NEC UNIVERGE IX-R/IX-V · N-able N-central · OpenMAIC
Date: 2026-09-07 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership
Executive Summary
New high-impact exposure affects NEC UNIVERGE IX-R/IX-V routers, with an authentication bypass reportedly enabling unauthenticated CLI command execution. N-able also disclosed a separate pre-authentication remote-code-execution vulnerability in N-central, requiring immediate management-platform review. MikroTik RouterOS exploitation has materially escalated: attacks reportedly began by at least 2 September and include creation of persistence accounts. New high-severity vulnerabilities also affect OpenMAIC, PostgreSQL Anonymizer and several WordPress plugins.
Critical Vulnerabilities
CVE-2026-16876 — NEC UNIVERGE IX-R/IX-V
- Severity: CVSS 9.3
- EPSS: Not available
- Technical detail: An authentication-bypass vulnerability in the WebGUI allows an attacker to tamper with WebGUI messages and execute arbitrary CLI commands. Affected versions include UNIVERGE IX-R/IX-V releases within the specified Ver1.1–Ver1.5 branches. Internet exposure of router administration interfaces substantially increases risk.
- Exploitation status: No exploitation was confirmed in the supplied intelligence.
- Remediation: Apply the vendor-fixed release when available, or isolate affected management interfaces immediately. Restrict WebGUI access to trusted administration networks, disable external access and review configuration, administrator and command-execution logs for unauthorized changes.
CVE-2026-86218 — N-able N-central
- Severity: CVSS 10.0
- EPSS: 0 — no exploitation probability currently reported
- Technical detail: N-central versions before 2026.3.1.14 contain a pre-authentication remote-code-execution vulnerability. The flaw affects a remote-management platform with privileged access to managed endpoints, making compromise potentially high impact even where the N-central console itself is not directly internet-facing.
- Exploitation status: No exploitation was reported in the supplied intelligence.
- Remediation: Upgrade to N-central 2026.3.1.14 or later. Confirm that management services are restricted to trusted networks, inspect authentication and API telemetry, and investigate unexpected commands, policies, scripts or endpoint changes originating from N-central.
CVE-2026-86259 — OpenMAIC
- Severity: CVSS 9.0
- EPSS: Not available
- Technical detail: OpenMAIC versions before 1.0.1 fail to enforce server-side request-forgery validation in non-production builds. An unauthenticated attacker can potentially reach cloud instance-metadata services through crafted requests, risking exposure of cloud credentials and instance information. Deployments using non-production configuration in reachable environments are particularly concerning.
- Exploitation status: No exploitation was reported in the supplied intelligence.
- Remediation: Upgrade to version 1.0.1 or later and ensure production validation controls are enabled. Restrict access to the service, block unnecessary metadata-service access from workloads and review cloud audit logs for anomalous metadata queries or credential use.
CVE-2026-19633 — PostgreSQL Anonymizer
- Severity: CVSS 8.8
- EPSS: Not available
- Technical detail: PostgreSQL Anonymizer versions before 3.1.4 allow unprivileged masked users to execute arbitrary code through operators, domain casts or view subqueries containing untrusted expressions. Successful exploitation may result in code execution under the operating-system account running PostgreSQL. Risk depends on access to affected anonymized database functionality.
- Exploitation status: No exploitation was reported in the supplied intelligence.
- Remediation: Upgrade to version 3.1.4 or later. Review roles with masked-user access, restrict untrusted SQL and inspect database and host telemetry for unexpected function execution, process creation or outbound connections.
CVE-2026-75816 — Frontend Admin by DynamiApps
- Severity: CVSS 9.8
- EPSS: Not available
- Technical detail: The WordPress plugin through version 3.29.12 contains an authentication-bypass condition that can lead to account takeover. Internet-facing WordPress sites using the plugin may be exposed to unauthorized administrative access and subsequent content or server compromise.
- Exploitation status: No exploitation was reported in the supplied intelligence.
