WordPress Core RCE Under Active Exploitation, WSO2 and Adobe Commerce Added to KEV, TeamCity Flaw Tied to Ransomware

This brief covers security developments from September 23–25, 2026. Every item was checked against the vendor advisory, the CISA KEV catalog, or the original research, with reputable outlets linked for context.

Attackers move from probing to payloads on WordPress core flaw CVE-2026-87902

WordPress / Patchstack · September 23, 2026

CVE-2026-87902 is an unauthenticated path traversal flaw in WordPress core page-template resolution. It affects versions 4.7.0 through 7.1.1, and the WordPress security team rates it critical (CVSS v4.0 9.2). WordPress 7.1.2 fixed it on September 22, and the fix was backported to every branch down to 4.7. Patchstack saw reconnaissance start within hours of the patch. By September 23, traffic had grown tenfold and included pearcmd.php-based payloads that write PHP files to /tmp and /var/tmp. Remote code execution requires specific theme and server conditions, such as a theme directory whose name starts with page- and PHP’s register_argc_argv setting being enabled. None of the sources reviewed reported a CISA KEV listing.

“Because this is a security release, it is recommended that you update your sites immediately.” — WordPress.org, 7.1.2 release notes

Source: WordPress 7.1.2 Release · GHSA-7hp8-65ch-5whp · BleepingComputer

CISA adds WSO2 API Manager auth bypass CVE-2026-5430 to KEV

CISA / WSO2 · September 24, 2026

CISA added CVE-2026-5430 to the Known Exploited Vulnerabilities catalog after evidence of active exploitation. Federal agencies must patch by September 27. WSO2’s advisory scores the flaw CVSS 3.1 10.0, or 9.8 in single-tenant deployments. It describes a JWT authentication bypass: a token signed with an unsupported algorithm is accepted, which can lead to takeover of administrative accounts. CISA’s KEV entry calls it a path traversal. Affected products are WSO2 API Control Plane 4.5.0–4.6.0, API Manager 4.1.0–4.6.0, Traffic Manager 4.5.0–4.6.0, and Universal Gateway 4.5.0–4.6.0. watchTowr reported in-the-wild attempts against its honeypots since at least September 13.

“JWT authentication can be bypassed when a token is signed using an unsupported algorithm, allowing unauthorized access.” — WSO2 Security Advisory WSO2-2026-5328

Source: WSO2-2026-5328 · CISA alert · The Hacker News

Adobe Commerce / Magento session-switching flaw CVE-2026-71362 added to KEV

CISA / Adobe · September 24, 2026

CISA added CVE-2026-71362, an incorrect authorization flaw in Adobe Commerce and Magento Open Source (CVSS 9.1), to the KEV catalog in the same September 24 update. The federal remediation deadline is September 27. The bug lets an unauthenticated attacker switch a customer session to another customer’s account. Sansec reported blocking exploitation attempts in August, shortly after Adobe’s APSB26-92 fix. Adobe has not yet updated its advisory to confirm exploitation. The fix is to install the -2026-aug security release or the APSB26-92 isolated patch.

“The vulnerability lets attackers switch a customer session to another customer account.” — Sansec

Source: CISA alert · Sansec research · The Hacker News

CISA marks JetBrains TeamCity CVE-2026-63077 as used in ransomware campaigns

CISA / JetBrains · September 23, 2026

CISA updated the KEV entry for CVE-2026-63077 to show that it is “Known” to be used in ransomware campaigns. The flaw is a critical authentication bypass in TeamCity On-Premises that JetBrains patched on July 25 in versions 2025.11.7 and 2026.1.3. It allows unauthenticated OS command execution through the agent polling protocol. The CVE was first added to KEV on August 5. Shadowserver still tracks about 160 unpatched internet-exposed servers.

