← All briefings

SAP NetWeaver Message Server · SAP Extended Passport Processing · Adobe Commerce / Magento Open Source

Date: 2026-09-08 Prepared for: SOC Analysts | Incident Responders | Vulnerability Management | Security Leadership

Executive Summary

Active exploitation continues against MikroTik RouterOS and Magento/Adobe Commerce, while reporting now indicates N-able N-central may also be exploited in the wild, although vendor statements are inconsistent. Newly published critical SAP vulnerabilities affect NetWeaver Message Server and Extended Passport processing, both potentially reachable over enterprise networks. A new ScreenConnect vulnerability is reportedly unpatched, increasing risk for remote-management environments.

Critical Vulnerabilities

CVE-2026-58240 — SAP NetWeaver Message Server

  • Severity: CVSS 9.8
  • EPSS: 0 — no exploitation probability currently reported
  • Technical detail: SAP NetWeaver Message Server insufficiently validates the authenticity of internal application-server components during registration. An unauthenticated attacker with network access to the affected Message Server may be able to register a rogue component and compromise message-server security assumptions. Exposure depends heavily on network reachability and Message Server access controls.
  • Exploitation status: No exploitation reported in the supplied intelligence.
  • Remediation: Apply the SAP security update immediately. Restrict Message Server ports to trusted application-server networks, verify registration and topology logs, and investigate unexpected component registrations.

CVE-2026-44756 — SAP Extended Passport Processing

  • Severity: CVSS 10.0
  • EPSS: 0 — no exploitation probability currently reported
  • Technical detail: A memory-safety vulnerability affects SAP Extended Passport processing across multiple SAP kernel and Web Dispatcher-related versions. A crafted network request may trigger memory corruption; the supplied description does not establish whether code execution is possible in every affected deployment. Internet exposure of SAP Web Dispatcher or other components processing EPP data would increase risk.
  • Exploitation status: No exploitation reported in the supplied intelligence.
  • Remediation: Apply the applicable SAP kernel and component fixes. Identify all affected versions, restrict exposed SAP services, and monitor for malformed requests, crashes and unexpected child processes.

CVE-2026-75650 — Adobe Commerce / Magento Open Source

  • Severity: CVSS 10.0
  • EPSS: 0 — no exploitation probability currently reported
  • Technical detail: Improper neutralization in a template engine can result in arbitrary code execution in the context of the current user. Affected Adobe Commerce and Magento Open Source branches include multiple 2.4.x releases. This vulnerability should be assessed alongside the separately reported StyleSmuggler exploitation affecting Magento and Adobe Commerce; the supplied data does not explicitly confirm that the campaign uses this CVE.
  • Exploitation status: Active exploitation of a Magento/Adobe Commerce zero-day campaign has been reported; linkage to this CVE is unconfirmed.
  • Remediation: Apply the vendor fix or supported security update. If immediate patching is unavailable, restrict administrative access, deploy vendor mitigations and inspect web roots, payment templates, administrator accounts, cron jobs and outbound connections for compromise.

CVE-2026-86218 — N-able N-central

  • Severity: CVSS 10.0
  • EPSS: 0 — no exploitation probability currently reported
  • Technical detail: N-central versions before 2026.3.1.14 contain a pre-authentication RCE vulnerability in a remote-management platform with privileged access to managed endpoints. N-able has issued multiple hotfixes; reporting states that the flaw may have been exploited in the wild, while release notes describe exploitation as unconfirmed.
  • Exploitation status: STATUS CHANGE — possible active exploitation reported; confidence is limited because vendor communications are inconsistent.
  • Remediation: Upgrade to 2026.3.1.14 or later, including the latest required hotfix. Restrict N-central access to trusted networks, review server and agent activity, and investigate unexpected scripts, policies, commands or endpoint changes originating from N-central.

CVE-2026-86480 — JetBrains Hub

  • Severity: CVSS 9.8
  • EPSS: 0 — no exploitation probability currently reported
  • Technical detail: JetBrains Hub versions before 2026.2.52442 allow an unauthenticated attacker to register a trusted service and obtain superuser privileges. Internet-accessible Hub instances are particularly exposed because the attack does not require prior authentication.
  • Exploitation status: No exploitation reported in the supplied intelligence.
  • Remediation: Upgrade to 2026.2.52442 or later. Restrict Hub administration to trusted networks, review service registrations and superuser activity, and rotate credentials or tokens if unauthorized access is suspected.

