Skip to content
[SecurityIntel] 05 Sep | Critical RCEs Actively Exploited

[SecurityIntel] 05 Sep | Critical RCEs Actively Exploited

Buttondown September 5, 2026

SECURITYINTEL DAILY BRIEF ■ Threat Intel Brief Saturday, September 05, 2026 INTEL CONFIDENCE 100% THREAT LEVEL CRITICAL THREAT OF THE DAY Critical RCEs Actively Exploited CRITICAL 5 C2 IPs 89 OTX IOCs 33 ARTICLES ■ ANALYST TLDR Multiple critical vulnerabilities are under active exploitation, including RCE flaws in HPE AOS-CX, Citrix NetScaler, Sangoma Switchvox, and WordPress plugins, alongside a Google Chrome zero-day. Organizations face significant risk from these exploited flaws, large-scale data breaches affecting identity verification services, and sophisticated phishing campaigns leveraging unicode evasion. Proactive patching and enhanced detection are paramount. ■ CRITICAL STORIES CRITICAL #1 HPE, Citrix, Sangoma, WordPress RCEs Exploited In The Wild Multiple critical RCE and authentication bypass vulnerabilities across HPE AOS-CX (CVE-2026-73749), Citrix NetScaler (CVE-2026-19490), Sangoma Switchvox (CVE-2026-9586), and WordPress plugins Super Forms (CVE-2026-14894) and Elementor Pro are being actively exploited. These flaws allow for remote code execution or authentication bypass, posing an immediate and severe threat to affected systems. INFO #2 Google Chrome Zero-Day Actively Exploited (CVE-2026-85046) Google has patched a high-severity zero-day vulnerability (CVE-2026-85046) in the Chrome V8 engine that is under active exploitation. This marks the 6th Chrome zero-day patched this year, highlighting the persistent threat of browser-based attacks. INFO #3 IDScan Sued Over Alleged Data Breach Affecting 153 Million Drivers Identity verification company IDScan is facing lawsuits following an alleged data breach that compromised over 153 million driver's licenses. This incident underscores the severe impact of breaches on identity-related services and the vast amount of sensitive data at risk. INFO #4 Phishing Campaign Uses Invisible Unicode to Evade Filters A high-volume phishing campaign is leveraging invisible Unicode tag characters to bypass Microsoft email filters. This sophisticated evasion technique allows malicious emails to reach inboxes, increasing the risk of credential theft and malware delivery. ■ CVEs IDENTIFIED CVE-2026-73749 HPE AOS-CX — RCE Vulnerabilities Critical (9.8) CVE-2026-19490 Citrix NetScaler — Authentication Bypass (exploited in the wild) Critical CVE-2026-6471 PostgreSQL — Logical Decoding Flaw, Replication-Role Code Execution High (7.2) CVE-2026-9586 Sangoma Switchvox — Unauthenticated SQL Injection, RCE (exploited in the wild) Critical ■ THREAT ACTORS Nightmare Eclipse Security Researcher Released CrowdStrike Falcon zero-day exploit Amir Yaryab Iranian Cyber Unit Leader Oversees IRGC's cyber unit and CyberAv3ngers IRGC's cyber unit State- Cyberattacks on critical infrastructure ■ ATT&CK TTPs T1566.001 Spearphishing Attachment | Phishing campaign using invisible Unicode to evade filters T1036.002 Masquerading: Spoofing Name/Location | Invisible Unicode characters in phishing emails T1190 Exploit Public-Facing Application | Exploitation of HPE AOS-CX, Citrix NetScaler, Sangoma Switchvox, WordPress Super Forms/Elementor Pro RCEs T1078 Valid Accounts | Citrix NetScaler auth bypass, Dropbox account compromises, X password reset attacks, IDScan data breach T1068 Exploitation for Privilege Escalation | CrowdStrike Falcon zero-day, PostgreSQL RCE, VMware Workstation/Fusion RCE T1203 Exploitation for Client Execution | Google Chrome zero-day (V8 engine) ■ PATCH PRIORITY [P1 PATCH NOW] ≤24h HPE AOS-CX — RCE, actively exploited — SW [P1 PATCH NOW] ≤24h Citrix NetScaler — Auth Bypass, actively exploited — BC [P1 PATCH NOW] ≤24h Sangoma Switchvox — RCE, actively exploited — SW [P1 PATCH NOW] ≤24h WordPress Super Forms — RCE, actively exploited — THN ■ RECOMMENDED ACTIONS TODAY 1 [P1] Immediately patch HPE AOS-CX to address CVE-2026-73749 , Citrix NetScaler for CVE-2026-19490 , Sangoma Switchvox for CVE-2026-9586 , and WordPress plugins Super Forms ( CVE-2026-14894 ) and Elementor Pro due to active exploitation. 2 [P1] Update Google Chrome to the latest version to mitigate CVE-2026-85046 and other critical vulnerabilities, ensuring browser security against active zero-day exploits. 3 [P2] Apply updates for PostgreSQL ( CVE-2026-6471 ) and VMware Workstation/Fusion to prevent privilege escalation and host compromise from virtual machines. 4 [P2] Review and strengthen email security configurations to detect and block sophisticated phishing campaigns, specifically those leveraging Unicode character evasion as reported by Microsoft. 5 [P3] Audit and secure all systems handling sensitive identity data, such as IDScan, to prevent large-scale data breaches, focusing on robust access controls, encryption, and continuous monitoring. LIVE IOC FEED C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 PORT 8080 STATUS OFFLINE MALWARE Emotet COUNTRY US IP ADDRESS 50.16.16.211 PORT 443 STATUS ONLINE MALWARE QakBot COUNTRY US IP ADDRESS 34.204.119.63 PORT 443 STATUS OFFLINE MALWARE QakBot COUNTRY US IP ADDRESS 178.62.3.223 PORT 443 STATUS OFFLINE MALWARE QakBot COUNTRY GB IP ADDRESS 27.133.154.218 PORT 443 STATUS OFFLINE MALWARE QakBot COUNTRY JP FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