“An unauthenticated attacker could exploit the vulnerability via the TeamCity agent polling protocol to bypass authentication checks and execute arbitrary operating system commands.” — JetBrains

Source: CISA KEV entry · JetBrains update · BleepingComputer

Still developing

Check Point confirms exploitation of Security Gateway VPN RCE and a Management Server zero-day

Check Point · September 22, 2026

Check Point Research confirmed exploitation of two flaws, both rated CVSS 9.8. The first, CVE-2026-85102, is a pre-authentication RCE in Security Gateway and Spark VPN certificate handling. It was patched September 9, and exploitation attempts against Spark customers started September 12. The second, CVE-2026-93616, is a pre-authentication path traversal zero-day in the Management web service that allows arbitrary script execution and Java class loading. It was used in a handful of targeted attacks on July 23 and is fixed via sk1000171. CISA added both to KEV on September 22 with a September 25 due date.

“Customers running affected versions should install the applicable fixes immediately.” — Lotem Finkelstein, Check Point Research

Source: Check Point advisory · sk1000117 · sk1000171 · BleepingComputer

F5 BIG-IP APM OAuth Authorization Server zero-day CVE-2026-94127

F5 · September 22, 2026

F5 patched CVE-2026-94127, a heap-based buffer overflow in BIG-IP APM (CVSS 3.1 9.8 / CVSS 4.0 9.3). Unauthenticated attackers can get RCE when APM is configured as an OAuth Authorization Server. F5 confirmed in-the-wild exploitation and published indicators of compromise plus an iRule mitigation. CISA added the flaw to KEV on September 22. Shadowserver sees roughly 14,700 IPs with BIG-IP APM fingerprints.

“We have learned that this vulnerability has been exploited.” — F5, K000162605

Source: F5 K000162605 · BleepingComputer

ShinyHunters claims FBI breach via unpatched Oracle PeopleSoft zero-day

BleepingComputer · September 22, 2026

The ShinyHunters extortion group claims it used a new Oracle PeopleSoft RCE zero-day to reach FBI systems and FBI-managed AWS GovCloud infrastructure. It says it stole 2–3 TB of employee and applicant data. The FBI says it is investigating “claims regarding unauthorized activity affecting FBIjobs.gov” but has not confirmed a breach. Oracle has not published an advisory or CVE, and the zero-day has not been independently verified.

Source: BleepingComputer


This brief covers the trailing ~48 hours (September 23–25, 2026).

Primary sources:

Anthropic Launches Claude Opus 5.5, OpenAI Ships GPT-6 Sol and Luna at Half Price, and Claude Agents Find a CRISPR-Like Enzyme System

This brief covers the trailing ~72 hours (September 22–25, 2026). Every item below was confirmed on the originating organization’s own page, with a published date inside the window. Two frontier releases landed on the same day: Anthropic introduced Claude Opus 5.5, the first model in its Claude 5.5 family, and OpenAI extended its GPT-6 generation downmarket with GPT-6 Sol and GPT-6 Luna at 50% lower API prices. Anthropic also unveiled a life sciences lab and early results in which Claude agents found a previously unrecognized enzyme system. At the UN, Sam Altman addressed the Security Council and OpenAI extended its Daybreak cyber-defense program to Ukraine, and Google added real-time video avatars to Gemini 3.8 Live.

Anthropic introduces Claude Opus 5.5: Fable 5.1-level performance at 40% lower cost than Opus 5

Anthropic · September 22, 2026

Opus 5.5 is the first model in the Claude 5.5 family and Anthropic’s first release since it called for “pacing the frontier.” Anthropic reports 66.4% on Terminal-Bench 4.0, 54.4% on FrontierCode v1.1, 57.8% on CursorBench 4.0, and a GDPval-AA v2.1 Elo of 1846, ahead of Fable 5.1, Opus 5, and GPT-6 Astra on most of those measures. Pricing drops to $4/$20 per million input/output tokens with cache reads at $0.20 (60% below Opus 5), output is over 30% faster, and the model scored best to date on Anthropic’s automated behavioral audit. Because its biology and cyber capabilities are comparable to Claude Mythos 5.1, it ships with Fable 5.1-class safeguards that transparently fall back to other models; Sonnet 5.5 and Haiku 5.5 are due in the coming weeks.

“It performs at the level of Claude Fable 5.1 on most work and costs 40% less to run than Opus 5.” — Anthropic

Source: Introducing Claude Opus 5.5

OpenAI releases GPT-6 Sol and GPT-6 Luna, cutting API prices 50% versus GPT-5.6

OpenAI · September 22, 2026

OpenAI expanded the GPT-6 family with two cheaper tiers trained with methods similar to GPT-6 Astra. GPT-6 Sol is priced at $2/$10 per million input/output tokens and GPT-6 Luna at $0.10/$0.50, both half the GPT-5.6 promotional prices. OpenAI reports Sol scoring 33.2% on Zapier’s AutomationBench at $0.27 per task and 68.8% on DeepSWE v1.1, and says Sol makes about half as many factual mistakes as its predecessor on its internal evaluation. The launch also brings improved prompt caching with 90% discounts on cached reads and cache-preserving changes to reasoning effort and tools; the models are live in ChatGPT Work, Codex, and the API as gpt-6-sol and gpt-6-luna.

“GPT-6 Astra introduced a new generation of intelligence—these models help distribute the benefits of that intelligence by advancing the frontier on cost efficiency.” — OpenAI

Source: Introducing GPT-6 Sol and Luna

Claude agents discover a novel enzyme system with CRISPR-like repeats as Anthropic unveils a life sciences lab

Anthropic · September 23, 2026

Anthropic introduced a new life sciences research group and Bay Area wet lab focused on AI-driven genome mining. In its first reported result, roughly 950 Claude agents spent 21 hours and 210 million tokens surveying over 200,000 reverse transcriptases, narrowing 3,500 candidate systems to 20 detailed reports. One agent spotted a tandem repeat array next to an unusual RT in jumbo phages, a system Anthropic calls array-associated reverse transcriptases (ART). Initial lab experiments show the array is expressed as distinct short RNAs, suggesting a possibly programmable mechanism; its function is still under investigation, and a pre-print has been released.

“This is an exciting example of how AI agents can contribute to biological discovery.” — Feng Zhang, MIT and the Broad Institute

Source: Claude discovers a novel enzyme system with CRISPR-like repeats

Sam Altman addresses the UN Security Council, calling for international frontier AI standards

OpenAI · September 23, 2026

In remarks to the Security Council, Altman named two failure modes to avoid: losing control of the future to AI, especially as systems approach recursive self-improvement, and excessive concentration of power. He said OpenAI has unilaterally slowed down before and will again, and called for complementary national and international frontier AI standards covering capability measurement, risk assessment, safeguard sufficiency, incident reporting, and secure channels for sharing emerging threats, without locking in incumbents.

“Beating companies in a competitive pace is not a reason to make rash decisions.” — Sam Altman, OpenAI

Source: Sam Altman’s remarks at the United Nations Security Council

OpenAI extends its Daybreak cyber-defense program to the Government of Ukraine

OpenAI · September 23, 2026

Announced on the sidelines of the UN General Assembly, the arrangement with Ukraine’s Ministry of Digital Transformation gives Ukrainian teams access to OpenAI’s Daybreak tools for finding software vulnerabilities and developing and testing fixes to protect civilian infrastructure. OpenAI noted its cyber models are already used by defenders in France, Germany, and Poland, and by the EU cyber agency ENISA, and that CERT Polska used them to help find six vulnerabilities in third-party router software.

“Ukraine is already on the front line, and its defenders need support now.” — Sasha Baker, Head of National Security Policy, OpenAI

Source: OpenAI extends cyber access to Ukraine for civilian defense

Google adds Live Avatar to Gemini 3.8 Live for real-time, lip-synced video agents

Google · September 24, 2026

Google paired its Gemini 3.8 Live native dialogue model with low-latency streaming video, producing enterprise agents that listen, see, and speak through an animated persona with lip-sync and facial expressions. The feature supports asynchronous tool calling so the avatar keeps talking while fetching data in the background, switches among 97 languages mid-conversation, and can generate custom avatars from a reference image for allowlisted enterprises. All audio and video output is watermarked with SynthID, and the feature is available now in Gemini Enterprise.

“Starting today, Gemini 3.8 Live with Live Avatar is available in Gemini Enterprise.” — Google

Source: Introducing Gemini 3.8 Live with Live Avatar


This brief covers the trailing ~72 hours (September 22–25, 2026).

