CTIPilot
Mon · 07 Sep 2026
All daily briefs ↗
Daily brief · UTC day

Monday, 7 September 2026

4 verified findings from 1 run · 1 update to prior coverage · the settled record for this UTC day, in the classic brief order.

ACT NOW · CRITICALCVE-2026-86206 +2 · exploited · 6 sources · 07 Sep 04:33Z

N-able ships a fourth emergency hotfix in a month after a fully patched N-central server was compromised again through a brand-new flaw

N-able's N-central RMM platform has shipped four emergency hotfixes against three separate, unrelated authentication/RCE flaw sets since 1 August 2026. Huntress found on 2026-09-04 that a customer's already-patched N-central server was compromised again; N-able's Hotfix 3 (CVE-2026-86206, CVE-2026-86207) followed on 2026-09-05, and a third, independent researcher then reported CVE-2026-86218, a pre-auth CVSS 10.0 remote-code-execution zero-day N-able's own Active Incident dashboard states has been observed exploited in the wild. Hotfix 4 (build 2026.3.1.14) is mandatory even for servers already on Hotfix 3.

N-able's own Active Incident dashboard and N-able's Jason Murphy both state CVE-2026-86218 (a pre-authentication remote-code-execution flaw rated CVSS 10.0) has been observed exploited in the wild, even though the concurrently published Hotfix 4 release notes hedge to no confirmed production exploitation. Hotfix 4 supersedes Hotfix 3 and is required even for servers already upgraded to it; hosted (NCOD) instances are already patched by N-able. Self-hosted administrators must apply Hotfix 4 immediately, restrict the N-central console to a VPN or IP allowlist, and audit user/role tables for accounts created without authorization, the exploit chain grants full administrative control over user management.

Open the full advisory to act →
Criticality
Kind
Topic
Region
TL;DR · the day in one read
  1. 01N-able ships a fourth emergency hotfix in a month after a fully patched N-central server was compromised again through a brand-new flaw. N-able's N-central RMM platform has shipped four emergency hotfixes against three separate, unrelated authentication/RCE flaw sets since 1 August 2026. Huntress found on 2026-09-04 that a customer's already-patched N-central server was compromised again; N-able's Hotfix 3 (CVE-2026-86206, CVE-2026-86207) followed on 2026-09-05, and a third, independent researcher then reported CVE-2026-86218, a pre-auth CVSS 10.0 remote-code-execution zero-day N-able's own Active Incident dashboard states has been observed exploited in the wild. Hotfix 4 (build 2026.3.1.14) is mandatory even for servers already on Hotfix 3.
  2. 02Insikt Group: the same six-tool stack followed thirteen unrelated CVEs into Exchange, SharePoint, FortiOS, Cisco IOS XE, F5 BIG-IP, GeoServer and Apache Shiro. Recorded Future's Insikt Group published its H1 2026 Malware and Vulnerability Trends report on 2026-09-03, tracking 215 actively exploited CVEs. Its most actionable defender-facing finding is that post-exploitation tool-stack reuse persists across otherwise-unrelated initial-access vulnerabilities: a cluster designated StrikeShark applied an identical six-tool stack across thirteen separate CVEs spanning multiple vendors, and Storm-1175 linked the same credential-theft and ransomware tooling across ten different initial CVEs.
  3. 03ChimeraZ expands beyond its fire-and-rescue targets to a French department's job-seeker platform, exposing CVs and personal data for over 20,000 people. The criminal-forum handle ChimeraZ, already tracked for a recurring data-theft campaign against French departmental fire-and-rescue services (SDIS); claims to have exfiltrated and published data from OnRecrute.EnAveyron.fr, the Département de l'Aveyron's employment platform, exposing 23,381 records covering 20,316 people plus roughly 1,499 PDF CVs. One of two independent reviewers of the leaked files attributes access to a no-MFA customer account combined with an IDOR flaw reaching a misconfigured Odoo database; the other declines to confirm any mechanism. No statement has been issued by the Département or the platform operator.

