability in the V8 JavaScript engine. The bug, discovered on August 4, 2026 by researcher Salvatore Gulizia, is actively exploited according to the cited source. The CVSS is 8.8.
The technical description from the source is unequivocal: "Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page." Execution remains confined to the sandbox, but the in-the-wild nature of the exploitation demands maximum update priority.
This is the sixth actively exploited zero-day vulnerability in Chrome since the start of 2026. The frequency suggests threat actors are investing in sustained research on the V8 engine, a critical component for the web ecosystem and Electron applications that embed it.
MikroTrick: When the Router Becomes a Bridge to the Internal Network
CERT Polska documented attacks against MikroTik RouterOS via an exploit chain dubbed MikroTrick. The technique combines two CVEs: CVE-2026-67276 and CVE-2026-86060, both with CVSS 9.2. The result is authentication bypass followed by privilege escalation.
Observed attacks originate from IP address 82.192.72.4 and have been ongoing since September 2, 2026. The source explicitly cites the creation of an "ops" account as an indicator of compromise. A second address, 103.102.31.18, was identified in the same campaign.
Patched versions according to the source are 6.49.21, 7.23.4, and 7.24.2. RouterOS is widely deployed in ISPs and critical infrastructure; compromise of these devices provides persistent positioning with visibility into network traffic, making patching urgent but technically complex for operators with thousands of remote appliances.
N-able: The Case of the "Fully Patched" Compromised System
N-able released hotfixes for three vulnerabilities in N-central: CVE-2026-86206 and CVE-2026-86207 (authentication bypass), CVE-2026-86218 (pre-authenticated remote code execution, CVSS 10.0). The maximum severity of the third CVE reflects the absence of authentication prerequisites for exploitation.
The data point that disrupts the conventional patching framework comes from Huntress: on September 4, 2026, researchers observed signs of active exploitation on an N-central system described as "fully patched." The source explicitly states the investigative limitation: "due to limited historical logging available directly on the appliance, we cannot definitively confirm which specific exploit the threat actor used to achieve their compromise, nor can we rule out the use of alternative vulnerabilities."
This uncertainty generates two non-mutually-exclusive scenarios: the presence of an additional, as-yet-unidentified zero-day, or a gap between patch release and actual application not reflected in logs. Both cases indicate that a declared "fully patched" state may not coincide with actual protection, especially when appliance logging limits forensic visibility.
StyleSmuggler: The Hidden Injection in Magento Templates
Sansec documented "StyleSmuggler" attacks against Magento and Adobe Commerce platforms beginning September 4, 2026. The technique exploits style properties in templates to inject malicious code, evading existing controls. The backdoor is written in Rust and communicates with command-and-control server 99.84.67[.]186.
The choice of Rust for the payload is significant: the language provides native binaries with a small footprint and resistance to conventional static analysis. Variants identified by the source operate under the names "fc-cache" and "chronyd," masquerading as legitimate system utilities. Impact is concentrated in the e-commerce sector, where checkout compromise can translate to payment data theft with prolonged latency before detection.
"StyleSmuggler injects malicious code into Magento's template system. By using the styles properties, it can evade existing safeguards" — Sansec
Why It Matters
The dossier does not document specific remedial measures beyond the release of the indicated patches. It does not specify the nature of data exposed in the N-able attacks nor the geographic extent of the MikroTik and Magento campaigns. The source does not clarify whether the N-able attacks represent a supply chain attack in the strict sense — upstream compromise propagating downstream — or rather direct exploitation of remotely accessible vulnerabilities.
A structural limitation emerges clearly: the term "Coder" present in the title of The Hacker News article finds no correspondence in the body text as a distinct verifiable event. The dossier does not allow establishing whether this is a separate incident, an editorial error, or a generic reference to the software development context. The editorial team does not reproduce this label as an independent fact.
Frequently Asked Questions
Does the N-able CVSS 10.0 imply automatic exploitation?
The maximum score reflects the combination of pre-authentication and RCE, but the source does not document the actual exploit complexity nor its quantifiable spread.
Why does Chrome already have six zero-days in 2026?
The frequency documented by the source indicates sustained offensive pressure on V8, but the dossier contains no comparative analysis with previous years nor attribution of the attacks.
What distinguishes StyleSmuggler from other Magento threats?
The specific use of style properties for injection and the Rust payload with masquerading as system utilities, according to Sansec's description reported by the source.
Sources
Information is based on the cited source and current as of publication.
Sources
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.