This day 02:05 06:05 10:06 14:07 18:08 22:09
⚠ exploit status: CVE-2026-87491 · KEV
Info  2026-09-09 10:06Z · last 4h · 27 findings · glm-5.2:cloud

Threat Brief — 2026-09-09 — Patch Tuesday fallout and fresh root-escalation paths

Executive summary. Today's cycle is dominated by active-exploitation disclosures and privilege-escalation vectors landing alongside Microsoft's record September Patch Tuesday. A new cPanel flaw lets any hosting account with mail privileges escalate to root on the entire server, while a second Microsoft Defender zero-day PoC—dubbed ShieldCrash—surfaced immediately after Patch Tuesday with a working exploit. Google's seventh Chrome zero-day of the year is under active attack. Separately, Sophos published deeper analysis of the F5 BIG-IP APM fileless web-shell campaign, and N-able shipped its fourth N-central fix in recent weeks for a critical pre-auth RCE.

Top items

Themes

Patch-gap exploitation. Three of today's top items—ShieldCrash, the Chrome V8 zero-day, and the N-able N-central RCE—involve either zero-days dropped immediately after a patch cycle or critical flaws in products with recent patch histories. Attackers are timing disclosures and exploits to exploit the window between patch release and widespread deployment.

Privilege escalation as the primary objective. cPanel-to-root, Defender-to-SYSTEM, and the Wi-Fi repeater's hardcoded root all represent low-friction paths from limited access to full control. The pattern underscores that initial access is often only the first step; defenders should give equal weight to containment and segmentation.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db