Critical RCE Vulnerabilities Under Active Exploitation

Critical RCE Vulnerabilities Under Active Exploitation

First seen 6 Sep 2026, 18:34 UTC Buttondown 78.0

Article Content

Browse articles
ThreatCluster

Multiple critical vulnerabilities are currently being exploited, including remote code execution (RCE) flaws in HPE AOS-CX (CVE-2026-73749), Citrix NetScaler (CVE-2026-19490), Sangoma Switchvox (CVE-2026-9586), and Elementor Pro (CVE-2026-32475). A zero-day vulnerability in Google Chrome (CVE-2026-85046) is also under active exploitation. Organizations using affected systems are at significant risk of data breaches and unauthorized access. Additionally, a phishing campaign is utilizing invisible Unicode characters to bypass email filters, increasing the risk of credential theft. The ongoing exploitation of these vulnerabilities underscores the need for immediate patching and enhanced detection measures. The situation is compounded by the recent data breach at IDScan, affecting over 153 million driver's licenses. Security teams must prioritize addressing these vulnerabilities to mitigate potential impacts.

Key Points: • Multiple critical RCE vulnerabilities are actively exploited, affecting various platforms. • A zero-day vulnerability in Google Chrome is among the active threats this week. • Organizations are urged to patch vulnerabilities immediately to prevent data breaches.

Ask AI about this cluster

Timeline

2026-07-10
CVE-2026-14894 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-13
CVE-2026-6471 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-19
CVE-2026-19490 published
Citrix NetScaler authentication bypass vulnerability disclosed, critical for affected systems.
Buttondown
2026-08-19
CVE-2026-32475 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-01
CVE-2026-73749 published
HPE AOS-CX RCE vulnerability disclosed, posing critical risk to users.
Buttondown
2026-09-02
CVE-2026-9586 added to CISA KEV
Sangoma Switchvox RCE vulnerability confirmed under active exploitation.
Buttondown
2026-09-03
CVE-2026-85046 added to CISA KEV
Google Chrome zero-day vulnerability confirmed under active exploitation.
Buttondown
2026-09-06
Active exploitation of Adobe Commerce zero-day
Attackers exploit an unpatched RCE vulnerability in Adobe Commerce and Magento to backdoor online stores.
Buttondown
2026-09-06
Phishing campaign using invisible Unicode
A high-volume phishing campaign exploits invisible Unicode to bypass email filters, increasing credential theft risk.
Buttondown