Daily briefing · September 8, 2026
Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security Bulletin
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — attention1 seen before CISA
September 8 delivers an ATTENTION-level day: three vulnerabilities are confirmed under active exploitation, with two Windows privilege escalation flaws (CVE-2026-81963 and CVE-2026-85880) on the CISA KEV list and a critical ScreenConnect file-execution bypass (CVE-2026-84869) flagged by VulnCheck before any official CISA confirmation. The broader landscape adds seven more critical-severity disclosures spanning Adobe Campaign Classic, ColdFusion, Android platforms, and Microsoft Entra, making patch prioritization an immediate operational necessity.
Today’s brief
- Two Windows LPE flaws (Update Stack and ALPC) are under active exploitation — patch Windows 10 and 11 endpoints now
- ScreenConnect clients face a critical unauthorized file transfer/execution flaw detected in the wild before official CISA confirmation
- Adobe Campaign Classic and ColdFusion carry CVSS 10 / 9.9 RCE vulnerabilities requiring no user interaction
- Brazil is under sustained ransomware pressure: thegentlemen group alone accounts for multiple recent victims across manufacturing, retail, and transportation sectors
Critical highlights
1
An improper link-resolution flaw in the Windows Update Stack on Windows 11 23H2 allows local privilege escalation and is already confirmed in active exploitation by CISA and observed independently by VulnCheck — any unpatched Windows 11 endpoint should be treated as a priority remediation target.
2
A heap-based buffer overflow in Windows ALPC on Windows 10 1607 enables local privilege escalation and is actively exploited in the wild with dual confirmation from CISA and VulnCheck, making it equally urgent to the Windows 11 flaw above.
3
A critical (CVSS 9.9) authorization bypass in ScreenConnect clients allows files to be transferred and executed through an active remote session without host approval — VulnCheck observed exploitation before CISA acted, indicating attackers are already moving against this vector in the wild.
4
A missing permission check in MicroXR Blobstore for Android XR scores a perfect CVSS 10.0 and allows any local attacker to escalate privileges and access other applications' files with no user interaction required — an especially dangerous condition on shared or multi-tenant device environments.
5
A missing permission check in Android Wear's PermissionsManager scores CVSS 10.0 and exposes sensitive device state data to unauthorized local processes without any user interaction, creating serious privacy and security risks for wearable deployments in corporate environments.
6
An OS command injection vulnerability in Adobe Campaign Classic scores CVSS 10.0 and allows unauthenticated arbitrary code execution with changed scope — any internet-exposed ACC instance should be considered critically at risk until patched.
7
An incorrect authorization flaw in Adobe Experience Manager 6.5 (CVSS 9.9) allows a low-privileged attacker to achieve arbitrary code execution and hijack user sessions or elevate account control without user interaction — a high-value target for attackers given AEM's widespread enterprise adoption.
8
Eclipse aeriOS in its current development build ships insecure default credentials and exposes Keycloak and its PostgreSQL database via Kubernetes NodePort and Docker Compose by default — a CVSS 9.9 misconfiguration-class flaw that could grant full identity infrastructure compromise if exposed to untrusted networks.
9
An eval injection flaw in Adobe ColdFusion 2023 (CVSS 9.9) permits low-privileged attackers to execute arbitrary code without user interaction and with changed scope — ColdFusion servers have historically been rapid targets for ransomware operators and should be patched immediately.
10
A missing authorization check in Microsoft Entra ID (CVSS 9.9) allows an authorized attacker to escalate privileges over the network — given Entra's central role in enterprise identity management, exploitation could translate directly into broad tenant-level access or lateral movement.
Ransomware today
The thegentlemen group has been the most active ransomware threat in Brazil recently, claiming victims across multiple sectors including Biotipo Jeans (Retail), Zanini and Alurwalls (Manufacturing), Mutant, and Lider Aviacao (Transportation) in a short period. Over the past 30 days, thegentlemen leads activity with 9 confirmed victims, all in Brazil, followed by direwolf, krybit, dragonforce, emperador, and kazu — indicating a sustained and geographically focused campaign against Brazilian organizations. Additional groups such as Vexy Ransomware (targeting Engefitas) and settra (targeting ialegre.com) further demonstrate the breadth of active threat actors targeting the country.
Alurwalls BRDark Project · Manufacturing
Biotipo Jeans BRthegentlemen · Retail & E-Commerce
Zanini BRthegentlemen · Manufacturing
Mutant BRthegentlemen · Other
Lider Aviacao BRthegentlemen · Transportation
thegentlemen 9direwolf 3krybit 3dragonforce 2emperador 2kazu 2
Active groups & APTs
Several threat actor groups are being tracked as active or recently updated, including dragonforce, fulcrumsec, funksec, linkc, spacebears, and the Iran-linked blackshadow group — none have publicly disclosed new victims at this time, but their monitored status indicates potential pre-attack reconnaissance or infrastructure staging activity. The presence of blackshadow, attributed to Iran, warrants particular attention for organizations in sectors historically targeted by Iranian threat actors such as aviation, finance, and critical infrastructure.
Brazil focus
Brazil is experiencing an intense ransomware targeting cycle, with at least eight organizations identified as recent victims across manufacturing, retail, transportation, and other sectors. The thegentlemen group stands out as the dominant threat actor, while Dark Project, direwolf, Vexy Ransomware, and settra also claimed Brazilian victims in recent weeks — pointing to Brazil as a primary focus for multiple independent ransomware operations simultaneously.
Zaninithegentlemen · Manufacturing
AlurwallsDark Project · Manufacturing
Biotipo Jeansthegentlemen · Retail & E-Commerce
Mutantthegentlemen · Other
Lider Aviacaothegentlemen · Transportation
EngefitasVexy Ransomware · Manufacturing
ialegre.comsettra · Other
Oportunidadosdirewolf
Today’s recommendation: Immediately apply patches for CVE-2026-81963 and CVE-2026-85880 on all Windows endpoints, treat ScreenConnect deployments as compromised until CVE-2026-84869 is remediated, and accelerate patching of Adobe Campaign Classic and ColdFusion given their CVSS 10/9.9 RCE exposure with no user interaction required. Review and revoke overly permissive Entra ID roles and audit exposed identity infrastructure such as Eclipse aeriOS deployments for default credentials.
With actively exploited privilege escalation flaws, a pre-CISA zero-day in remote access tooling, and multiple perfect-score RCEs disclosed today, now is the moment to validate whether your own attack surface is exposed to any of these vectors before adversaries do it for you.Don’t wait to become a statistic: validate today, at no cost, whether any of these vectors reach your systems.Meet the Autonomous AI Pentest Agent →Previous briefings
September 8, 2026 — Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 2026 — 22 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026 — Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026 — WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026 — WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026 — Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026 — WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026 — Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026 — WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026 — Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026 — Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 2026 — 10 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026 — Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026 — Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →