IT Intelligence · IT

The IT week was RMM, session theft, and a sixth Chrome 0-day — not a quiet Labor Day

31 August–7 September 2026. N-central took four hotfixes in five weeks and a CVSS 10 pre-auth RCE. BigBear 2.0 and Knight Office kept eating Microsoft 365 sessions. Chrome CVE-2026-85046 is in the wild. Magento StyleSmuggler is the storefront story, not the enterprise one.

RWP Ventures · 2026-09-07 · 5 min read · priority 8.7

Executive summary

FACT: This week the highest-leverage enterprise problem was not a new nation-state wiper. It was the tools that already sit above every endpoint — RMM, the browser, and the Microsoft 365 session.

N-able N-central absorbed a fourth hotfix in five weeks. CVE-2026-86218 is a pre-auth RCE, CVSS 4.0 10.0, CWE-96, fixed in 2026.3 Hotfix 4 (build 2026.3.1.14) on 6 September. It is unrelated to CVE-2026-86206 / CVE-2026-86207 (auth bypass to internal APIs / admin creation), which Huntress tied to a 4 September customer compromise on a Hotfix-2 box and which Hotfix 3 (2026.3.1.13) addressed. N-able's own pages disagree on whether 86218 is exploited in production; Huntress and several recaps treat the RMM wave as exploited. Earlier CVE-2026-18577 is already on CISA KEV. Shadowserver: ~1,500 N-central instances on the internet. Hosted NCOD was auto-patched; on-prem is not.

Google shipped Chrome 152.0.7977.82/.83 for CVE-2026-85046, V8 type confusion, sixth in-the-wild Chrome 0-day of 2026. Identity: BigBear 2.0 reported against 258 organizations / 5,000+ M365 credentials; Knight Office AiTM (Docusign lures, Monday.com and Joomla redirects) joined EvilTokens/Kali365. Magento/Adobe Commerce StyleSmuggler is today's Daily Top — commerce RCE, not the RMM blast radius.

ASSESSMENT: If you run on-prem N-central below 2026.3.1.14, that is this week's patch. Browser and Entra session hygiene are the standing war.

The week in one assessment

Three threads, one pattern: attackers keep buying the control plane (RMM, IdP session, renderer) instead of writing a new implant for each victim.

1. Most important development

N-central. An MSP or internal IT console that can script, remote, and push to every downstream endpoint is a domain controller with a web UI. Four hotfixes in five weeks, including a max-severity pre-auth RCE one day after an auth-bypass pair, is not a tidy Patch Tuesday. Huntress investigated a live compromise on 4 September; Hotfix 3 went out 5 September; Hotfix 4 6 September. On-prem operators who applied HF3 on Friday still needed HF4 on Saturday. That is the operational fact.

2. Active exploitation

CONFIRMED Chrome CVE-2026-85046 — Google: exploit in the wild. Sixth Chrome 0-day this year.

CONFIRMED N-central CVE-2026-18577 — CISA KEV (August). Huntress: exploitation of the August/early-September N-central waves in customer environments.

REPORTED / disputed: CVE-2026-86218 in production. N-able incident text vs release notes vs Huntress. Treat as exploited until your own telemetry says otherwise.

REPORTED Citrix NetScaler CVE-2026-19490 auth bypass leveraged in attacks (Previdian via BleepingComputer, 4 September). Edge devices do not get a week off because RMM is louder.

REPORTED BigBear 2.0 and Knight Office session theft.

3. Threat actor / campaign activity

Identity kits keep multiplying after Tycoon2FA's spring disruption. Knight Office is Docusign-themed AiTM plus device-code phishing; Huntress counted at least nine identity attacks on that kit in two weeks. BigBear 2.0 is PhaaS against M365 MFA. Magento StyleSmuggler is a separate commerce-RCE cluster (see Daily Top) — do not mash it into the RMM story.

UNKNOWN a single actor behind all N-central waves. Do not invent one.

4. Vulnerabilities to prioritize

  1. N-central → 2026.3.1.14. Audit admin accounts created since 1 August. Pull internet-facing N-central off WAN.
  2. Chrome / Edge Chromium → 152.0.7977.82+ across the estate this week, not next month.
  3. Citrix NetScaler CVE-2026-19490 — if Previdian's in-the-wild note holds, treat as KEV-speed even if CISA has not listed it yet. Verify against your ADC inventory.
  4. Exchange CVE-2026-62911 — Shadowserver ~22,000 internet-facing unpatched (August auth bypass / NTLM relay via MRSProxy). Still unpaid debt.

No invented CVEs. If a number is only in a secondary recap, it is REPORTED.

5. Identity / cloud / enterprise

Session cookies still beat passwords. Knight Office's path (trusted SaaS redirect → AiTM → token) is the same class as Tycoon2FA with new paint. Conditional Access that ignores token replay will keep losing. Device-code phishing belongs in the tabletop. Dropbox (~5,000 accounts in the week's "in other news") is commodity account takeover, not your IdP — unless those accounts hold shared links into the enterprise.

6. Ransomware / criminal activity

Manchester Airports Group: ~8.8 million people, ~550 GB published after a refused ransom; initial access claimed as exposed admin keys (SecurityWeek). That is criminal extortion on a transport operator's IT, not confirmed OT/ATC impact. Nidec Taiwan subsidiary: Blackfield $2M demand — manufacturing IT. Rhysida vs Berlin government data. Infostealer → session → ransomware remains the pipeline; this week's StealC/Amadey disruption (June) does not cancel September kits.

7. Defensive priorities

  1. N-central HF4 + admin-account diff + WAN exposure.
  2. Forced Chrome 152.
  3. Entra: CAE, token binding where you have it, block legacy device-code if unused.
  4. NetScaler and remaining Exchange on the internet.
  5. Magento/Adobe Commerce owners: StyleSmuggler Daily Top, not this RMM ticket.

8. What changed from last week

There was no prior RWP weekly IT cycle on this site — this is the first. Versus late August: N-central moved from "KEV auth bypass, patch hosted" to "on-prem still hunting a 10.0 the day after the last hotfix." Chrome added a sixth 0-day. Identity kits did not pause for the holiday.

9. What we are watching next

Whether CISA puts 86218 on KEV. Whether Huntress publishes the HF3/HF4 exploit chain. NetScaler exploitation volume. Whether BigBear 2.0 numbers hold under a named vendor report. Friday's weekly OT for the industrial read of the same week.

10. RWP assessment

Confidence: High on N-central patch urgency and Chrome in-the-wild. Medium on unifying the RMM CVEs into one campaign. The week does not require a new SIEM use-case. It requires the RMM and the browser to be patched, and the IdP to assume stolen sessions.

This assessment covers 31 August–7 September 2026 and was published 7 September 2026.

Sources

  1. N-able — N-central 2026.3 Hotfix 4 / CVE-2026-86218
  2. The Hacker News — Fourth N-central hotfix in five weeks
  3. Huntress / CSO Online — N-central auth-bypass chain and Hotfix 3–4
  4. BleepingComputer — Chrome CVE-2026-85046 exploited in the wild
  5. BleepingComputer — BigBear 2.0 Microsoft 365 phishing
  6. The Hacker News — Knight Office AiTM kit
  7. RWP — StyleSmuggler Magento/Adobe Commerce RCE
  8. CISA KEV — CVE-2026-18577 N-central (August addition)