ONGOING

  • CVE-2026-86060 (MikroTik RouterOS): actively exploited with persistence-account creation; patch immediately and investigate accounts, SSH keys and configuration changes.
  • CVE-2026-85046 (Chromium V8): actively exploited and KEV-listed; complete browser deployment.
  • CVE-2026-63520 (Microsoft SharePoint): active exploitation and public PoC remain reported; hunt for web shells.
  • CVE-2026-19490 (Citrix NetScaler): attacks remain reported; verify patching and management-interface restrictions.
  • CVE-2026-81578 / CVE-2026-82078 (PaperCut): exploitation remains reported; remediate before the 2026-09-14 KEV deadline.
  • CVE-2026-83548 / CVE-2026-83549 (SonicWall SMA1000), CVE-2026-0768 (Langflow) and remaining listed KEV items: remediation remains required.

European Advisories

CERT-Bund/BSI issued a new critical MikroTik RouterOS advisory covering remote, unauthenticated takeover, information disclosure, security-control bypass and denial-of-service impacts. This supports the active exploitation assessment in Critical Vulnerabilities.

WID-SEC-2026-3205 (N-able N-central): covered in Critical Vulnerabilities. The advisory states that remote unauthenticated attackers may disclose information, bypass protections or execute code.

WID-SEC-2026-3212 (SmarterTools SmarterMail) reports authenticated path traversal and potential access to administrative tokens and cached authentication data. Prioritize internet-facing mail servers and review mailbox, API and authentication logs.

WID-SEC-2026-3210 (OpenCTI) reports code execution, SSRF to internal services or cloud metadata, and unauthorized deletion of draft workspaces. Patch exposed OpenCTI deployments and restrict outbound access.

WID-SEC-2026-3207 (Snipe-IT), WID-SEC-2026-3200 (Froxlor) and WID-SEC-2026-3196 (rclone) are new high-severity advisories requiring product-specific update and access-control review.

Citrix NetScaler, Linux kernel, Windows, Chrome and Firefox advisories were updated without a material development beyond previously reported remediation.

Active Threats and Campaigns

  • Magento/Adobe Commerce StyleSmuggler — STATUS CHANGE: Multiple sources report active exploitation of a Magento/Adobe Commerce zero-day to deploy a Linux backdoor. Hunt for modified storefront or payment files, new administrator accounts, web shells, suspicious cron jobs and unexpected outbound traffic. BleepingComputer
  • MikroTik RouterOS — ONGOING: Internet-exposed SSH services are being exploited for router takeover and persistence through new accounts. Heise
  • ScreenConnect — NEW: A newly reported remote-access vulnerability is currently without a vendor patch. Apply temporary mitigations, restrict exposure and monitor newly connected hosts for unauthorized scripts. BleepingComputer
  • TerminalFix, ClickFix, RMM phishing, developer supply-chain compromise and Virtualizor malicious updates — ONGOING: No material new development supplied.

Security News and Context

  • Researchers reported PEEP, a post-compromise Chromium extension that can turn Chrome or Edge into a command-execution backdoor after administrative or code-execution access is obtained. The Hacker News
  • A Microsoft 365 phishing operation using help-desk vishing, adversary-in-the-middle token theft and residential proxies reportedly targeted executives. The Hacker News
  • The UK NCSC highlighted risks from unapproved “shadow AI” tools, particularly data leakage and unmanaged access to organizational information. NCSC
  1. Patch SAP NetWeaver Message Server and affected SAP kernel/EPP components; restrict Message Server exposure.
  2. Patch or isolate Magento/Adobe Commerce and perform compromise hunting for StyleSmuggler-related backdoors.
  3. Upgrade N-central to 2026.3.1.14 or later and audit all management actions.
  4. Patch MikroTik RouterOS; enumerate users, SSH keys, firewall rules and configuration changes.
  5. Patch JetBrains Hub and review trusted-service registrations and superuser activity.
  6. Apply ScreenConnect mitigations and block unnecessary internet exposure pending the vendor patch.
  7. Review BSI advisories for SmarterMail, OpenCTI, Snipe-IT and Froxlor applicability.
  8. Continue remediation of previously reported items: Chromium V8, SharePoint, Citrix NetScaler, PaperCut, SonicWall SMA1000, Langflow and remaining KEV entries.