Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
N-able patched three critical N-central vulnerabilities (CVE-2026-86206, CVE-2026-86207, CVE-2026-86218), including a CVSS 10.0 pre-auth RCE flaw, with evidence of active exploitation observed by Huntress Google patched CVE-2026-85046, a type confusion bug in Chrome's V8 engine under active exploitation, marking the sixth actively exploited Chrome zero-day of 2026 The MikroTrick exploit chain leverages two zero-day flaws (CVE-2026-67276, CVE-2026-86060) in MikroTik RouterOS to bypass authenticat
Analysis
TL;DR
- N-able patched three critical N-central vulnerabilities (CVE-2026-86206, CVE-2026-86207, CVE-2026-86218), including a CVSS 10.0 pre-auth RCE flaw, with evidence of active exploitation observed by Huntress
- Google patched CVE-2026-85046, a type confusion bug in Chrome's V8 engine under active exploitation, marking the sixth actively exploited Chrome zero-day of 2026
- The MikroTrick exploit chain leverages two zero-day flaws (CVE-2026-67276, CVE-2026-86060) in MikroTik RouterOS to bypass authentication and elevate privileges without credentials
- StyleSmuggler is an unpatched Magento/Adobe Commerce zero-day enabling unauthenticated RCE via a two-stage PHP code injection through template styles, deploying a Rust-based backdoor to a C2 server
- RevStealer (REF2859) is a sophisticated Windows information stealer using Polygon blockchain dead drops (EtherHiding), targeting gaming accounts and crypto wallets, distributed via fake game cheats and a counterfeit Claude Desktop app
Why It Matters
This week's threat landscape demonstrates a clear escalation in zero-day exploitation across browsers, network infrastructure, and e-commerce platforms, with multiple vulnerabilities being actively weaponized before patches were available. The convergence of supply chain compromise (trusted software source delivering credential-stealing code) and novel evasion techniques (text-based QR codes bypassing image filters, blockchain-based C2 resilience) signals that threat actors are increasingly targeting both technical and human-layer defenses simultaneously.
Technical Details
- N-able N-central: CVE-2026-86206 and CVE-2026-86207 enable authentication bypass for full platform access; CVE-2026-86218 (CVSS 10.0) allows pre-authenticated remote code execution. Huntress observed compromise of a fully patched environment, suggesting possible alternative exploit vectors.
- Chrome CVE-2026-85046: Type confusion vulnerability in the V8 JavaScript/WebAssembly engine (CVSS 8.8) allowing arbitrary code execution inside the sandbox via a crafted HTML page. Discovered by researcher Salvatore Gulizia (Serotav) on August 4, 2026.
- MikroTrick (MikroTik RouterOS): Exploit chain combining CVE-2026-67276 and CVE-2026-86060 (both CVSS 9.2) to bypass SSH authentication and escalate privileges. Six total flaws patched; attacks traced to IP 82.192.72.4 since September 2, 2026, including creation of a rogue "ops" account.
- StyleSmuggler (Magento/Adobe Commerce): Two-stage attack — (1) inject poisoned PHP code via styles properties to evade safeguards, (2) trigger execution through failed payment email templates. Deploys a Rust backdoor connecting to C2 at 99.84.67[.]186, with two variants (fc-cache, chronyd). A separate cluster drops PHP web shells into product image caches.
- RevStealer (REF2859): Windows info stealer with embedded sandbox scoring and Polygon blockchain dead drop (EtherHiding). Modules include C2 tasks for wallet/browser extension theft and phishing overlays, WinUpdate for cryptocurrency address replacement, SoftManager for reverse SOCKS5 proxy over encrypted WebSocket, and LockAppHost for XMRig deployment and competitor suspension.
Industry Insight
- Organizations relying on N-central, MikroTik routers, or Magento/Adobe Commerce should prioritize immediate patching and audit logs for signs of compromise, especially the creation of unauthorized accounts or unexpected outbound connections to known C2 infrastructure.
- The proliferation of blockchain-based dead drops (EtherHiding) in malware C2 architectures represents an emerging resilience technique that security teams should monitor, as it complicates traditional domain-based blocking and takedown strategies.
- The use of counterfeit AI tooling (fake Claude Desktop app) and game cheat distribution as malware delivery vectors indicates threat actors are strategically targeting high-trust communities; security awareness programs should address these specific social engineering vectors alongside traditional phishing training.
Disclaimer: The above content is generated by AI and is for reference only.