Cyber Threat Brief — September 8 2026
1. StyleSmuggler → CVE-2026-75650 / APSB26-146 — Adobe Hotfix + Credential Rotation
TL;DR: Adobe released APSB26-146 (Sep 7; bulletin window Sep 8) for CVE-2026-75650 (CVSS critical unauth RCE), confirming ITW against Commerce merchants. Apply composer hotfix VULN-39341, verify with magento-patches, and rotate encryption key plus all related creds at source — patch alone is not remediation.
What’s New:
- Official CVE + vendor hotfix: download
VULN-39341-composer-patches.zip; Cloud verify:vendor/bin/magento-patches -n status | grep 39341(expect Applied) - Affected: Adobe Commerce / Magento OS 2.4.9-2026-aug and earlier (listed 2.4.4–2.4.9 branches) + listed B2B; Cloud + on-prem
- Adobe must: apply patch AND rotate encryption key plus admin passwords, integration tokens, OAuth secrets, payment gateway API keys at provider, DB, SSH/deploy, shipping/tax APIs
- Sansec: implant mutated —
fc-cache(Sep 6),chronyd(Sep 7); still hunt[kworker/u:8:0]/.gvfsd; second attacker PHP webshell underpub/media/.../sync_*.php(Sep 7) - Story change vs Sep 6: was unpatched zero-day → now CVE + hotfix + mandatory rotation
Actionable Intel
| Artifact | Type | ATT&CK | Log Source | Action |
|---|---|---|---|---|
| Unpatched Commerce/Magento ≤ 2.4.9-2026-aug (no VULN-39341 Applied) | Vulnerable asset | N/A | Patch inventory / magento-patches | Apply hotfix immediately (Cloud + on-prem) |
| Encryption key + admin / integration / OAuth / payment gateway (provider) / DB / SSH / shipping-tax APIs | Credential exposure | T1078 / T1552 | IdP, vault, gateway consoles | Rotate at source after patch — key rotate alone ≠ invalidate stolen secrets |
Process [kworker/u:8:0] / fc-cache / chronyd under /tmp/.kw_*, ~/.cache/fontconfig/, /tmp/.fc-*, /tmp/.chrony-*, ~/.local/share/.gvfsd/ | Implant | T1036 / T1053.003 | EDR, auditd, Sysmon Linux | Kill; collect hash; assume compromise → full rotation |
Cron gvfsd-user / fc-cache (13,43) / chronyd (57,27) | Persistence | T1053.003 | Cron spool + crontab inventory | Remove; empty crontab ≠ clean (chronyd may self-relaunch) |
POST /graphql?styles[ … ] / PayPal transparent eval(base64 | Exploit delivery | T1190 | WAF, Magento access logs | Alert/block; keep GraphQL restricted if unused |
pub/media/catalog/product/cache/ss_*/sync_*.php + X-Cache-Token | Second-attacker webshell | T1505.003 | FIM, web logs | find pub/media -name '*.php'; remove + rotate |
Detection
| Source | Rule | Gap |
|---|---|---|
| Splunk ESCU | PARTIAL — Linux Add Files In Known Crontab Directories | FileCreate under */etc/cron* / */var/spool/cron/* can catch cron-spool install; misses GraphQL styles, implant ([kworker]/fc-cache/chronyd), Adobe patch status. Rejected ESCU Linux Kworker Process In Writable Process Path (needs iptables child — CyclopsBlink-shaped) |
| Elastic | PARTIAL — Cron Job Created or Modified | /var/spool/cron/crontabs/* create/rename — persistence aspect only. Rejected Executable Masquerading as Kernel Process (kworker* does not match bracketed [kworker/…]) |
| Sigma | PARTIAL — New Cron File Created | Cron-dir file create only; 0 ET-2026 Magento GraphQL / StyleSmuggler / CVE-2026-75650 rules |
Hunt hint: Verify Adobe patch: vendor/bin/magento-patches -n status | grep 39341. Hunt processes/paths for [kworker/u:8:0], fc-cache (~/.cache/fontconfig/, /tmp/.fc-*), chronyd (/tmp/.chrony-*/), .gvfsd/gvfsd-user; crontab + spool file for 13,43 / 57,27 / gvfsd. Alert GraphQL styles[ and PayPal eval(base64. Hunt find pub/media -name '*.php' and NTP/123 to ntp.timesync.to / 185.157.160.251. Patch does not clean prior compromise — scan then rotate.
Sources: Adobe KB APSB26-146, Sansec StyleSmuggler, stanislavdevops on X, Daily_CyberSec on X, SecureChap on X, Sep 6 brief
Status Updates
- N-central CVE-2026-86218: HF4 (build 2026.3.1.14) still required — HF3 insufficient. Sep 7 staging
- MikroTrick (RouterOS): Vendor patches remain; continue Flagged/
ops/-2SSH hunts on internet-exposed devices. Sep 6 - CVE-2026-85046 (Chrome V8): Still on CISA KEV; federal due September 18 — Opera shipped Chromium patch covering this CVE. Sep 5
- FalconFlank / PostGREShell (CVE-2026-6471): No material change — continue
bcrypt.dllsideload hunt and REPLICATION-account audit. Sep 5 - CVE-2026-19490 (Citrix NetScaler ADC/Gateway): Auth-bypass probing / patch builds unchanged vs Sep 6. Sep 6
- SonicWall SMA1000 (CVE-2026-83548 / 83549): Metasploit module circulating — prior KEV deadlines were Sep 5; verify remediation closure. Sep 3