Primary sources:

F5 BIG-IP APM RCE, Arista VeloCloud and Check Point Management Zero-Days Hit CISA KEV

This brief covers September 22–23, 2026. Every item below was checked against CISA’s KEV alert and the vendor advisory as reported. On September 22, CISA added four actively exploited flaws to the Known Exploited Vulnerabilities catalog. Three are zero-days in edge and management infrastructure: F5 BIG-IP APM, Arista VeloCloud Orchestrator, and Check Point Management Server. Federal agencies were given three days to patch under BOD 26-04.

F5 BIG-IP APM: unauthenticated RCE exploited as a zero-day (CVE-2026-94127)

F5 / CISA · September 22, 2026

CVE-2026-94127 (CVSS 9.8) is a heap-based buffer overflow in BIG-IP Access Policy Manager. An unauthenticated attacker can use it for remote code execution when an APM access policy and an OAuth profile are configured on a virtual server. Only deployments using APM as an OAuth Authorization Server are affected; Appliance mode is also vulnerable. Affected versions are 21.1.0, 17.5.0–17.5.1 and 17.1.0–17.1.3. F5 has shipped hotfixes and published three indicators of compromise (IoCs). The flaw is actively exploited and was added to KEV on September 22.

“We have learned that this vulnerability has been exploited.” — F5 advisory K000162605

Source: F5 K000162605 · SecurityWeek

Arista VeloCloud Orchestrator On-Prem: CVSS 10 zero-day under active attack (CVE-2026-93952)

Arista / CISA · September 22, 2026

CVE-2026-93952 (CVSS 10) is an improper input validation flaw in on-premises VeloCloud Orchestrator (VCO). It lets remote attackers reach privileged internal functionality without tenant or operator credentials. Only instances using certificate-based Edge-to-VCO authentication are exposed. The flaw is fixed in VCO 5.2.3.16 and 6.4.2.8, and patches for other trains are coming. Arista has published no definitive IoCs and recommends reviewing web, application and system logs. The flaw is actively exploited and was added to KEV on September 22.

“This issue was discovered externally and is known to be actively exploited.” — Arista Security Advisory 0183

Source: Arista Security Advisory 0183 · SecurityWeek

Check Point Management Server: pre-auth path traversal and file upload zero-day (CVE-2026-93616)

Check Point / CISA · September 22, 2026

CVE-2026-93616 (CVSS 9.8) is a directory traversal and file upload flaw. It lets unauthenticated attackers upload and run arbitrary scripts on Security Management Server, Multi-Domain Security Management, Log Server, Multi-Domain Log Server and SmartEvent. Fixes are in the R82.20 Security Hotfix and in Jumbo Hotfix Takes for R82.10, R82, R81.20 and R81.10. Standard LivePatch updates do not fix it. As interim mitigation, restrict TCP/19009 to trusted IPs. The flaw is actively exploited against a small number of customers and was added to KEV on September 22.

“This vulnerability is exploited in the Wild. Check Point is aware of a handful of customers who have been attacked.” — Check Point sk1000171

Source: Check Point sk1000171 · SecurityWeek

Check Point Security Gateway / Spark VPN auth bypass now exploited (CVE-2026-85102)

Check Point / CISA · September 22, 2026

CVE-2026-85102 (CVSS 9.8) is improper certificate validation during VPN negotiation. It allows unauthenticated authentication bypass and code execution on Security Gateway and Spark firewalls. Check Point patched it on September 9 and at that time had no evidence of exploitation. It now reports exploitation attempts against Spark customers worldwide. The flaw was added to KEV on September 22.

“We are now observing exploitation attempts against Check Point Spark customers globally.” — Check Point

Source: Check Point advisory blog · CISA KEV alert

Still developing

Zyxel GS1900 switch stack overflow added to KEV (CVE-2026-7273)

CISA · September 21, 2026

CISA added CVE-2026-7273, a stack-based buffer overflow in Zyxel GS1900 Series switches, to the KEV catalog based on evidence of active exploitation. SecurityWeek has linked the exploitation to Chinese threat actors. GS1900 owners should apply Zyxel’s fixed firmware.