01Active threats, incidents & disclosures2 items

NOTABLENATOC2

ChimeraZ claims France's Département de l'Aveyron employment platform, exposing 20,000+ people's data including 1,499 CVs, a customer account without MFA, an IDOR flaw and a misconfigured Odoo database, per one of two trackers who reviewed the leak

The threat actor ChimeraZ (a criminal-forum handle already tracked for a recurring data-theft campaign against French departmental fire-and-rescue services) claimed on 5 September 2026 to have exfiltrated and published data from OnRecrute.EnAveyron.fr, an employment and CV platform the Département de l'Aveyron operates through its Agence Départementale de l'Attractivité et du Tourisme (ADAT). Two independent breach-tracking outlets, FrenchBreaches and Cyberattaque.org, each state they obtained and personally analysed the leaked files rather than relaying the forum post, and both corroborate the same scope: 23,381 records covering 20,316 people, plus roughly 1,499 PDF documents (~451 MB) (predominantly job-seeker CVs) for a claimed total of ~465 MB (FrenchBreaches, 2026-09-06; Cyberattaque.org, 2026-09-06). Exposed fields include names, email addresses, phone numbers, postal codes and communes, plus (within the CVs specifically) dates of birth, driving-licence status, education, employment history and named former employers (FrenchBreaches, 2026-09-06). Cyberattaque.org notes several candidate profiles were created or updated as recently as August 2026, indicating the exposed data is live production data rather than a stale archive (Cyberattaque.org, 2026-09-06).

The two trackers diverge sharply on how access was obtained, and neither account is a victim statement. FrenchBreaches alone reports the mechanism as a compromised customer account lacking multi-factor authentication, combined with an IDOR (Insecure Direct Object Reference) flaw that reached a misconfigured Odoo database from which the data was extracted, and adds that no detection of the malicious activity has occurred to date (FrenchBreaches, 2026-09-06). Cyberattaque.org, which independently obtained and reviewed the same files, explicitly declines to confirm any mechanism, stating that the hacker did not specify the access method and that nothing in the leak establishes whether access came from the employment platform itself, its extranet, or another component of the wider "En Aveyron" ecosystem (Cyberattaque.org, 2026-09-06). No statement has been issued by the Département de l'Aveyron, the ADAT, or the platform operator as of this run.

ChimeraZ is already tracked for the SDIS fire-and-rescue campaign, tied by name to five of seven French departmental fire-and-rescue services (SDIS) hit in an August 2026 wave; an earlier July 2026 wave against five further SDIS was attributed only collectively to three handles including ChimeraZ, with no per-unit breakdown. This incident shows the same forum handle now reaching French departmental administrative services outside that vertical, via a suspected third-party customer-account foothold into a business-application (Odoo) backend rather than the fire-and-rescue-specific access this actor was previously observed using. The pattern (an outsourced business-application backend reachable through a customer account without MFA) is directly transferable to Swiss cantonal and communal administrations running comparable outsourced CRM- or ERP-backed citizen or partner portals.

Selon nos informations, la fuite aurait été rendue possible par la compromission d'un compte client dépourvu de double authentification, combinée à une faille IDOR donnant accès à une base de données Odoo mal configurée. Aucune détection de l'activité malveillante n'aurait eu lieu à ce jour. (translated from French: According to our information, the leak was made possible by the compromise of a client account lacking two-factor authentication, combined with an IDOR flaw granting access to a misconfigured Odoo database. No detection of the malicious activity has reportedly occurred to date.)

FrenchBreaches 2026-09-06

Le hacker ne précise toutefois pas la méthode utilisée pour obtenir ces informations. Rien ne permet à ce stade de déterminer si l'accès provient directement de la plateforme d'emploi, de son extranet ou d'un autre composant de l'écosystème En Aveyron. (translated from French: The hacker does not, however, specify the method used to obtain this information. Nothing at this stage allows us to determine whether the access came directly from the employment platform, its extranet, or another component of the wider En Aveyron ecosystem.)

Cyberattaque.org 2026-09-06

Le pirate ChimeraZ revendique les données de 20 316 personnes ainsi que près de 1 500 documents PDF, dont des CV contenant de nombreuses informations personnelles et professionnelles. (translated from French: The hacker ChimeraZ claims the data of 20,316 people plus nearly 1,500 PDF documents, including CVs containing extensive personal and professional information.)

