11 Sep 2026

Week in review

Greetings,

This week, Mathspace disclosed a data breach affecting about 1.08 million students, carers and staff in Australia and New Zealand.

Information stolen includes names, email addresses, usernames, account types and countries . While no passwords or sign-on credentials were accessed, the exposed information could be used to create convincing phishing emails impersonating Mathspace.

The attackers accessed the data by exploiting a flaw in Mathspace’s self-hosted installation of Metabase. While Metabase had disclosed the vulnerability and provided a patch, Mathspace had not installed the patch at the time of the attack. Attackers exploited the vulnerability days after it was disclosed and patched by Metabase on 6 August.

This breach follows a ransomware attack on education platform Canvas earlier this year. These incidents highlight the value of sensitive information held by education platforms and the attractiveness of the education sector to cyber criminals.

The Metabase vulnerability allowed attackers to gain administrator access to the affected system without legitimate credentials. Mathspace said its vulnerability-notification process did not identify and escalate the Metabase advisory for action. The company later secured the affected system, took it offline and notified affected users and relevant authorities. Mathspace said there is currently no evidence that the stolen information has been published, sold or misused. However, affected users should remain alert to phishing and impersonation attempts using the exposed information.


Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Date: 2026-09-07
Author: Security Week

Threat actors are exploiting a zero-day vulnerability in Adobe Commerce and Magento e-commerce platforms to backdoor online stores, cybersecurity firm Sansec reports.
Dubbed StyleSmuggler, the security defect enables attackers to inject PHP code into Magento’s template system and evade detection by using the ‘styles’ properties.
According to Sansec, the attack works in two stages: first, the PHP code is injected by generating a failure report, and then Magento executes the code via a failed payment email.

N-able patches max severity N-central flaw amid ongoing attacks
Date: 2026-09-07
Author: Bleeping Computer

N-able has released an emergency hotfix for a maximum-severity remote code execution (RCE) flaw affecting its N-central remote monitoring and management (RMM) platform.
IT departments and managed service providers (MSPs) use the N-central platform to monitor, manage, and maintain client networks and devices from a centralized web-based console.
Tracked as CVE-2026-86218, this RCE vulnerability allows threat actors without privileges to execute malicious code on unpatched N-central instances exposed online in low-complexity attacks.

Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
Date: 2026-09-06
Author: The Hacker News

[AUSCERT has notified potentially affected members]
Attackers are exploiting MikroTik routers with their Secure Shell (SSH) remote-access service, which is reachable from the internet, to gain full administrative control without authentication, according to CERT Polska's attack warning, published on September 5.
Successful attacks date to at least September 2. The Hacker News’s September 6 review of the warning found no victim count or attacker identity.
MikroTik's security update lists fixed RouterOS releases. CERT says the fixes prevent the observed attacks and recommends immediate installation, followed by a check for unauthorized configuration changes.

SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution
Date: 2026-09-09
Author: The Hacker News

SAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing that could have a severe impact on the confidentiality, integrity, and availability of the application
The vulnerability, tracked as CVE-2026-44756 (CVSS score: 10.0), has been described as a case of memory corruption. Discovered and reported by SAP security company Onapsis, it has been codenamed OVERPASS.

Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Date: 2026-09-08
Author: CyberScoop

[AUSCERT has published security bulletins for these Microsoft updates]
Microsoft addressed 974 defects across its product suite, including two actively exploited zero-day vulnerabilities, in its monthly Patch Tuesday security program.
The massive batch of patches, Microsoft’s largest ever, reflects a continuing trend for the vendor as it leans on artificial intelligence to discover more vulnerabilities at a faster rate. Yet, the recent period of record breaking vulnerability disclosures hasn’t resulted in a flood of actively exploited zero-days.


ESB-2026.10690 – Adobe Commerce: CVSS (Max): 10.0

Adobe has released a security update for Adobe Commerce and Magento Open Source. This update resolves critical, important, and moderate vulnerabilities.

ASB-2026.0220 – Microsoft Windows: CVSS (Max): 9.8

Microsoft has released 'Microsoft Windows' updates to resolve 726 vulnerabilities, as part of the Microsoft security patch updates for the month of September 2026.

ASB-2026.0212 – Microsoft Azure: CVSS (Max): 10.0

Microsoft has released 'Microsoft Azure' updates to resolve 12 vulnerabilities, as part of the Microsoft security patch updates for the month of September 2026.

ESB-2026.10780 – Palo Alto Networks PAN-OS: CVSS (Max): 9.2

A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service (DoS) condition.

ESB-2026.10661 – Linux kernel (GCP): CVSS (Max): 10.0

Ubuntu have provided an update(s) for several vulnerabilities that were discovered in the Linux kernel for Google Cloud Platform (GCP) systems.


Stay safe, stay patched and have a good weekend!

The AUSCERT team