Source: CISA KEV alert

Brevo supply-chain attack served ClickFix malware through embedded scripts

Brevo / Sansec · September 18, 2026

Attackers used a compromised long-lived Cloudflare API key to deploy a worker. The worker injected malicious scripts into brevo.com, sibforms.com and three JavaScript files that customers embed on their sites. The scripts showed selected visitors fake “verify you are human” ClickFix pages. On WordPress sites where the visitor was a logged-in admin, they tried to install a plugin. Sansec estimates more than 100,000 sites were affected. Sites that embed Brevo widgets should check for unauthorized plugins.

Source: Brevo post-mortem · Sansec · SecurityWeek


This brief covers the trailing ~48 hours (September 22–23, 2026).

Primary sources:

Check Point Management Zero-Day, F5 BIG-IP APM Heap Overflow, and Arista VeloCloud CVSS 10.0 Land in CISA KEV; WordPress 7.1.2 Path Traversal Under Active Attack

This brief covers the trailing ~48 hours (September 22–23, 2026). Every item below was checked against its primary source — the vendor advisory, CISA’s Known Exploited Vulnerabilities (KEV) catalog, or the original research post — and the dates and scores shown are the ones published there.

CISA adds four zero-days to KEV in one day: Check Point (×2), F5 BIG-IP APM, Arista VeloCloud

CISA · September 22, 2026

CISA added four vulnerabilities to the KEV catalog on September 22, all of them edge or management-plane products and all with a federal remediation deadline of September 25, 2026: CVE-2026-85102 and CVE-2026-93616 (Check Point), CVE-2026-93952 (Arista VeloCloud Orchestrator), and CVE-2026-94127 (F5 BIG-IP APM). Each is covered in its own item below. A day earlier, on September 21, CISA also added CVE-2026-7273, a stack-based buffer overflow in Zyxel GS1900 series switches, with a September 24 deadline.

“These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.” — CISA

Source: CISA alert (Sept 22) · CISA alert (Sept 21, Zyxel)

Check Point discloses exploited Security Management zero-day (CVE-2026-93616) and confirms in-the-wild attacks on the VPN certificate flaw (CVE-2026-85102)

Check Point · September 22, 2026

Check Point published sk1000171 and a security blog for CVE-2026-93616 (CVSS 9.8), a pre-authentication directory traversal and file upload bug in the Security Management Server, Multi-Domain Server, Log Server, and SmartEvent that lets an attacker with access to the management web service (TCP/19009) run arbitrary scripts. The company says it was used in a handful of targeted attacks on July 23, 2026. Affected: R82.20, R82.10 JHF Take 44 and below, R82 Take 126 and below, R81.20 Take 166 and below, and end-of-support R81.10 and earlier; fixes are R82.10 Take 45+, R82 Take 127+, R81.20 Take 170+, R81.10 Take 192+, and a hotfix for R82.20. There is no LivePatch for this one. The same advisory reports that CVE-2026-85102 (CVSS 9.8, the improper certificate validation flaw patched September 9) is now seeing exploitation attempts against Spark firewall customers globally, starting around September 12. Both CVEs were added to CISA KEV on September 22.

“CVE-2026-93616 is a newly discovered zero-day vulnerability in Security Management, and a fix is available now as part of this advisory.” — Lotem Finkelstein, Check Point

Source: Check Point sk1000171 · Check Point blog · BleepingComputer

F5 patches BIG-IP APM heap overflow exploited for unauthenticated RCE on OAuth authorization servers (CVE-2026-94127)

F5 · September 22, 2026

F5 advisory K000162605 describes CVE-2026-94127, a heap-based buffer overflow (CWE-122) in BIG-IP Access Policy Manager rated 9.8 on CVSS v3.1 and 9.3 on CVSS v4.0. It is reachable only when an APM access policy and OAuth profile are attached to a virtual server with APM acting as an OAuth Authorization Server; client- and resource-server-only deployments are not affected. F5 says the bug has been exploited and shipped engineering hotfixes for 21.1.0, 17.5.0–17.5.1, and 17.1.0–17.1.3, with an iRule mitigation available from F5 Support. Other BIG-IP modules, BIG-IP Next, F5OS, NGINX, and Distributed Cloud are not vulnerable. Added to CISA KEV September 22.