SECURITYINTEL DAILY BRIEF

Saturday, September 05, 2026

INTEL CONFIDENCE 100%

Critical RCEs Actively Exploited

Multiple critical vulnerabilities are under active exploitation, including RCE flaws in HPE AOS-CX, Citrix NetScaler, Sangoma Switchvox, and WordPress plugins, alongside a Google Chrome zero-day. Organizations face significant risk from these exploited flaws, large-scale data breaches affecting identity verification services, and sophisticated phishing campaigns leveraging unicode evasion. Proactive patching and enhanced detection are paramount.

HPE, Citrix, Sangoma, WordPress RCEs Exploited In The Wild

Multiple critical RCE and authentication bypass vulnerabilities across HPE AOS-CX (CVE-2026-73749), Citrix NetScaler (CVE-2026-19490), Sangoma Switchvox (CVE-2026-9586), and WordPress plugins Super Forms (CVE-2026-14894) and Elementor Pro are being actively exploited. These flaws allow for remote code execution or authentication bypass, posing an immediate and severe threat to affected systems.

Google Chrome Zero-Day Actively Exploited (CVE-2026-85046)

Google has patched a high-severity zero-day vulnerability (CVE-2026-85046) in the Chrome V8 engine that is under active exploitation. This marks the 6th Chrome zero-day patched this year, highlighting the persistent threat of browser-based attacks.

IDScan Sued Over Alleged Data Breach Affecting 153 Million Drivers

Identity verification company IDScan is facing lawsuits following an alleged data breach that compromised over 153 million driver's licenses. This incident underscores the severe impact of breaches on identity-related services and the vast amount of sensitive data at risk.

Phishing Campaign Uses Invisible Unicode to Evade Filters

A high-volume phishing campaign is leveraging invisible Unicode tag characters to bypass Microsoft email filters. This sophisticated evasion technique allows malicious emails to reach inboxes, increasing the risk of credential theft and malware delivery.

HPE AOS-CX — RCE Vulnerabilities

Citrix NetScaler — Authentication Bypass (exploited in the wild)

PostgreSQL — Logical Decoding Flaw, Replication-Role Code Execution

Sangoma Switchvox — Unauthenticated SQL Injection, RCE (exploited in the wild)

Released CrowdStrike Falcon zero-day exploit

Oversees IRGC's cyber unit and CyberAv3ngers

Cyberattacks on critical infrastructure

HPE AOS-CX — RCE, actively exploited — SW

Citrix NetScaler — Auth Bypass, actively exploited — BC

Sangoma Switchvox — RCE, actively exploited — SW

WordPress Super Forms — RCE, actively exploited — THN

■ RECOMMENDED ACTIONS TODAY

C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools

IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB