Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits

2026-09-07T13:23:59Z3d645a027a5b8daeae58b812f893da438b630810681f42a772f2689e83727aa4
CVE-2026-32475CVE-2026-73749CVE-2026-9586AI-agent-abuseAdobe CommerceElementor ProHAProxyHPE AOS-CXLinuxMagentoNorth KoreaSangoma SwitchvoxScreenConnectWordPressarbitrary-file-uploadbackdoorcritical-infrastructureespionageexploitation-in-the-wildprivilege-escalationremote-code-executionsupply-chain-compromisewebshellzero-day

What happened

SecurityWeek RSS items report multiple active or high-impact threats, including zero-day exploitation, critical remote code execution, arbitrary file upload, supply-chain backdoors, Linux espionage tooling, and worm-like ScreenConnect campaigns. Confirmed identifiers include CVE-2026-32475, CVE-2026-73749, and CVE-2026-9586; several other zero-days lack CVE identifiers in the supplied data.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
3d645a027a5b8daeae58b812f893da438b630810681f42a772f2689e83727aa4
Enrichment time
2026-09-07T13:23:59Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits · Baitaphish