The item to act on tonight is MikroTik. CERT Polska says a two-bug chain it calls MikroTrick is being used to take over RouterOS devices with SSH exposed, and it traces successful attacks back to at least September 2 — the day before MikroTik shipped the fix. Nothing else published today is being exploited. That is why it leads over a 9.8 unauthenticated SQL injection in IBM’s Operational Decision Manager, which sits on top of underwriting, pricing, and benefits databases, and over a payroll-vendor breach at the parent of JCPenney, Brooks Brothers, and four other retail brands that exposed passports, Alien Registration numbers, and digital signatures. Both of those matter. Neither is happening to a reader’s network right now. An exposed RouterOS SSH port is.
The MikroTik story also settles an argument about silent patching. MikroTik withheld the details deliberately, writing that “To give time to update your systems, we are not currently publishing detailed information.” The withholding bought about one day: a researcher binary-diffed the releases on September 4 and published working proof-of-concept code for three of the fixes, and the CERT Polska advisories landed the next day.
Across the rest of the day there is a thread, and it is the fix line. In six of today’s twelve stories, the part of the record that tells an administrator what to install is the part that breaks. N-able’s release notes describe an unauthorized party gaining “full access to the N-central platform,” while its own CVSS vectors say one flaw needs an account and the other only reads. Post Grid’s new 9.8 carries two contradictory version ranges, and the higher ceiling names a release the plugin has never shipped. IBM lists seven affected Operational Decision Manager versions and six interim fixes, and 9.5.0.0 is the one with no row. Cua’s named fix version changed a bind default rather than the missing authentication. Mail Mint’s fix shipped in a release whose only security bullet describes something else, and Mstore API’s arrived as one line inside a feature release of roughly twenty-five items.
In practical order after RouterOS: on-premises N-central operators should take HF3, build 2026.3.1.13, whatever the scoring argument says, because an MSP’s remote monitoring console reaches every endpoint it manages. Then the WordPress plugins that do have installable fixes — Hummingbird 3.21.2, where a guard checked for a class in the wrong namespace and an unauthenticated cookie name became executable PHP; Mstore API 4.21.0, where a Firebase token check validated four claims and never verified the signature; and Mail Mint 1.31.1. Then IBM’s interim fixes. Then the group where there is nothing to install and network position is the only lever: Coolify’s OAuth callback, which signs a user in on an email match alone and whose affected ceiling is the current release; the Cua and AutoAgent agent sandboxes, listening on every interface with authentication off; and AVideo, whose statistics endpoint returns every viewer’s password hash and whose 30-day CVE total reached 46 today, none of them naming a version to upgrade to. Lowest priority: four comment-XSS records in W3 Total Cache, CleanTalk, and iubenda, each gated behind a non-default setting or moderator approval.
Still open: Catalyst Brands has named neither the payroll vendor nor the number of people affected, and its own letter and the California Attorney General’s index disagree on the breach date. Coolify, AVideo, AutoAgent, and Post Grid all end the day with no build a reader can install — and in Post Grid’s case WPScan is telling site owners to move to 2.3.33, which does not exist. IBM has still not said what a 9.5.0.0 operator should do. And the MikroTik chain has working public exploit code against devices that, on CERT Polska’s account, were already being taken over before the patch existed.
