Cyber Threat Brief — September 8 2026

⚠️ This report is AI-generated. Always validate findings.

1. StyleSmuggler → CVE-2026-75650 / APSB26-146 — Adobe Hotfix + Credential Rotation

TL;DR: Adobe released APSB26-146 (Sep 7; bulletin window Sep 8) for CVE-2026-75650 (CVSS critical unauth RCE), confirming ITW against Commerce merchants. Apply composer hotfix VULN-39341, verify with magento-patches, and rotate encryption key plus all related creds at source — patch alone is not remediation.

What’s New:

  • Official CVE + vendor hotfix: download VULN-39341-composer-patches.zip; Cloud verify: vendor/bin/magento-patches -n status | grep 39341 (expect Applied)
  • Affected: Adobe Commerce / Magento OS 2.4.9-2026-aug and earlier (listed 2.4.4–2.4.9 branches) + listed B2B; Cloud + on-prem
  • Adobe must: apply patch AND rotate encryption key plus admin passwords, integration tokens, OAuth secrets, payment gateway API keys at provider, DB, SSH/deploy, shipping/tax APIs
  • Sansec: implant mutated — fc-cache (Sep 6), chronyd (Sep 7); still hunt [kworker/u:8:0] / .gvfsd; second attacker PHP webshell under pub/media/.../sync_*.php (Sep 7)
  • Story change vs Sep 6: was unpatched zero-day → now CVE + hotfix + mandatory rotation

Actionable Intel

ArtifactTypeATT&CKLog SourceAction
Unpatched Commerce/Magento ≤ 2.4.9-2026-aug (no VULN-39341 Applied)Vulnerable assetN/APatch inventory / magento-patchesApply hotfix immediately (Cloud + on-prem)
Encryption key + admin / integration / OAuth / payment gateway (provider) / DB / SSH / shipping-tax APIsCredential exposureT1078 / T1552IdP, vault, gateway consolesRotate at source after patch — key rotate alone ≠ invalidate stolen secrets
Process [kworker/u:8:0] / fc-cache / chronyd under /tmp/.kw_*, ~/.cache/fontconfig/, /tmp/.fc-*, /tmp/.chrony-*, ~/.local/share/.gvfsd/ImplantT1036 / T1053.003EDR, auditd, Sysmon LinuxKill; collect hash; assume compromise → full rotation
Cron gvfsd-user / fc-cache (13,43) / chronyd (57,27)PersistenceT1053.003Cron spool + crontab inventoryRemove; empty crontab ≠ clean (chronyd may self-relaunch)
POST /graphql?styles[] / PayPal transparent eval(base64Exploit deliveryT1190WAF, Magento access logsAlert/block; keep GraphQL restricted if unused
pub/media/catalog/product/cache/ss_*/sync_*.php + X-Cache-TokenSecond-attacker webshellT1505.003FIM, web logsfind pub/media -name '*.php'; remove + rotate

Detection

SourceRuleGap
Splunk ESCUPARTIALLinux Add Files In Known Crontab DirectoriesFileCreate under */etc/cron* / */var/spool/cron/* can catch cron-spool install; misses GraphQL styles, implant ([kworker]/fc-cache/chronyd), Adobe patch status. Rejected ESCU Linux Kworker Process In Writable Process Path (needs iptables child — CyclopsBlink-shaped)
ElasticPARTIALCron Job Created or Modified/var/spool/cron/crontabs/* create/rename — persistence aspect only. Rejected Executable Masquerading as Kernel Process (kworker* does not match bracketed [kworker/…])
SigmaPARTIALNew Cron File CreatedCron-dir file create only; 0 ET-2026 Magento GraphQL / StyleSmuggler / CVE-2026-75650 rules

Hunt hint: Verify Adobe patch: vendor/bin/magento-patches -n status | grep 39341. Hunt processes/paths for [kworker/u:8:0], fc-cache (~/.cache/fontconfig/, /tmp/.fc-*), chronyd (/tmp/.chrony-*/), .gvfsd/gvfsd-user; crontab + spool file for 13,43 / 57,27 / gvfsd. Alert GraphQL styles[ and PayPal eval(base64. Hunt find pub/media -name '*.php' and NTP/123 to ntp.timesync.to / 185.157.160.251. Patch does not clean prior compromise — scan then rotate.

Sources: Adobe KB APSB26-146, Sansec StyleSmuggler, stanislavdevops on X, Daily_CyberSec on X, SecureChap on X, Sep 6 brief


Status Updates

  • N-central CVE-2026-86218: HF4 (build 2026.3.1.14) still required — HF3 insufficient. Sep 7 staging
  • MikroTrick (RouterOS): Vendor patches remain; continue Flagged/ops/-2 SSH hunts on internet-exposed devices. Sep 6
  • CVE-2026-85046 (Chrome V8): Still on CISA KEV; federal due September 18 — Opera shipped Chromium patch covering this CVE. Sep 5
  • FalconFlank / PostGREShell (CVE-2026-6471): No material change — continue bcrypt.dll sideload hunt and REPLICATION-account audit. Sep 5
  • CVE-2026-19490 (Citrix NetScaler ADC/Gateway): Auth-bypass probing / patch builds unchanged vs Sep 6. Sep 6
  • SonicWall SMA1000 (CVE-2026-83548 / 83549): Metasploit module circulating — prior KEV deadlines were Sep 5; verify remediation closure. Sep 3