v vanemmerik.ai / SUPPLY-CHAIN
Supply Chain Β· Watch Saturday Β· 05 September 2026 End-of-day synthesis 4 watches Β· 2 items

From the watchtower β€” what crossed the wire today.

A four-times-a-day standing watch on the open-source supply chain. Each pass pulls newly disclosed CVEs, freshly catalogued KEV adds, and active attacks reported in the wild β€” then ranks them by severity for the day.

The story of the day β€” A live, unauthenticated, patch-less Magento zero-day landed the same afternoon a Switchvox KEV hit its remediation deadline β€” one bug you can still fix, one you can only shield.

A quiet day by item count β€” two entries β€” but both carry real urgency and they landed within hours of each other. CISA's BOD 26-04 deadline for the unauthenticated Sangoma Switchvox SQL injection (CVE-2026-9586) closed out today, and separately Sansec disclosed a zero-day already being exploited against production stores.

StyleSmuggler is the one to watch overnight: an unauthenticated RCE in Magento Open Source and Adobe Commerce, smuggled through a template's `styles` property and detonated by Magento's own automated β€œPayment Transaction Failed Reminder” email, so no admin has to click anything. Attacks started September 4 and are ongoing, and as of publication Adobe has issued no CVE, no advisory, and no patch β€” Sansec's Shield WAF rules are the only mitigation on the table, which is a rare and uncomfortable position for a platform this widely deployed.

β†’ Operational priority for the night confirm Switchvox is on 8.4.0.2+ or off the internet before the BOD deadline closes the loop, and if you run Magento or Adobe Commerce, deploy Sansec's Shield rules now and alert on unexpected admin/template writes triggered by payment-failure emails β€” there is no vendor fix to fall back on yet.

18:00 ET Β· First Watch

StyleSmuggler: unauthenticated, unpatched Magento/Adobe Commerce zero-day under active exploitation

Sansec disclosed StyleSmuggler, an unauthenticated remote code execution affecting all current Magento Open Source and Adobe Commerce builds including 2.4.9: it smuggles malicious code through a template's `styles` property, then detonates it when Magento auto-sends its own "Payment Transaction Failed Reminder" email, so no admin has to open or click anything. Attacks began September 4 and are ongoing against live stores, and as of publication Adobe has issued no CVE, no advisory, and no patch β€” an unauthenticated RCE in a major e-commerce platform with zero vendor mitigation to fall back on. If you run Magento or Adobe Commerce, deploy Sansec's Shield WAF rules now and alert on unexpected admin/template writes triggered by payment-failure emails.

06:00 ET Β· Morning Watch

CISA KEV: Sangoma Switchvox unauthenticated SQL injection to RCE (CVE-2026-9586)

CISA added CVE-2026-9586 to the KEV catalog on September 2 but it slipped past this pipeline's backfill window until now: an unauthenticated SQL injection in Sangoma Switchvox lets a single crafted request run arbitrary SQL against the backend PostgreSQL database, up to and including remote code execution. Switchvox is an on-prem PBX/UC appliance β€” exactly the class of internet-facing box that gets deployed once and forgotten β€” and CISA's BOD 26-04 remediation deadline for this one is today, September 5. The vendor fix has been out since the 8.4.0.2 release in July; if you're still running an older build, patch or pull it off the internet now rather than waiting for confirmation it's being exploited against you specifically.