Security News Bulletin - September 2026

Banner Background

Adobe Commerce Remote Code Execution Vulnerability

CVE-2026-75650

Published: 2026-09-07 
Updated: 2026-09-07  

Vendor: Adobe 
Product: Adobe Commerce

Attack Tags: Remote Code Execution, Unauthenticated Exploitation, Template Injection, Magento/Adobe Commerce, PHP Code Injection.

Severity: Critical (10.0)

What Is CVE-2026-75650?
 

CVE-2026-75650 is a critical remote code execution vulnerability affecting Adobe Commerce, Adobe Commerce B2B, and Magento Open Source. The vulnerability is caused by improper neutralization of special elements in a template engine (CWE-1336). An unauthenticated attacker can exploit the flaw remotely without user interaction to inject malicious PHP code and execute arbitrary commands on the affected server. 

Security researchers have dubbed the vulnerability “StyleSmuggler.” Research indicates that attackers can smuggle malicious PHP code through HTTP headers and parameters, which can subsequently be executed during automated email/template rendering. 

Affected Versions 

Adobe Commerce 

  • affected from 0 through 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug  

Adobe Commerce B2B 

  • affected from 0 through 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug  

Magento Open Source 

  • affected from 0 through 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug  

Observed Attack Activity 

Active exploitation has been confirmed. CVE-2026-75650 was added to the CISA Known Exploited Vulnerabilities (KEV) Catalog. CISA's assessment records exploitation as active, automatable, with total technical impact. 

Multiple affected Magento/Adobe Commerce stores were reportedly targeted, with attackers attempting to achieve remote code execution and establish persistence on compromised servers. 

 Indicators of Compromise are: 

  • Suspicious requests containing unusual HTTP headers or parameters
  • Unexpected PHP files or web shells on Magento servers
  • Unusual PHP process execution or outbound connections
  • Unauthorized modifications to Magento configuration or application files
  • Unexpected administrator accounts or credentials
  • Suspicious activity associated with automated email/template rendering
  • Unexpected outbound connections from Magento/Adobe Commerce servers

Additional Resources  

  1. Official CVE Record — CVE.org 
    https://www.cve.org/CVERecord?id=CVE-2026-75650 

  2. Adobe Security Bulletin 
    https://helpx.adobe.com/security/products/magento/apsb26-146.html 

  3. Tenable.com 
    https://www.tenable.com/blog/stylesmuggler-cve-2026-75650-frequently-asked-questions-about-adobe-commerce-and-magento-zero 


WordPress Login XSS Vulnerability

CVE-2026-64638

Published: 2026-08-07 
Updated: 2026-08-07  

Vendor: WordPress 
Product: WordPress

Attack Tags: Reflected Cross-Site Scripting (XSS), Pre-Authentication, Web Application Exploitation, Credential Theft, WordPress Core.

Severity: High (CVSS 8.9)

What Is CVE-2026-64638?
 

CVE-2026-64638 is a high-severity pre-authentication reflected Cross-Site Scripting (XSS) vulnerability in the WordPress login screen. The flaw results from differences in how malformed input is interpreted by multiple HTML sanitization components. An attacker can supply specially crafted input through the WordPress login process and have malicious content reflected back to a victim's browser. 

The vulnerability can be exploited through a malicious third-party webpage or link. Successful exploitation requires the target to interact with the malicious content. Under specific conditions, researchers have demonstrated that the XSS can be chained with additional weaknesses to achieve remote code execution (RCE) on the WordPress server. 

Affected Versions 

  • unaffected from 0 before 7.0.3  

Observed Attack Activity 

Public proof-of-concept exploits have been released, including repositories demonstrating the XSS and potential XSS-to-RCE attack chain. However, available reporting should distinguish this from confirmed widespread exploitation: as of the latest reviewed reporting, there was no confirmed in-the-wild exploitation or mass-scanning telemetry, and the vulnerability was not reported as being in the CISA KEV catalog. 

The vulnerability has nevertheless attracted significant attention because of the potential XSS-to-RCE escalation path and the availability of public PoCs. Organizations should monitor WordPress login endpoints for suspicious requests and prioritize upgrading affected WordPress installations. 