“This vulnerability allows an unauthenticated attacker to perform RCE.” — F5, K000162605

Source: F5 K000162605 · BleepingComputer

Arista VeloCloud Orchestrator CVSS 10.0 input-validation flaw actively exploited (CVE-2026-93952)

Arista · September 22, 2026

Arista Security Advisory 0183 covers CVE-2026-93952, an improper input validation bug in on-premises VeloCloud Orchestrator rated 10.0 on CVSS v3.1 (9.5 on v4.0). It affects deployments that use certificate-based Edge-to-Orchestrator authentication; an attacker with network access to the VCO web UI and the public portion of an Edge authentication certificate can reach privileged internal functions without tenant or operator credentials. Affected: 5.2.3.15 and below, 6.1.3.7 and below, 6.4.2.7 and below, and 7.0.0.2 and below. Fixes are available for 5.2.3.16+ and 6.4.2.8+; Arista says patches for the 6.1.x and 7.0.x lines are still pending, and hosted VCO instances have already been patched. The advisory lists file, service, and IP indicators of compromise. Added to CISA KEV September 22.

“This issue was discovered externally and is known to be actively exploited.” — Arista Security Advisory 0183

Source: Arista SA 0183 · BleepingComputer

WordPress 7.1.2 fixes unauthenticated path traversal (CVE-2026-87902); exploitation began within hours

WordPress.org / Patchstack · September 22–23, 2026

WordPress 7.1.2 shipped on September 22 to fix CVE-2026-87902, an unauthenticated path traversal in page template resolution that yields local file inclusion and, on servers with a writable include path or PEAR’s pearcmd available, code execution. WordPress rates it 9.2 on CVSS v4.0 (8.1 on v3.1); it affects every core release from 4.7.0 through 7.1.1, with backports down to 4.7.37. A proof of concept from the reporter is public. Patchstack observed reconnaissance traffic less than five hours after the release and, by September 23, attackers writing PHP files to disk via the flaw. Not in CISA KEV at time of writing.

“That is arbitrary file write with attacker-controlled PHP content, which is code execution.” — Patchstack

Source: WordPress 7.1.2 release · Patchstack · BleepingComputer

Next.js 16.3.6 patches critical RCE in next/og ImageResponse (CVE-2026-94545)

Vercel · September 22, 2026

Vercel published GHSA-vcvr-r3jv-pc5j for CVE-2026-94545, rated Critical (CVSS v4.0 9.5), in the Node.js implementation of ImageResponse from next/og. Improper escaping in SVG output generated by the upstream Satori library can lead to remote code execution when attacker-controlled values land in SVG content, attributes, or styles. Affected: Next.js 16.2.0 through 16.3.5; fixed in 16.3.6 (15.5.26 adds hardening, and the Edge runtime implementation is not affected). No exploitation has been reported and the flaw is not in KEV.

Source: GHSA-vcvr-r3jv-pc5j · Next.js blog · The Hacker News

Public exploit for unpatched Ubuntu kernel AF_UNIX use-after-free enables container-to-host root (CVE-2026-80521)

DepthFirst · September 22, 2026

DepthFirst researcher Zhenpeng Lin published a working container escape exploit for CVE-2026-80521 (CVSS 7.8), a use-after-free in the Linux kernel’s AF_UNIX socket garbage collector introduced in 6.10 and backported to 6.1 and 6.6. Upstream fixed it on August 6 (mainline 7.2, stable 7.1.10), but Ubuntu’s tracker still lists the kernel packages for 26.04 and 24.04 as “Vulnerable, work in progress.” The exploit code is public on GitHub. No in-the-wild exploitation has been reported and the CVE is not in KEV.

“As of today, it is still unpatched in the latest ubuntu 26.04 release.” — DepthFirst

Source: DepthFirst research · The Hacker News

Financially motivated actor uses open-source AI agent frameworks to skim 600,000+ payment cards

Gambit Security · September 22, 2026

Gambit Security’s threat intelligence team documented an ongoing campaign, active since at least July, in which a threat actor runs open-source agent frameworks (Strix, Cairn, Hermes) to attack online retailers autonomously at roughly $25 per target. The report counts more than 600,000 unexpired card records taken from two victims, skimmers on at least 119 sites, and 105 attack projects against 27+ companies in the September 10–15 window alone. No CVE is involved; the agents chain ordinary web application weaknesses.

“Between 10 and 15 September alone, 105 attack projects were launched and at least 27 companies were compromised to varying degrees.” — Gambit Security

Source: Gambit Security · BleepingComputer

ShinyHunters claims FBI breach via alleged Oracle PeopleSoft zero-day; FBI says it is investigating

Reuters / 404 Media · September 22, 2026

ShinyHunters claims to have breached the FBI through an unpatched Oracle PeopleSoft vulnerability, pivoted into AWS GovCloud infrastructure, and stolen 2–3 TB of data on agents and job applicants; apply.fbijobs.gov was defaced and currently shows a maintenance page. 404 Media verified some phone numbers in a roughly 5,000-record sample. The FBI told Reuters and BleepingComputer it is aware of the claims and investigating. No CVE has been published, Oracle has not commented, and the zero-day claim remains unverified.

“The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating.” — FBI statement to Reuters

Source: Reuters · 404 Media · The Hacker News

Still developing

Three Linux kernel flaws added to KEV; Red Hat flags known exploits

CISA / Red Hat · September 18–19, 2026

CISA added CVE-2025-39682 (kTLS receive path, CVSS 9.8), CVE-2026-53266 (ebtables SNAT ARP out-of-bounds write, CVSS 8.8), and CVE-2025-39964 (AF_ALG race condition, CVSS 7.8) to KEV on September 18 with a September 21 federal deadline. Red Hat updated its advisories on September 19 to mark all three as having known exploits. Fixed upstream kernels have been available since 2025 for the two older bugs and since June 2026 for CVE-2026-53266.

Source: CISA alert (two) · CISA alert (one) · The Hacker News

Joint advisory: North Korea’s WaterPlum infected 30,000 devices, moved $10.7M in crypto

FBI / Japan NPA / ACSC / BfV · September 18, 2026

A joint advisory from U.S., Japanese, Australian, and German authorities attributes the “Contagious Interview” fake-recruiter campaign to WaterPlum, a unit under North Korea’s 313 General Bureau, and ties it to the DPRK IT-worker scheme. It names the BeaverTail, InvisibleFerret, OtterCookie, OtterCandy, and StoatWaffle malware families and notes the actors’ use of AI face-swapping in video interviews.

“WaterPlum actors have infected at least 30,000 devices in more than 100 countries and exfiltrated funds or account credentials from over 7,000 cryptocurrency wallets.” — Joint cybersecurity advisory

Source: IC3 joint advisory (PDF) · BleepingComputer

ShinyHunters defaces Clop’s leak site, claims theft of onion keys

BleepingComputer · September 19, 2026

ShinyHunters breached and defaced the Clop ransomware gang’s Tor data leak site via what it says is an unauthenticated file upload flaw in Grav CMS, and claims to have taken source code, logs, and the onion service private keys. BleepingComputer confirmed the defacement but not the theft claims. The group frames it as retaliation in a feud dating to Clop’s 2025 Oracle E-Business Suite campaign.

Source: BleepingComputer


This brief covers the trailing ~48 hours (September 22–23, 2026).

