🛡️ Cyber Times — CISO Intelligence Update
Wednesday, 09 September 2026 · Coverage: 08 Sep 2026 08:00 IST → 09 Sep 2026 08:00 IST
The high-confidence sweep produced 37 publishable records. This edition presents 9 source-linked updates across 3 security domains; 8 are marked for priority review.
🔴 Critical Threats & Active Exploitation
CVE-2026-75650 added to CISA KEV — Adobe Commerce and Magento
CRITICAL — Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage…
Defender action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for…
Validation: primary source · Published: 09 Sep 2026 00:07 IST Sources: CISA KEV · The Hacker News · BleepingComputer · SecurityWeek
🛡️ Vulnerabilities Worth Attention
CVE-2026-82004 — Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’) vulnerability that…
CRITICAL — NVD CVSS 10.0 (critical). Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’) vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 09 Sep 2026 00:49 IST Sources: NVD
CVE-2026-49883 — In checkReadPermission of PermissionsManager.java, there is a possible way to monitor sensitive device state data due to a missing permission check
CRITICAL — NVD CVSS 10.0 (critical). In checkReadPermission of PermissionsManager.java, there is a possible way to monitor sensitive device state data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 09 Sep 2026 01:47 IST Sources: NVD
CVE-2026-28659 — In MicroXR Blobstore, there is a possible way to access other app’s files due to a missing permission check
CRITICAL — NVD CVSS 10.0 (critical). In MicroXR Blobstore, there is a possible way to access other app’s files due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 09 Sep 2026 01:47 IST Sources: NVD
CVE-2026-86464 — In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deployment included…
CRITICAL — NVD CVSS 9.9 (critical). In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deployment included insecure default configurations and credentials for security-sensitive services. The Helm chart exposed the Keycloak service and its PostgreSQL backing database through Kubernetes NodePort services by default, while the Docker Compose…
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 09 Sep 2026 01:48 IST Sources: NVD
CVE-2026-84869 — A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host…
CRITICAL — NVD CVSS 9.9 (critical). A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 09 Sep 2026 01:48 IST Sources: NVD
CVE-2026-48273 — ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code (‘Eval Injection’) vulnerability that could result in arbitrary…
CRITICAL — NVD CVSS 9.9 (critical). ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code (‘Eval Injection’) vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 09 Sep 2026 01:47 IST Sources: NVD
CVE-2026-19232 — Adobe Experience Manager is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current…
CRITICAL — NVD CVSS 9.9 (critical). Adobe Experience Manager is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or control over the victim’s account or session. A low-privileged attacker could exploit this vulnerability to gain elevated access or control over the victim’s account or session. Exploitation…
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 09 Sep 2026 01:47 IST Sources: NVD
🧪 Threat Intelligence & Attack Research
Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities
INFORMATIONAL — Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as “critical.”
Defender action: Review the linked evidence, confirm organizational exposure, and update detections or mitigations where applicable.
Validation: direct source · Published: 09 Sep 2026 03:46 IST Sources: Cisco Talos
💡 Defensive Priority
Open the linked primary or corroborating evidence before changing production systems. Confirm asset exposure, use vendor guidance for remediation, and retain the source links with the operational change record.
Collection: 4,115 records inspected · 141 passed collection filters · 37 passed the high-confidence evidence gate · 27/28 source endpoints available. Automated intelligence is a triage aid; verify exposure and remediation against the linked primary advisory.