 Indicators of Compromise are: 

  • Unusual requests to wp-login.php
  • Suspicious or malformed values in login parameters
  • Repeated requests containing HTML/script-like payloads
  • Unexpected administrator-session activity
  • Suspicious changes to WordPress files or configuration following user interaction with malicious links

Additional Resources  

  1. Official CVE Record – CVE.org 
    https://www.cve.org/CVERecord?id=CVE-2026-64638 

  2. National Vulnerability Database (NVD) 
    https://nvd.nist.gov/vuln/detail/cve-2026-64638? 

  3. Imperva.com 
    https://www.imperva.com/blog/imperva-customers-protected-against-xss2shell-cve-2026-64638-in-wordpress-core/ 

  4. WordPress Documentation 
    https://wordpress.org/documentation/wordpress-version/version-7-0-3/ 


CrowdStrike Falcon Sensor Arbitrary File Write / Local Privilege Escalation

CVE-2026-40058

Published: 2026-09-15 
Updated: 2026-09-15  

Vendor: CrowdStrike 
Product: Falcon sensor for Windows

Attack Tags: Local Privilege Escalation, Arbitrary File Write, Windows, Endpoint Security, TOCTOU

Severity: High (CVSS 8.8)

What Is CVE-2026-40058?
 

CVE-2026-40058 is a high-severity vulnerability in the CrowdStrike Falcon Sensor for Windows. The issue is related to the Falcon feature that removes malicious macros from Microsoft Office files. Under a specific configuration, an unprivileged local user may be able to write an arbitrary file to a protected location. This could potentially allow the attacker to escalate their privileges and gain higher-level access to the Windows system. 

The vulnerability is associated with a time-of-check/time-of-use (TOCTOU) race condition (CWE-367).  Importantly, the vulnerability only exists when the Microsoft Office File Malicious Macro Removal Windows policy is enabled. CrowdStrike states that customers remain protected through its Cloud Anti-malware for Microsoft Office Files settings. 

Affected Versions 

  • affected from 8.10.0 before 8.10.21408 
  • affected from 7.40.0 before 7.40.21309 
  • affected from 7.39.0 before 7.39.21113 
  • affected from 7.38.0 before 7.38.21007 
  • affected from 7.37.0 before 7.37.20912 
  • affected from 7.36.0 before 7.36.20807 
  • affected from 7.35.0 before 7.35.20712 
  • affected from 7.34.0 before 7.34.20613 
  • affected at 7.33.0
  • affected from 7.32.0 before 7.32.20410  

Falcon Sensor for Mac and Linux are not affected 

Observed Attack Activity 

As this vulnerability was only disclosed on September 15, 2026, there are currently no confirmed reports of widespread exploitation in the sources reviewed. The primary concern is local privilege escalation: an attacker who already has low-level access to a Windows endpoint could potentially abuse the flaw to write files into protected locations and increase their privileges. 

 Endpoint security software operates with highly privileged access. A vulnerability within such software can therefore create an additional attack path on protected systems. 

Successful exploitation could potentially allow an attacker to: 

  • Write files to protected system locations
  • Escalate from an unprivileged account
  • Gain higher-level access to the endpoint
  • Potentially bypass some security boundaries

Organizations using affected Falcon Sensor versions should prioritize applying CrowdStrike's available security updates. 

Additional Resources  

  1. Official CVE Record — CVE.org 
    https://www.cve.org/CVERecord?id=CVE-2026-40058 

  2. CrowdStrike Security Advisory 
    https://www.crowdstrike.com/en-us/security-advisories/cve-2026-40058/ 

  3. National Vulnerability Database 
    https://nvd.nist.gov/vuln/detail/cve-2026-40058 

  4. Tenable.com 
    https://www.tenable.com/cve/CVE-2026-40058 


Linux Kernel Wi-Fi Memory Corruption Vulnerability

CVE-2026-68472

Published: 2026-08-15 
Updated: 2026-08-17  

Vendor: Linux 
Product: Linux

Attack Tags: Wi-Fi , Out-of-Bounds Read, Memory Corruption, Malicious Access Point, EHT Multi-Link Element , Remote/Adjacent Attack, DoS

Severity: High (CVSS 8.1)

What Is CVE-2026-68472?
 

CVE-2026-68472 is a high-severity Linux kernel vulnerability in the cfg80211 Wi-Fi subsystem. The flaw occurs when the kernel processes a specially crafted EHT Multi-Link Element (MLE) contained in an MBSSID beacon. 

A malicious Wi-Fi access point can send a truncated EHT MLE that causes the kernel to access data beyond the valid element boundary. This can result in an out-of-bounds read and memory corruption, potentially leading to system crashes or exposure of sensitive kernel memory. The attack requires the attacker to be within Wi-Fi radio range but does not require authentication or user interaction. 

Affected Versions 

  • affected from 61dcfa8c2a8f6c53ce77b2c832b82990754b2aa9 before 584657c5fc58d7a840623a2fa06331c9661dd0f1 
  • affected from 61dcfa8c2a8f6c53ce77b2c832b82990754b2aa9 before 3b0505e43da8fb5b2a7994c3c3604e5a74692154 
  • affected from 61dcfa8c2a8f6c53ce77b2c832b82990754b2aa9 before 74e27cd1d98b546fdb276008a83708d062339661  

Observed Attack Activity 

No confirmed active exploitation has been identified in the sources reviewed. The vulnerability was publicly disclosed in August 2026 and has received patches in the Linux kernel stable branches. CISA's vulnerability summary lists CVE-2026-68472 with its 8.1 severity but does not indicate confirmed exploitation in that listing. 

The attack scenario is nevertheless significant for organizations using Linux devices with Wi-Fi enabled: an attacker located within wireless range could potentially deliver a malicious beacon without requiring network-level access or credentials. 

 Indicators of Compromise are: 

  • Malformed or truncated EHT Multi-Link Elements (MLE) in MBSSID beacon frames.
  • Repeated anomalous beacon frames originating from an unknown BSSID/MAC address.
  • Kernel oops, panic, or crash associated with cfg80211/Wi-Fi MLE processing.
  • KASAN/KFENCE out-of-bounds read reports involving ieee80211_mle_get_mld_id().
  • Unexpected wireless-interface resets or system instability immediately after receiving beacon traffic from a specific AP.
  • Wireless IDS/IPS alerts identifying malformed 802.11 management frames.

Additional Resources  

  1. Official CVE Record — CVE.org 
    CVE Record: CVE-2026-68472 

  2. Ubuntu Security Advisory 
    https://ubuntu.com/security/CVE-2026-68472 

  3. Tenable.com 
    https://www.tenable.com/cve/CVE-2026-68472? 


Linux Kernel ext4 Deadlock Vulnerability

CVE-2026-92503

Published: 2026-09-17 
Updated: 2026-09-17  

Vendor: Linux 
Product: Linux

Attack Tags: ext4, ABBA Deadlock, Denial of Service, Extended Attributes, Local Attack, Kernel Filesystem, Resource Contention

Severity: CVSS score not assigned by CVE/NVD

What Is CVE-2026-92503?
 

CVE-2026-92503 is a Linux kernel vulnerability in the ext4 filesystem involving an ABBA deadlock in ext4_xattr_inode_cache_find(). 

The issue occurs when ext4 handles concurrent extended-attribute (xattr) workloads with the ea_inode mount/format option enabled. One task can hold a reference to an mbcache_entry while waiting for an EA inode to finish eviction, while the eviction thread simultaneously waits for that reference to be released. This circular dependency can cause the affected processes to remain blocked indefinitely. 

The Linux kernel fix introduces the EXT4_IGET_NOWAIT option so that the affected inode lookup can be performed without waiting for an inode that is being created or evicted. 

Affected Versions 

  • affected from 0a46ef234756dca04623b7591e8ebb3440622f0b before 7720fddd1fe344d14be258a2028f74ebf1569511
  • affected from 0a46ef234756dca04623b7591e8ebb3440622f0b before 03438084a7b8621fb5c762dd3d04cff5f2630fb2
  • affected at 0752e7fb549d90c33b4d4186f11cfd25a556d1dd
  • affected at 737fb7853acd5bc8984f6f42e4bfba3334be8ae1
  • affected at 111103907234bffd0a34fba070ad9367de058752
  • affected from 6.1.107 before 6.2
  • affected from 6.6.47 before 6.7
  • affected at 6.10 

Observed Attack Activity 

No confirmed active exploitation has been reported at the time of review. 

The underlying deadlock was identified through Syzbot/stress-ng testing, rather than through a reported real-world attack. Current tracking also indicates no known exploit and no CISA KEV listing for CVE-2026-92503. 

The primary security concern is local denial of service/system instability on systems using the affected ext4 configuration and experiencing the required concurrent xattr and inode-eviction workload. 

 Indicators of Compromise are: 

  • No known malicious IP addresses, domains, URLs, or file hashes.
  • Linux kernel hung-task messages indicating processes blocked for extended periods.
  • Kernel warnings or errors related to ext4 filesystem operations.
  • Repeated filesystem operations becoming unresponsive or timing out.
  • System instability or application hangs associated with intensive ext4 xattr activity.
  • Repeated deadlock conditions when ea_inode functionality is enabled.

Additional Resources  

  1. Official CVE Record – CVE.org 
    CVE Record: CVE-2026-92503 

  2. Linux Kernel Advisory 
    https://kernel.googlesource.com/pub/scm/linux/security/vulns/%2B/bf297c92367287cf2c79a2a38dd5df1fe24220be/cve/published/2026/CVE-2026-92503.mbox 

  3. National Vulnerability Database (NVD) 
    https://nvd.nist.gov/vuln/detail/cve-2026-92503 

  4. Amazon Linux Security Center 
    https://explore.alas.aws.amazon.com/CVE-2026-92503.html 

Back to Newsletter Home