The IT week was RMM, session theft, and a sixth Chrome 0-day — not a quiet Labor Day
31 August–7 September 2026. N-central took four hotfixes in five weeks and a CVSS 10 pre-auth RCE. BigBear 2.0 and Knight Office kept eating Microsoft 365 sessions. Chrome CVE-2026-85046 is in the wild. Magento StyleSmuggler is the storefront story, not the enterprise one.
Executive summary
FACT: This week the highest-leverage enterprise problem was not a new nation-state wiper. It was the tools that already sit above every endpoint — RMM, the browser, and the Microsoft 365 session.
N-able N-central absorbed a fourth hotfix in five weeks. CVE-2026-86218 is a pre-auth RCE, CVSS 4.0 10.0, CWE-96, fixed in 2026.3 Hotfix 4 (build 2026.3.1.14) on 6 September. It is unrelated to CVE-2026-86206 / CVE-2026-86207 (auth bypass to internal APIs / admin creation), which Huntress tied to a 4 September customer compromise on a Hotfix-2 box and which Hotfix 3 (2026.3.1.13) addressed. N-able's own pages disagree on whether 86218 is exploited in production; Huntress and several recaps treat the RMM wave as exploited. Earlier CVE-2026-18577 is already on CISA KEV. Shadowserver: ~1,500 N-central instances on the internet. Hosted NCOD was auto-patched; on-prem is not.
Google shipped Chrome 152.0.7977.82/.83 for CVE-2026-85046, V8 type confusion, sixth in-the-wild Chrome 0-day of 2026. Identity: BigBear 2.0 reported against 258 organizations / 5,000+ M365 credentials; Knight Office AiTM (Docusign lures, Monday.com and Joomla redirects) joined EvilTokens/Kali365. Magento/Adobe Commerce StyleSmuggler is today's Daily Top — commerce RCE, not the RMM blast radius.
ASSESSMENT: If you run on-prem N-central below 2026.3.1.14, that is this week's patch. Browser and Entra session hygiene are the standing war.
The week in one assessment
Three threads, one pattern: attackers keep buying the control plane (RMM, IdP session, renderer) instead of writing a new implant for each victim.
1. Most important development
N-central. An MSP or internal IT console that can script, remote, and push to every downstream endpoint is a domain controller with a web UI. Four hotfixes in five weeks, including a max-severity pre-auth RCE one day after an auth-bypass pair, is not a tidy Patch Tuesday. Huntress investigated a live compromise on 4 September; Hotfix 3 went out 5 September; Hotfix 4 6 September. On-prem operators who applied HF3 on Friday still needed HF4 on Saturday. That is the operational fact.
2. Active exploitation
CONFIRMED Chrome CVE-2026-85046 — Google: exploit in the wild. Sixth Chrome 0-day this year.
CONFIRMED N-central CVE-2026-18577 — CISA KEV (August). Huntress: exploitation of the August/early-September N-central waves in customer environments.
REPORTED / disputed: CVE-2026-86218 in production. N-able incident text vs release notes vs Huntress. Treat as exploited until your own telemetry says otherwise.
REPORTED Citrix NetScaler CVE-2026-19490 auth bypass leveraged in attacks (Previdian via BleepingComputer, 4 September). Edge devices do not get a week off because RMM is louder.
REPORTED BigBear 2.0 and Knight Office session theft.
3. Threat actor / campaign activity
Identity kits keep multiplying after Tycoon2FA's spring disruption. Knight Office is Docusign-themed AiTM plus device-code phishing; Huntress counted at least nine identity attacks on that kit in two weeks. BigBear 2.0 is PhaaS against M365 MFA. Magento StyleSmuggler is a separate commerce-RCE cluster (see Daily Top) — do not mash it into the RMM story.
UNKNOWN a single actor behind all N-central waves. Do not invent one.
4. Vulnerabilities to prioritize
- N-central → 2026.3.1.14. Audit admin accounts created since 1 August. Pull internet-facing N-central off WAN.
- Chrome / Edge Chromium → 152.0.7977.82+ across the estate this week, not next month.
- Citrix NetScaler CVE-2026-19490 — if Previdian's in-the-wild note holds, treat as KEV-speed even if CISA has not listed it yet. Verify against your ADC inventory.
- Exchange CVE-2026-62911 — Shadowserver ~22,000 internet-facing unpatched (August auth bypass / NTLM relay via MRSProxy). Still unpaid debt.
No invented CVEs. If a number is only in a secondary recap, it is REPORTED.
5. Identity / cloud / enterprise
Session cookies still beat passwords. Knight Office's path (trusted SaaS redirect → AiTM → token) is the same class as Tycoon2FA with new paint. Conditional Access that ignores token replay will keep losing. Device-code phishing belongs in the tabletop. Dropbox (~5,000 accounts in the week's "in other news") is commodity account takeover, not your IdP — unless those accounts hold shared links into the enterprise.
6. Ransomware / criminal activity
Manchester Airports Group: ~8.8 million people, ~550 GB published after a refused ransom; initial access claimed as exposed admin keys (SecurityWeek). That is criminal extortion on a transport operator's IT, not confirmed OT/ATC impact. Nidec Taiwan subsidiary: Blackfield $2M demand — manufacturing IT. Rhysida vs Berlin government data. Infostealer → session → ransomware remains the pipeline; this week's StealC/Amadey disruption (June) does not cancel September kits.
7. Defensive priorities
- N-central HF4 + admin-account diff + WAN exposure.
- Forced Chrome 152.
- Entra: CAE, token binding where you have it, block legacy device-code if unused.
- NetScaler and remaining Exchange on the internet.
- Magento/Adobe Commerce owners: StyleSmuggler Daily Top, not this RMM ticket.
8. What changed from last week
There was no prior RWP weekly IT cycle on this site — this is the first. Versus late August: N-central moved from "KEV auth bypass, patch hosted" to "on-prem still hunting a 10.0 the day after the last hotfix." Chrome added a sixth 0-day. Identity kits did not pause for the holiday.
9. What we are watching next
Whether CISA puts 86218 on KEV. Whether Huntress publishes the HF3/HF4 exploit chain. NetScaler exploitation volume. Whether BigBear 2.0 numbers hold under a named vendor report. Friday's weekly OT for the industrial read of the same week.
10. RWP assessment
Confidence: High on N-central patch urgency and Chrome in-the-wild. Medium on unifying the RMM CVEs into one campaign. The week does not require a new SIEM use-case. It requires the RMM and the browser to be patched, and the IdP to assume stolen sessions.
This assessment covers 31 August–7 September 2026 and was published 7 September 2026.
Sources
- N-able — N-central 2026.3 Hotfix 4 / CVE-2026-86218
- The Hacker News — Fourth N-central hotfix in five weeks
- Huntress / CSO Online — N-central auth-bypass chain and Hotfix 3–4
- BleepingComputer — Chrome CVE-2026-85046 exploited in the wild
- BleepingComputer — BigBear 2.0 Microsoft 365 phishing
- The Hacker News — Knight Office AiTM kit
- RWP — StyleSmuggler Magento/Adobe Commerce RCE
- CISA KEV — CVE-2026-18577 N-central (August addition)