Info
2026-09-08 18:05Z · last 4h · 38 findings
· glm-5.2:cloud
Threat Brief — 2026-09-08: Microsoft CVE Flood, StyleSmuggler Named
Microsoft disclosed a large batch of vulnerabilities spanning SQL Server, Entra ID, DNS Server, Skype for Business, and Media Foundation — several enabling unauthenticated remote code execution over the network. The actively exploited Magento/Adobe Commerce zero-day now carries the name "StyleSmuggler" per Sansec researchers. SAP patched a maximum-severity kernel memory-corruption flaw, and CISA warned of full-device-takeover vulnerabilities in CareCam Pro IP cameras.
Top items
- StyleSmuggler — actively exploited unauthenticated RCE in Magento/Adobe Commerce. Sansec warns that the critical flaw enabling unauthenticated remote code execution in Magento Open Source and Adobe Commerce is under active exploitation. The vulnerability, now publicly named "StyleSmuggler," was first reported on 2026-09-05 when Adobe shipped an emergency patch for CVE-2026-75650KEV; the new development is the Sansec naming and detailed attribution. (src: Xakep)
- Microsoft September batch — multiple unauthenticated network RCE flaws. A large MSRC disclosure includes CVE-2026-77482 (SQL Server heap-based buffer overflow, unauthenticated network RCE), CVE-2026-69782 (Windows DNS Server race condition, unauthenticated network RCE), CVE-2026-69522 (.NET/Visual Studio heap overflow, unauthenticated network RCE), CVE-2026-66302 (Skype for Business path traversal, unauthenticated network RCE), CVE-2026-62744 (Windows Media Foundation heap overflow, unauthenticated network RCE), and CVE-2026-62916 (Entra ID authentication bypass, unauthenticated network EoP). Additional elevation-of-privilege and information-disclosure issues affect Entra ID (CVE-2026-83941), Microsoft Fabric, Power Automate, Azure Cosmos DB, Azure Arc, the Windows kernel, and the RDP client. (src: MSRC — CVE-2026-77482, MSRC — CVE-2026-69782, MSRC — CVE-2026-66302)
- SAP "OVERPASS" — maximum-severity kernel vulnerability. SAP's September 2026 security updates address 20 vulnerabilities across multiple products, including a maximum-severity memory-corruption flaw in the SAP Kernel code. (src: BleepingComputer)
- CareCam Pro IP Cameras — full device takeover. CISA advisory ICSA-26-251-01 warns that affected versions of CareCam Pro IP Cameras (ANJIA AJL33PC0801) contain vulnerabilities that allow an attacker to take full control of the device. (src: CISA)
- Liquid Network heist — partial bitcoin return confirmed on chain. Following the $320M crypto theft first reported 2026-09-08, the perpetrators returned 3,400 of nearly 4,000 stolen bitcoin the next day per Bitcoin's public ledger. Approximately 598.5 BTC (~$47M) remains unreturned. (src: The Hacker News)
Themes
- Concentrated unauthenticated RCE surface. The Microsoft batch is notable for the number of unauthenticated, network-reachable RCE paths across diverse products — SQL Server, DNS Server, Skype for Business, .NET tooling, and Media Foundation — which together represent a broad remote attack surface.
- Identity infrastructure under pressure. Two separate Entra ID elevation-of-privilege flaws (CVE-2026-83941, CVE-2026-62916) appear alongside authorization issues in Microsoft Fabric, Power Automate, and Azure Cosmos DB, suggesting a pattern of missing-authorization and authentication-bypass defects in cloud identity and platform services.
