Daily briefing · September 8, 2026

Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security Bulletin

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — attention1 seen before CISA

September 8 delivers an ATTENTION-level day: three vulnerabilities are confirmed under active exploitation, with two Windows privilege escalation flaws (CVE-2026-81963 and CVE-2026-85880) on the CISA KEV list and a critical ScreenConnect file-execution bypass (CVE-2026-84869) flagged by VulnCheck before any official CISA confirmation. The broader landscape adds seven more critical-severity disclosures spanning Adobe Campaign Classic, ColdFusion, Android platforms, and Microsoft Entra, making patch prioritization an immediate operational necessity.

Today’s brief
  • Two Windows LPE flaws (Update Stack and ALPC) are under active exploitation — patch Windows 10 and 11 endpoints now
  • ScreenConnect clients face a critical unauthorized file transfer/execution flaw detected in the wild before official CISA confirmation
  • Adobe Campaign Classic and ColdFusion carry CVSS 10 / 9.9 RCE vulnerabilities requiring no user interaction
  • Brazil is under sustained ransomware pressure: thegentlemen group alone accounts for multiple recent victims across manufacturing, retail, and transportation sectors
80
critical
3
Actively exploited
1
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-81963KEVHIGH 7.8affects Windows 11 version 23H2
An improper link-resolution flaw in the Windows Update Stack on Windows 11 23H2 allows local privilege escalation and is already confirmed in active exploitation by CISA and observed independently by VulnCheck — any unpatched Windows 11 endpoint should be treated as a priority remediation target.
2
CVE-2026-85880KEVHIGH 7.8affects Windows 10 Version 1607
A heap-based buffer overflow in Windows ALPC on Windows 10 1607 enables local privilege escalation and is actively exploited in the wild with dual confirmation from CISA and VulnCheck, making it equally urgent to the Windows 11 flaw above.
3
CVE-2026-84869◆ VulnCheckCVSS 9.9affects ScreenConnect
A critical (CVSS 9.9) authorization bypass in ScreenConnect clients allows files to be transferred and executed through an active remote session without host approval — VulnCheck observed exploitation before CISA acted, indicating attackers are already moving against this vector in the wild.
4
CVE-2026-28659CVSS 10affects Android XR
A missing permission check in MicroXR Blobstore for Android XR scores a perfect CVSS 10.0 and allows any local attacker to escalate privileges and access other applications' files with no user interaction required — an especially dangerous condition on shared or multi-tenant device environments.
5
CVE-2026-49883CVSS 10affects Android Wear
A missing permission check in Android Wear's PermissionsManager scores CVSS 10.0 and exposes sensitive device state data to unauthorized local processes without any user interaction, creating serious privacy and security risks for wearable deployments in corporate environments.
6
CVE-2026-82004CVSS 10affects Adobe Campaign Classic
An OS command injection vulnerability in Adobe Campaign Classic scores CVSS 10.0 and allows unauthenticated arbitrary code execution with changed scope — any internet-exposed ACC instance should be considered critically at risk until patched.
7
CVE-2026-19232CVSS 9.9affects Adobe Experience Manager 6.5
An incorrect authorization flaw in Adobe Experience Manager 6.5 (CVSS 9.9) allows a low-privileged attacker to achieve arbitrary code execution and hijack user sessions or elevate account control without user interaction — a high-value target for attackers given AEM's widespread enterprise adoption.
8
CVE-2026-86464CVSS 9.9affects Eclipse aeriOS
Eclipse aeriOS in its current development build ships insecure default credentials and exposes Keycloak and its PostgreSQL database via Kubernetes NodePort and Docker Compose by default — a CVSS 9.9 misconfiguration-class flaw that could grant full identity infrastructure compromise if exposed to untrusted networks.
9
CVE-2026-48273CVSS 9.9affects ColdFusion 2023
An eval injection flaw in Adobe ColdFusion 2023 (CVSS 9.9) permits low-privileged attackers to execute arbitrary code without user interaction and with changed scope — ColdFusion servers have historically been rapid targets for ransomware operators and should be patched immediately.
10
CVE-2026-83941CVSS 9.9affects Microsoft Entra
A missing authorization check in Microsoft Entra ID (CVSS 9.9) allows an authorized attacker to escalate privileges over the network — given Entra's central role in enterprise identity management, exploitation could translate directly into broad tenant-level access or lateral movement.
Ransomware today

The thegentlemen group has been the most active ransomware threat in Brazil recently, claiming victims across multiple sectors including Biotipo Jeans (Retail), Zanini and Alurwalls (Manufacturing), Mutant, and Lider Aviacao (Transportation) in a short period. Over the past 30 days, thegentlemen leads activity with 9 confirmed victims, all in Brazil, followed by direwolf, krybit, dragonforce, emperador, and kazu — indicating a sustained and geographically focused campaign against Brazilian organizations. Additional groups such as Vexy Ransomware (targeting Engefitas) and settra (targeting ialegre.com) further demonstrate the breadth of active threat actors targeting the country.

Alurwalls BRDark Project · Manufacturing
Biotipo Jeans BRthegentlemen · Retail & E-Commerce
Zanini BRthegentlemen · Manufacturing
Mutant BRthegentlemen · Other
Lider Aviacao BRthegentlemen · Transportation
thegentlemen 9direwolf 3krybit 3dragonforce 2emperador 2kazu 2
Active groups & APTs

Several threat actor groups are being tracked as active or recently updated, including dragonforce, fulcrumsec, funksec, linkc, spacebears, and the Iran-linked blackshadow group — none have publicly disclosed new victims at this time, but their monitored status indicates potential pre-attack reconnaissance or infrastructure staging activity. The presence of blackshadow, attributed to Iran, warrants particular attention for organizations in sectors historically targeted by Iranian threat actors such as aviation, finance, and critical infrastructure.

Brazil focus

Brazil is experiencing an intense ransomware targeting cycle, with at least eight organizations identified as recent victims across manufacturing, retail, transportation, and other sectors. The thegentlemen group stands out as the dominant threat actor, while Dark Project, direwolf, Vexy Ransomware, and settra also claimed Brazilian victims in recent weeks — pointing to Brazil as a primary focus for multiple independent ransomware operations simultaneously.

Zaninithegentlemen · Manufacturing
AlurwallsDark Project · Manufacturing
Biotipo Jeansthegentlemen · Retail & E-Commerce
Mutantthegentlemen · Other
Lider Aviacaothegentlemen · Transportation
EngefitasVexy Ransomware · Manufacturing
ialegre.comsettra · Other
Oportunidadosdirewolf
Today’s recommendation: Immediately apply patches for CVE-2026-81963 and CVE-2026-85880 on all Windows endpoints, treat ScreenConnect deployments as compromised until CVE-2026-84869 is remediated, and accelerate patching of Adobe Campaign Classic and ColdFusion given their CVSS 10/9.9 RCE exposure with no user interaction required. Review and revoke overly permissive Entra ID roles and audit exposed identity infrastructure such as Eclipse aeriOS deployments for default credentials.
With actively exploited privilege escalation flaws, a pre-CISA zero-day in remote access tooling, and multiple perfect-score RCEs disclosed today, now is the moment to validate whether your own attack surface is exposed to any of these vectors before adversaries do it for you.Don’t wait to become a statistic: validate today, at no cost, whether any of these vectors reach your systems.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 8, 2026Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 202622 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 202610 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →
Share