- Remediation: Upgrade to a fixed release when available or disable/remove the plugin. Review WordPress authentication events, newly created administrator accounts, password-reset activity and modified PHP files; rotate credentials if compromise is suspected.
Status change
CVE-2026-86060(MikroTik RouterOS): exploitation is reportedly active, including unauthorized account creation for persistence; patch immediately, restrict SSH/WebFig and investigate all affected routers.
ONGOING
CVE-2026-85046(Chromium V8): actively exploited and KEV-listed; complete browser patch deployment and endpoint hunting.CVE-2026-63520(Microsoft SharePoint): active exploitation and public PoC remain reported; patch and inspect for web shells.CVE-2026-19490(Citrix NetScaler): attacks remain reported; verify patching and management-interface restrictions.CVE-2026-81578/CVE-2026-82078(PaperCut): exploitation remains reported; patch before the 2026-09-14 KEV deadline.CVE-2026-83548/CVE-2026-83549(SonicWall SMA1000): active exploitation remains reported; patch and assess for compromise.CVE-2026-0768(Langflow): active exploitation remains reported; upgrade and rotate exposed credentials.CVE-2026-60004,CVE-2026-49869,CVE-2026-82329andCVE-2026-9586: KEV remediation remains required.
European Advisories
CVE-2026-16876 (NEC UNIVERGE IX-R/IX-V), CVE-2026-86218 (N-able N-central), CVE-2026-86259 (OpenMAIC), CVE-2026-19633 (PostgreSQL Anonymizer) and CVE-2026-75816 (Frontend Admin) are newly listed in EUVD data and are covered in Critical Vulnerabilities.
CERT-PL reporting on MikroTik RouterOS remains operationally significant: exploitation of CVE-2026-86060 is now supported by reporting from SANS ISC and The Hacker News. Treat internet-exposed management services as compromised until investigated.
No new BSI WID or CERT-EU advisory was supplied for the reporting period. The BSI TerminalFix advisory remains relevant to German public-sector defenders but has no reported material change.
Active Threats and Campaigns
- MikroTik RouterOS exploitation — STATUS CHANGE: Attackers have reportedly exploited internet-reachable SSH services since at least 2 September, obtaining administrative control and creating accounts to preserve access after patching. Hunt for newly created users, altered SSH keys, policy changes, unexpected firewall rules and anomalous outbound traffic. Source: SANS ISC.
- TerminalFix — ONGOING: The BSI-linked compromise campaign targeting a German institution remains relevant; ransomware installation was reportedly attempted. Validate endpoint and identity telemetry for the previously reported campaign indicators.
- Magento/Adobe Commerce StyleSmuggler — ONGOING: Unauthenticated exploitation of online stores remains reported; inspect storefronts for web shells, altered payment pages, rogue accounts and suspicious outbound connections.
- ClickFix, Ted/curlRAT, RMM phishing, developer supply-chain compromise and Virtualizor malicious updates — ONGOING: No material new development supplied.
Security News and Context
- A reported cyberattack against Berlin’s administration may have exposed approximately 1.44 million files, with additional impact still being assessed. German organizations should monitor for released credentials and sensitive documents. Heise
- Security reporting continues to highlight MikroTik router takeover through internet-exposed SSH, including persistence through newly created accounts. The Hacker News
Recommended Actions
- Patch or isolate NEC UNIVERGE IX-R/IX-V devices; remove WebGUI exposure from the internet.
- Upgrade N-central to
2026.3.1.14or later and audit privileged management activity. - Patch MikroTik RouterOS immediately; enumerate accounts, keys and configuration changes.
- Patch OpenMAIC and block workload access to cloud instance-metadata services where unnecessary.
- Upgrade PostgreSQL Anonymizer and review masked-user roles and database execution telemetry.
- Disable or update Frontend Admin by DynamiApps and hunt for WordPress account takeover.
- Investigate Berlin-related exposure where relevant to organizational data or personnel.
- Continue remediation of previously reported items: Chromium V8, SharePoint, Citrix NetScaler, PaperCut, SonicWall SMA1000, Langflow and remaining KEV entries.