Skip to content
The Exploit Bulletin — Wednesday, September 9, 2026: 4 issues require action

The Exploit Bulletin — Wednesday, September 9, 2026: 4 issues require action

Buttondown September 9, 2026

Wednesday, September 9, 2026 — 4 issues require action. If you run none of the software below, you are done.

Affects: FortiOS · FortiSwitchManager · Siemens RUGGEDCOM APE1808 with Fortinet NGFW · Adobe Commerce · Magento Open Source · ConnectWise ScreenConnect Support and Access sessions · Commvault Cloud

1. Heap-based buffer overflow in FortiOS and FortiSwitchManager allows unauthenticated code execution (CVE-2025-25249)

REMOTE CODE EXECUTION · CRITICAL · CVSS 7.4

The CVE was added to VulnCheck's known-exploited catalog on 2026-09-08 with a report of a purpose-built FortiGate RAT being planted on unpatched devices, so any FortiGate or FortiSwitchManager still on an affected build should be updated as an emergency change rather than in the window.

A heap overflow reachable via specially crafted packets lets an attacker execute unauthorized code or commands on FortiOS and FortiSwitchManager devices without credentials. Reporting describes compromised devices being fitted with a Node.js post-exploitation RAT (PivotC2).

Affected: FortiOS 7.6.0–7.6.3; FortiOS 7.4.0–7.4.8; FortiOS 7.2.0–7.2.11; FortiOS 7.0.0–7.0.17; FortiOS 6.4 (all versions); FortiSwitchManager 7.2.0–7.2.6; FortiSwitchManager 7.0.0–7.0.5; Siemens RUGGEDCOM APE1808 with Fortinet NGFW Security > Roles, check which session groups still grant TransferFiles (TransferFIlesInSession on legacy versions). Hunt for unexpected or duplicate ScreenConnect client installations on unrelated hosts and for files written and executed during recent remote sessions, per the Huntress write-up.

How to Patch: On-premise: upgrade to ScreenConnect 26.6.5 from the vendor download page (a current maintenance licence is required). Cloud: no server action is needed, but reinstall host clients and update access agents so endpoints run the patched client. As an interim measure that needs no upgrade, edit each role under Administration > Security > Roles and deselect the TransferFiles permission (TransferFIlesInSession on legacy versions) for every session group that has it.

Evidence: VulnCheck KEV · Huntress: rogue ScreenConnect installations across unrelated hosts suggest worm-like activity (2026-09-08) · Vendor confirmed

Full entry with sources →

4. Command Center API authentication bypass, fixed builds available (Commvault Cloud)

UNVERIFIED PUBLIC REPORT · NO CVE · AUTHENTICATION BYPASS · CRITICAL

The Cyber Centre published AV26-895 on 2026-09-08 pointing at Commvault bulletin CV_2026_07_1, a Command Center API authentication bypass with fixed builds already available; backup platforms are a prime ransomware precursor target, so an unauthenticated bypass on the management API warrants same-day patching.

Commvault's bulletin CV_2026_07_1, relayed by the Canadian Centre for Cyber Security as AV26-895, describes an authentication bypass in the Command Center API of Commvault Cloud 11.36, 11.40, 11.44 and 11.46 feature releases prior to the listed maintenance builds. An attacker who can reach the Command Center API could act without valid credentials on the backup control plane. No CVE, CVSS score or statement exploitation appears in the advisory text, and the bulletin's technical details were not retrieved in this pass.

Affected: Commvault Cloud 11.36.0 prior to 11.36.123, 11.40.0 prior to 11.40.72, 11.44.0 prior to 11.44.20, 11.46.0 prior to 11.46.20

How to Test: In Command Center, check the installed version ( / CommServe version). Any 11.36.x below 11.36.123, 11.40.x below 11.40.72, 11.44.x below 11.44.20 or 11.46.x below 11.46.20 is affected. Confirm from the network whether the Command Center web/API ports are reachable from untrusted segments or the internet.

How to Patch: Apply the maintenance release for your feature release: 11.36.123, 11.40.72, 11.44.20 or 11.46.20 or later, as listed in Commvault's CV_2026_07_1. If you cannot update today, place the Command Center API behind a VPN or allowlist and audit recent API activity for sessions from unexpected sources.

Evidence: Canadian Centre for Cyber Security advisory AV26-895

Full entry with sources →

Read on the web · Every past edition

The Exploit Bulletin is free and daily. It publishes only what security teams must act on today — nothing else. Forward it freely.

Spot an error, or an exploit we missed? here or email [email protected] .