FrenchBreaches 2026-09-06

Builds on: 2026-08-31/france-sdis-fire-rescue-data-leak-campaign

incident07 Sep 04:40Zmulti-sourceOpen finding ↗
NOTABLENATOB2

"ted backdoor" and curlRAT, a DPRK-nexus actor recompiles a victim's own HAProxy source tree to hide C2 inside the load balancer's self-reported connection statistics

Rapid7 Labs documents a previously undocumented Linux espionage toolkit deployed against two South Korean automotive- and media-sector organizations, active since at least early 2025. Rather than exploiting a HAProxy vulnerability, the operators obtained code execution on the host by some other route and recompiled the victim's own HAProxy 2.8.12 source tree to embed a custom filter plugin (internally named ted_plugin, left in debug strings as "ted backdoor") that hooks HAProxy's native HTTP parser, memory-pool allocator and event scheduler (Rapid7 Labs, 2026-09-03). Because it is compiled into the load balancer's own binary rather than exploiting a flaw in it, the technique defeats vulnerability scanning and version-string checks outright: a recompiled binary still reports the same version string as a clean build (The Hacker News, 2026-09-04).

The filter's defining trick is anti-forensic self-falsification. After every command-and-control exchange, it reaches into HAProxy's own internal counters (using hardcoded struct offsets specific to build 2.8.12) and decrements the per-backend connection counts (beconn/feconn), the global active-connection count (actconn), and cumulative traffic fields (cum_conn, cum_req, bytes_in, bytes_out), so the C2 traffic that passed through the load balancer never appears in its own self-reported statistics or logs (Rapid7 Labs, 2026-09-03). A request to one hardcoded static-asset-style path switches the filter into C2 mode (beacon, file upload/download, shell command execution, configuration update) while outside that mode it can passively capture session cookies and selected HTTP headers, or, when several conditions match (a specific User-Agent pattern, a payload-path selector byte, a URL/referer regex, and either IP allow/deny-list membership or an operator key smuggled in the Accept-Language header that overrides IP filtering), substitute or append attacker content into the HTTP response body via HAProxy's own body-editing callbacks while rewriting Content-Type/Content-Length and stripping Accept-Ranges so the size change goes unnoticed by the client.

A companion RAT, curlRAT (named for its libcurl-based networking, distinct from the unrelated CurlBack RAT attributed to the Pakistan-linked SideCopy group), is compiled into trojanized replacements of crond, agetty, atd and polkitd (Rapid7 Labs, 2026-09-03). It polls a hardcoded C2 over HTTPS (with an HTTP fallback) every 12 hours by default, or every 30 seconds in an operator-set fast-poll mode, decoding tasking through a Base64-plus-rolling-XOR pipeline, and offers command execution, file transfer, an interactive PTY/reverse shell that escalates to full root privilege before handoff, and a watchdog thread that first checks for the presence of a specific virtualization-driver file before activating, sleeping and aborting if the host does not look virtualized, an anti-analysis check against sandboxed detonation; before reporting HAProxy's running/stopped/restarted state back to the operator every hour (Rapid7 Labs, 2026-09-03). If its primary C2 host fails configuration validation, curlRAT falls back to a second hardcoded server, and it derives a per-victim tracking identifier from a hash of host-specific values (hostname, IP address, hardware UUID and a cron-version string) letting the operator distinguish individual infected hosts across a botnet-style deployment rather than relying on a random or sequential ID (Rapid7 Labs, 2026-09-03). A stager component deploys only when HAProxy or cron are already present, verifies root, overwrites the legitimate crond binary in place, timestomps the replacement to match another system binary's own creation time, and scrubs the keywords tmp/wget/cron/crond from root's bash history and six system logs including auth.log and audit/audit.log, staged through a file named to resemble a JSP engine artifact (Rapid7 Labs, 2026-09-03). A separately trojanized sshd intercepts plaintext credentials into an encrypted log file for later retrieval (Rapid7 Labs, 2026-09-03).

Rapid7 could not establish the initial-access vector with certainty, but notes both victims ran an exposed groupware login portal and mail server on the same edge host; a plausible entry point Rapid7 says is consistent with documented Kimsuky tradecraft against Korean groupware vendors (Rapid7 Labs, 2026-09-03). The watering-hole delivery model otherwise overlaps Kaspersky's Operation SyncHole (November 2024–February 2025), which Kaspersky attributed to Lazarus; Rapid7 explicitly notes APT37 and Lazarus are organizationally distinct DPRK clusters operating under different agencies, so the toolkit's attribution rests on three only partially reconciled threads (APT37 via C2 infrastructure, Lazarus via the delivery model, Kimsuky via the initial-access hypothesis) rather than a single confirmed cluster (Rapid7 Labs, 2026-09-03).

Triage: a legitimate in-house HAProxy Lua or filter module can also hook the HTTP parser and modify response bodies, so that alone is not the signal. The discriminating feature this mechanism supports is that no operationally normal filter module needs to actively decrement or zero HAProxy's own connection or traffic counters, any module observed doing so, rather than only reading them, warrants immediate investigation.

The toolkit is attributed with medium confidence to DPRK APTs, given that the attacks Rapid7 observed were targeting South Korean media and automotive sectors, likely aiming at long-term espionage, the usage of simple xor-based encryption, custom substitution cipher, and the list of C2s hardcoded is associated to APT37 by ThreatFox and maltrail.

First, it reaches into HAProxy's internal counters to decrement active connection stats, referencing fields from the proxy struct via hardcoded 2.8.12 offsets to clear any trace left: the per-backend beconn/feconn and the global actconn, then 64-bit fields within be_counters (cum_conn, cum_req, bytes_in, bytes_out) guarded against underflow, and 32-bit peak metrics (sps_max, conn_max, cps_max) decremented only when exactly 1.

Rapid7 Labs 2026-09-03

It is not a HAProxy vulnerability, and installing it requires code execution on the host and the ability to replace the running binary.

The Hacker News 2026-09-04
threat07 Sep 04:37Zmulti-sourceOpen finding ↗

02Research, reports & policy1 item

NOTABLENATOB2

Recorded Future's H1 2026 Malware and Vulnerability Trends: two clusters reuse an identical post-exploitation tool stack across thirteen and ten unrelated initial CVEs

Recorded Future's Insikt Group published its H1 2026 Malware and Vulnerability Trends report on 3 September 2026, tracking 215 actively exploited CVEs in the first half of 2026, up 34% from 161 in H1 2025 (Recorded Future, 2026-09-03). Of those, 176 (82%) were network-accessible and 146 (68%) could be exploited without prior authentication; 142 of those 146 combined both properties, and 60 of 82 remote-code-execution CVEs combined network reachability, no authentication requirement and code execution in a single package (Recorded Future, 2026-09-03).

The report's most actionable finding for defenders is that post-exploitation tool-stack reuse persists across otherwise-unrelated initial-access vulnerabilities, regardless of vendor or product family (Recorded Future, 2026-09-03). A cluster the report designates StrikeShark applied an identical six-tool post-exploitation stack (SharkLoader, Cobalt Strike Beacon, FScan, Searchall, Pillager Stealer and SharpGPOAbuse) across thirteen separate CVEs spanning 2016 through 2025, reaching Microsoft Exchange, Microsoft SharePoint, Fortinet FortiOS, Cisco IOS XE, F5 BIG-IP, GeoServer and Apache Shiro (Recorded Future, 2026-09-03); SharkLoader itself was previously profiled by Kaspersky's GReAT, which found it deploying Cobalt Strike via "Perfect DLL Hijacking" in a campaign whose confirmed victims spanned government and diplomatic entities, software developers and organizations in several other sectors and regions (Kaspersky Securelist, 2026-06-24). Separately, Storm-1175 linked Mimikatz, Impacket, PsExec, Rclone and Medusa ransomware across ten different initial CVEs; a China-linked cluster the report designates SHADOW-EARTH-053 separately reused Mimikatz following exploitation of CVE-2021-26855 in Microsoft Exchange Server (Recorded Future, 2026-09-03). Insikt Group mapped 114 of the 215 CVEs to MITRE ATT&CK: exploitation of a public-facing application was associated with 77 CVEs (68%), and 50 of those 77 also co-occurred with PowerShell, Windows Command Shell or Unix Shell execution; every one of the 28 web-shell-associated CVEs also carried the public-facing-application technique. The next most frequently associated post-exploitation behaviors across the mapped CVEs were system-information discovery, collection of data from the local system, transfer of further tooling into the compromised environment, and exfiltration over the command-and-control channel or web-protocol-based C2 traffic (Recorded Future, 2026-09-03).

The report's own defender-facing conclusion is explicit: because the same limited tool stack recurs regardless of which vulnerability supplied the initial foothold, detection engineering should chain exploitation telemetry from public-facing systems through to the post-exploitation behaviors these clusters repeat (credential dumping, remote-service execution via native administration mechanisms, bulk outbound data transfer, and ransomware staging) rather than treating each CVE alert as an isolated, one-off event (Recorded Future, 2026-09-03).

Threat actors reused post-exploitation playbooks across different initial vulnerabilities; StrikeShark applied the same six-tool stack across thirteen CVEs, while Storm-1175 linked credential theft, remote execution, data transfer, and ransomware tooling across ten.

In the StrikeShark campaign, SharkLoader, Cobalt Strike Beacon, FScan, Searchall, Pillager Stealer, and SharpGPOAbuse were linked to the same thirteen CVEs. Those vulnerabilities spanned 2016 through 2025 and affected Microsoft Exchange and SharePoint, Fortinet FortiOS, Cisco IOS XE, F5 BIG-IP, GeoServer, Apache Shiro, and other public-facing technologies.

50 of the 77 CVEs associated with the exploitation of public-facing applications were also linked to PowerShell, Windows Command Shell, or Unix Shell, and all 28 web-shell-associated CVEs also included T1190.

Recorded Future (Insikt Group) 2026-09-03

Builds on: 2026-06-27/kaspersky-great-strikeshark-loader-deploys-cobalt-strike-via

annual-report07 Sep 04:43Zsingle-sourceOpen finding ↗

03Updates to prior coverage1 item

HIGHupdatedNATOB1

Berlin's state government confirms an extortion attempt after a phishing click opens the shared Landesnetz; media reporting names Rhysida

First published 2026-08-30 · open finding →

Updaterun 2026-09-07T0411Z-intelupdated_atsourcesevidencebody

Follow-up reporting establishes for the first time that the published leak extends well beyond personnel data: it includes records tied to district heating and power plants, fuel depots, backup-power installations, electrical substations, prisons and defense-industrial / Bundeswehr-related material. Germany's BSI issued a public warning of an elevated threat level from the leak (heightened targeted-phishing risk plus a hack-and-leak risk given Berlin's 20 September state election) while assessing the underlying intrusion itself as financially motivated. Berlin's government set up a dedicated coordination unit (BSI, BKA and the domestic intelligence service BfV jointly reviewing the material) and started a risk-based notification process for affected citizens, employees and companies.

Follow-up reporting establishes for the first time that the scope of the published leak extends well beyond the personal data first identified. Citing Der Tagesspiegel, heise reports the dataset also includes information on district-heating and power plants, fuel depots, backup-power installations, electrical substations, prisons, waterworks, and armaments companies and the Bundeswehr (translated from German) (heise online, 2026-09-06), a materially broader critical-infrastructure and defense-industrial exposure than the water-supply-vulnerability material Rhysida itself had claimed at disclosure.

Germany's BSI issued a public warning on 2026-09-05 of an elevated threat level stemming from the leak. The agency states data containing information on critical infrastructure, companies and organizations can, depending on its sensitivity, also increase the threat level (translated from German) (heise online, 2026-09-05), and separately warns of heightened targeted-phishing risk against anyone who had contact with affected individuals or institutions (heise online, 2026-09-05). BSI additionally flags a hack-and-leak risk specific to the political calendar: Berlin holds a state-parliament election on 20 September 2026, and stolen documents can be released or recontextualized at a moment favorable to an attacker (heise online, 2026-09-05). BSI assesses the underlying intrusion itself as financially rather than politically motivated (heise online, 2026-09-05), an assessment attributed to BSI, distinct from opposition politicians' own separately reported alarm about the incident's severity.

Berlin's government responded on 2026-09-06 by establishing a dedicated coordination unit ("Steuerungseinheit") in which BSI, the Federal Criminal Police Office (BKA) and the domestic intelligence service (BfV) jointly review and assess the leaked material, and by starting a risk-based notification process to contact affected citizens, employees and companies by letter or email (heise online, 2026-09-06). Independent IT-security expert Manuel Atug separately stated that the state of Berlin acted grossly negligently and deliberately failed to comply with classified-information protection requirements (translated from German), adding that he had already flagged the same security gaps to Berlin's parliamentary interior committee in 2023 and 2025 (heise online, 2026-09-06). Contradiction: the heise 2026-09-06 timeline separately dates full network reconnection to 2026-08-24, one day later than the 2026-08-23 date this entry's main analysis attributes to Der Tagesspiegel; both dates are carried without resolving the one-day gap.

The same 2026-09-06 report adds a fourth account of the date sequence: its own retrospective timeline states the two affected Senate departments were isolated from the Landesnetz on 2026-08-14 (matching Der Tagesspiegel and Berliner Zeitung's dating of the isolation, not Security Affairs' 2026-08-17) and separately states the Senate chancellery's public press statement disclosing the "ICT incident" followed on 2026-08-17 (translated from German) (heise online, 2026-09-06). This distinguishes network isolation (2026-08-14, now three independent accounts) from the Senate's own formal press disclosure (2026-08-17) as two separate events, but Security Affairs' claim that the isolation itself happened on 2026-08-17 remains an unresolved discrepancy with the German-language reporting, not one this update can settle.

04Deep dive1 item

CRITICALCVE-2026-86206 +2exploitedNATOB2

CVE-2026-86206 / CVE-2026-86207 / CVE-2026-86218, N-able N-central: a third, unrelated auth-bypass/RCE chain in five weeks, the third CVE a pre-auth CVSS 10.0 zero-day N-able says is already exploited

N-able's N-central, the remote-monitoring-and-management (RMM) platform MSPs use to centrally patch, monitor and remotely access their customers' servers and endpoints, has now shipped four emergency hotfixes in five weeks against three separate, mechanically unrelated flaw sets. The first, disclosed 1–2 August 2026 (CVE-2026-18556 / CVE-2026-18577), remains the one confirmed to have been exploited by the Storm-1175 ransomware actor with its StormEncryptor payload (Huntress, 2026-08-03). This entry covers the second and third flaw sets, which N-able itself describes as unrelated to the August chain and to each other.

Huntress's investigation of the second chain began on 4 September 2026, after a customer's fully patched N-central production server was compromised again (Huntress, 2026-09-06). Huntress reproduced and validated a working proof-of-concept authentication bypass against N-central 2026.3.1.10 and shared it with N-able, which shipped Hotfix 3 (build 2026.3.1.13, 2026-09-05) fixing two newly designated flaws (N-able Status, 2026-09-05): CVE-2026-86206, an access-control gap in N-central's internal API filter granting unauthorized access to internal-only APIs (OffSeq Threat Radar, 2026-09-05), and CVE-2026-86207 (CVSS 7.7), an authentication bypass by primary weakness reaching the same internal APIs (OffSeq Threat Radar, 2026-09-05). Huntress states this "net new exploit chain… potentially leverages one or both" of the two CVEs, but because logs on the compromised appliance had already rotated by the time of investigation, it cannot confirm which specific flaw the attacker used, nor rule out a third path.

Hours after Hotfix 3 shipped, in the early morning of 6 September 2026, a third and independent researcher alerted N-able to a wholly separate zero-day: CVE-2026-86218, a pre-authentication remote-code-execution flaw (CWE-96, static code injection) rated CVSS 10.0, the maximum possible score (OffSeq Threat Radar, 2026-09-06). Huntress reports that both N-able's own Active Incident dashboard and N-able's Jason Murphy convey that this flaw has been exploited in the wild (Huntress, 2026-09-06); Murphy's own quoted words state "Since the disclosures, a third, independent researcher alerted us to a new vulnerability that has been exploited in the wild"; Murphy separately confirmed on record that "this one is a Zero day." N-able's concurrently published Hotfix 4 release notes carry a narrower, conflicting statement; "we have no confirmations that this vulnerability has been exploited in production environments, but unpatched systems remain at risk" (N-able Status, 2026-09-06), leaving the vendor's own account internally inconsistent on confirmed exploitation while agreeing the flaw is a live zero-day. Hotfix 4 (build 2026.3.1.14) supersedes Hotfix 3 and is mandatory even for servers already running it; N-able-hosted (NCOD) instances were already remediated automatically.

Across both the August and September chains, successful exploitation grants an attacker full administrative control over N-central's user and role management, the same privilege level normally reserved for trusted NOC and engineering staff (Huntress, 2026-09-06). From there, an attacker can create rogue administrator accounts, push arbitrary scripts and jobs to every managed endpoint, and pivot into managed customer networks via N-central's built-in Take Control remote-access feature or by registering a persistent tunnel service (Huntress, 2026-09-06). Because N-central sits between an MSP and every customer network it manages, a single compromised instance is a force multiplier reaching every downstream client, a class of exposure directly relevant to any Swiss cantonal or communal administration that outsources IT operations to an MSP running this platform.

Huntress's detection guidance differs from the August incident: rather than the Take Control feature, this activity targets the underlying API and appliance logs directly. Defenders should review N-central's envoy_proxy_HTTPS.log and syslog ncentraldms for URL-encoded internal-API-route access anomalies, and audit newly created user accounts for unusual naming conventions, Huntress specifically flags email addresses suffixed with .invalid or similar string manipulations designed to pass casual inspection (Huntress, 2026-09-06). Reconnaissance for the September chain also probed the remoteControlAction.do?method=getPierDetails endpoint with specific appliance IDs to map the environment before exploitation. No source cited in this entry describes a public proof-of-concept for any of the three CVEs; Huntress's own reproduction remained private and was shared directly with N-able.

Triage: legitimate N-central administration routinely creates new users and pushes jobs across the managed fleet, so neither activity alone is a signal. For the September chain this entry covers, the discriminator Huntress's own investigation supports is a newly created or role-elevated account whose creation coincides with anomalous internal-API access or unusual entries in the appliance's own logs. Huntress's discriminator for the separate August chain, a remote-control session from a support-style account (e.g. the default "MSP Support" identity) that targets a domain controller or other high-value host outside an expected support ticket or maintenance window; remains a valid signal for that earlier flaw set but is not the pattern Huntress observed for September's API/log-based activity.

Since the disclosures, a third, independent researcher alerted us to a new vulnerability that has been exploited in the wild that is unrelated to the previously disclosed CVEs.

this one is a Zero day.

Jason Murphy, N-able, via Huntress

At this time, we have no confirmations that this vulnerability has been exploited in production environments, but unpatched systems remain at risk.

N-able Status (vendor) 2026-09-06

This activity represents a net new exploit chain that potentially leverages one or both of two newly designated vulnerabilities (CVE-2026-86206 and CVE-2026-86207), completely distinct from the flaws addressed by N-able's August hotfixes (CVE-2026-18556 and CVE-2026-18577).

Huntress 2026-09-06

Builds on: 2026-08-03/cve-2026-18577-n-able-n-central-auth-bypass-exploited

vulnerability07 Sep 04:33Zmulti-sourceOpen finding ↗

05Action items2 items

Verification & coverage notes1 run

2026-09-07T0411Z-intel · Sonnet 5 · window 24 h · 4 entries published

Verification & coverage notes

A standard-cadence fire (gap_hours ≈ 15, window_hours = 24; no catch-up disclosure required). Four new entries published, one existing entry updated through its changelog.

New entries:

  • 2026-09-07/cve-2026-86206-86207-86218-n-able-n-central-third-chain (priority: critical, this run's deep dive, category identity-infra), a third, unrelated N-able N-central auth-bypass/RCE chain in five weeks; CVE-2026-86218 confirmed exploited per N-able's own Active Incident dashboard and an on-record staff quote, though the vendor's own HF4 release notes carry a conflicting hedge (both statements carried, weighted per the entry's sourcing_note). References the existing 2026-08-03/cve-2026-18577-n-able-n-central-auth-bypass-exploited entry (distinct CVEs, same product).
  • 2026-09-07/rapid7-ted-backdoor-curlrat-dprk-haproxy (priority: notable), coverage-backlog recovery (row surfaced by the 2026-09-06T1308Z audit, exempt from the recency gate per its own header): a DPRK-nexus actor compiles a custom C2 filter into a victim's own HAProxy source tree. Attribution carried as three only-partially-reconciled evidentiary threads (APT37/C2 infra, Lazarus/delivery model, Kimsuky/initial-access hypothesis) rather than a single confirmed cluster, per the source's own caveat.
  • 2026-09-07/recordedfuture-h1-2026-tool-stack-reuse (kind: annual-report, priority: notable), PD-9 periodic-report treatment; another coverage-backlog composition item (row surfaced 2026-09-06T1308Z-audit), composed narrowly around the genuinely actionable tool-stack-reuse-across-CVEs finding rather than the report's vanity-metric headline figures.
  • 2026-09-07/chimeraz-aveyron-onrecrute-breach (priority: notable), French departmental (Aveyron) employment-platform breach, actor already tracked for the SDIS fire-and-rescue campaign; genuinely distinct victim type, so a new entry referencing the SDIS entry rather than an update. Access-vector claim single-sourced to one of two independent reviewers and explicitly contradicted by the second; both accounts held and attributed.

Update: 2026-08-30/berlin-landesnetz-rhysida-extortion-phishing-vector, type: update (floats). Full leak scope confirmed to include CI/defense-industrial records (heating/power plants, fuel depots, substations, prisons, Bundeswehr-related material); BSI public warning of elevated phishing and hack-and-leak risk ahead of Berlin's 20 September election; new BSI/BKA/BfV coordination unit and citizen-notification process; an independent expert's "gross negligence" accusation.

Dropped: German homemade-wire-slinging substation sabotage (S2), borderline-drop: physical/kinetic sabotage against German HV substations — no cyber intrusion, no digital access vector, no ATT&CK mapping possible; unlike the BACS-covered Poland grid sabotage (named cyber actor, Static Tundra, and attack infrastructure), no actor or cyber angle is stated here, so it cannot carry the evidence-bound techniques[] mapping check_run.py requires on an incident/threat entry. Out of scope for a cyber-CTI pipeline.

Coverage-backlog dispositions (all six re-checked rows: no change):

  • Boston Scientific incident (2026-08-25), still no attacker attribution/vector/mechanism from any party.
  • TheGentlemen/Ixa Systems SA listing, still only the original ransomware.live listing, no victim statement or Swiss press pickup.
  • Krybit/UICC listing, still only leak-site trackers repeat the claim.
  • Kairos/Ville de Libercourt listing, still no commune statement.
  • NovoCure incident (2026-09-01), still no attacker attribution/vector/mechanism.
  • VMSA-2026-0007/CVE-2026-59346, confirmed scoped to VMware Workstation/Fusion only (no ESXi row), no exploitation reports found; does not clear the recovery bar.

Backlog row struck: AA26-231A Siemens S7 joint-advisory re-read, S1 re-fetched the full PDF; prior updates already captured essentially all quotable substance; the only new detail (ICS-only MITRE ATT&CK for ICS ids T0834/T1694) is not mappable onto the Enterprise-only pinned dataset, so no changelog action follows. No further action needed.

Backlog row opened: ShinyHunters lists Medela AG (Baar, Zug) on its leak site (discovered <3h before this run), bare, uncorroborated claim whose own scope numbers read like a surface-scan result rather than confirmed data theft; fails PD-6 as it stands. Stated deadline 2026-09-08 makes a press pickup or statement plausible within 1-2 fires.

Backlog rows not addressed this run (no tasking): the Zurich District Court verdict row (correctly skipped, not due until 2026-09-10); the Keycloak-entry meta-fact correction (low priority); the Spring Ring Teams-vishing/NTLM-relay watch item; three of the four PD-11(d) research items held below the recovery bar (AWS root-password-spray, Exodus wallet installer, JSCeal deobfuscation); only the Ted backdoor/curlRAT portion of that bundled row was actioned this run.

Candidate sources: two research workers (S1, S4) each independently proposed a "new" candidate source (huntress-blog, cyberattaque-org); both were already tracked in sources/sources.json under existing ids (huntress, cyberattaque-org, the latter active since 2026-08-02); no duplicate added, so this run's one-new-candidate-source slot was not consumed.

Source lifecycle: frenchbreaches promoted candidate → active (promotion_due, 3 contributing runs). ssd-disclosure set to fetch_method: blocked after 10+ consecutive runs unreachable by every transport including the jina reader (confirmed independently by S1 and S3 this run); source_health.py's full 186-source sweep this run reported zero UNSOLVED sources.

Coverage gaps: cisa-directives (JS-shell listing shell persists, 6th+ consecutive occurrence, a recipe gap, not an anti-bot block; needs a structured-feed/API recipe on a future run); inside-it-ch (the Insel Gruppe/ServiceNow-migration backlog article now blocked even via the jina reader for the first time, worse than the prior subscriber-paywall condition, no corroborating outlet found on any transport).