Threat Brief — 2026-09-07 — Exploit chains and KEV additions accelerate
Executive summary: Several actively exploited vulnerability chains are reaching maturity simultaneously. A public proof-of-concept turns a Telerik UI padding-oracle flaw into unauthenticated RCE, while Chrome's V8 zero-day CVE-2026-85046KEV has been added to CISA's Known Exploited Vulnerabilities catalog. ConnectWise ScreenConnect worm-like activity and MikroTik RouterOS exploitation both remain unpatched or under active attack. On the data-breach front, Mathspace disclosed theft of over one million records via a compromised Metabase instance.
Top items
- Telerik UI padding-oracle chained to unauthenticated RCE; public exploit released. A proof-of-concept from TantoSec demonstrates that an AES-CBC padding-oracle weakness in Telerik UI for ASP.NET AJAX can be chained into unauthenticated remote code execution against applications in a specific non-default configuration. Progress has shipped a patch. Organisations running Telerik UI for ASP.NET AJAX should verify whether their deployment matches the vulnerable configuration and apply the vendor fix. (src: The Hacker News)
- Chrome V8 zero-day CVE-2026-85046KEV now in CISA KEV — known exploited in the wild. Google's Chrome update patches 12 vulnerabilities including this actively exploited V8 engine flaw, which enables arbitrary code execution via crafted content. The bug is now listed in CISA's Known Exploited Vulnerabilities catalog, confirming real-world exploitation. This is a development of a story first reported 2026-09-04 by The Hacker News. (src: Xakep)
- Rogue ConnectWise ScreenConnect clients spread four-stage VBScript chain — no patch available. Huntress reports worm-like activity abusing ScreenConnect to push a malicious VBScript payload to newly connected systems. Three unrelated incidents have been observed. No patch is currently available, making exposure mitigation reliant on access controls and monitoring of ScreenConnect deployments. This was first reported 2026-09-07 by BleepingComputer. (src: The Hacker News)
- MikroTik RouterOS vulnerabilities actively exploited to hijack SSH-exposed routers. Attackers are chaining two recently disclosed RouterOS flaws to take control of MikroTik devices with SSH services exposed to the internet. Routers running affected RouterOS versions with internet-facing SSH are at immediate risk. This was first reported 2026-09-04 by SecurityLab. (src: BleepingComputer)
- Mathspace discloses breach of over 1 million records via Metabase. Attackers compromised Mathspace's internal Metabase reporting system and stole data on more than one million students, staff, and parents. The breach pathway through Metabase reinforces the risk posed by exposed analytics and reporting infrastructure. This was first reported 2026-09-07 by BleepingComputer. (src: BleepingComputer)
- Notary digital signatures compromised in long-running campaign. Hundreds of notary offices were compromised by attackers who observed real transactions for months before stealing funds. The campaign highlights how sustained access to trusted signing infrastructure can be weaponised for financial fraud. This was first reported 2026-09-07 by SecurityLab. (src: SecurityLab)
- SecFlow orchestrates multiple LLMs as a coordinated AI hacking team. Exposed servers revealed an experiment where Claude, Qwen, and DeepSeek were assembled and assigned offensive security tasks through a framework called SecFlow. While not yet observed in the wild as a threat, it demonstrates the accessibility of multi-model orchestration for offensive purposes. This was first reported 2026-09-07 by SecurityLab. (src: SecurityLab)
Themes
Rapid weaponisation of fresh disclosures. Four of today's top items — Telerik, Chrome V8, ScreenConnect, and MikroTik — involve exploitation of recently disclosed or still-unpatched vulnerabilities. The gap between disclosure and active exploitation continues to narrow, particularly for products with internet-facing services (SSH, RMM clients, browsers). Prioritising patching of anything with a public PoC or KEV listing is increasingly the minimum viable response.
Analytics and reporting tools as breach entry points. The Mathspace breach via Metabase follows a recurring pattern of internal reporting and BI tools being treated as lower-trust systems despite holding broad data access. Exposed analytics interfaces warrant the same access controls and monitoring as production databases.