Primary sources:

xAI Ships Grok 4.7, OpenAI Forms an Independent Math Advisory Group After Its Navier–Stokes Result, Xiaomi Open-Sources MiMo-V2.6 and Alibaba Releases Qwen-Image-2.1

This brief covers the trailing ~72 hours (September 19–22, 2026). Every item below was confirmed on the originating organization’s own page, with a published date inside the window. The window was a model-release weekend: xAI shipped Grok 4.7 as its new flagship for coding and knowledge work, Xiaomi open-sourced the trillion-parameter, omnimodal MiMo-V2.6 series, and Alibaba’s Qwen team released Qwen-Image-2.1, a compact unified image generator and editor with native transparency. On the governance side, OpenAI responded to an open letter from mathematicians by standing up an independent Advisory Group on Mathematics and AI to review and communicate results from the internal model that resolved Navier–Stokes earlier this month. Google opened pre-orders for Googlebook, a laptop built around on-device Gemini, and OpenAI expanded OpenAI Academy with role-based learning paths.

xAI releases Grok 4.7, a larger base model with a new safeguard stack, at the same $2/$6 price as Grok 4.6

SpaceXAI · September 21, 2026

Grok 4.7 uses a new, larger base model than Grok 4.6 and was trained with a longer reinforcement-learning run weighted toward tasks that take many hours to complete, with explicit training to understand the Grok Bot harness. xAI reports 46.3% on CursorBench 4.0 (vs. 40.4% for 4.6), 71.0% on DeepSWE v1.1 at high effort, 38.0% on Terminal-Bench 4.0 (up from 20.3%), and a GDPval Elo of 1,695, placing it between Grok 4.6 and Fable 5.1. The company says the model was built with an entirely new safeguard stack, topping LatchBio’s biosafety benchmark at 62.4% and allowing only 3.3% of risky dual-use prompts through on its HackerBench v0.3, while select cybersecurity partners get invite-only access to its red-team capabilities. It is available today in Cursor, Grok Build, and the Grok API at $2 per million input tokens and $6 per million output tokens, with a fast variant at twice the output speed for twice the price.

“It works longer on difficult tasks, checks its own work more carefully, and comes with our best-calibrated safeguards to date.” — SpaceXAI

Source: Introducing Grok 4.7

OpenAI stands up an independent Advisory Group on Mathematics and AI after its internal model resolves 100+ open problems

OpenAI · September 21, 2026

OpenAI disclosed that the internal model it began training on August 28, the same system behind its Navier–Stokes result, has now resolved more than 100 long-standing open problems across most areas of mathematics, at a pace that surprised the company’s own mathematicians. Citing the open letter “A Severe Misalignment of AI in Mathematics,” in which mathematicians objected to solving open problems as a benchmark for new AI systems, OpenAI said it is working with an independent advisory group hosted at the Institute for Advanced Study to assess the significance of emerging results, coordinate their dissemination, and advise on academic standards. Members are unpaid, may publish unsolicited advice, and can change the group’s membership; initial members include Timothy Gowers, Martin Hairer, Edward Witten, Ravi Vakil, Camillo De Lellis, Melanie Matchett Wood, Ulrike Tillmann, Nikhil Srivastava, and François Charles. OpenAI notes the group will not advise on how to pace its internal progress on mathematics.

“The group will operate independently from OpenAI. The group will have the freedom to offer advice we have not requested, comment on OpenAI’s impact on mathematics, and make its advice public.” — OpenAI

Source: Advisory Group on Mathematics and Artificial Intelligence

Xiaomi open-sources MiMo-V2.6: a 1.02T-parameter omnimodal MoE with 1M context, trained in one mixed RL run

Xiaomi MiMo · September 21, 2026

Xiaomi released the MiMo-V2.6 series under an MIT license, led by MiMo-V2.6-Pro-RL, a sparse mixture-of-experts model with 1.02 trillion total and 42 billion active parameters, a 1M-token context window, and native text, image, video, and audio input. The technical approach centers on “You Only RL Once,” a single mixed reinforcement-learning run spanning coding, general agents, vision, and cybersecurity, plus a groupwise agentic grader that ranks passing rollouts against each other to push toward shorter, cheaper solutions. Xiaomi’s own evaluation table puts Pro at 71.9% on DeepSWE v1.1, 76.9% on Toolathlon-Verified, 82.0% on OSWorld-Verified, and 94.0% on CyberGym, generally within a few points of Claude Opus 5 and GPT-5.6 Sol on agentic benchmarks. A smaller Flash model (309B parameters) and an UltraSpeed variant of Pro are served through Xiaomi’s API at $0.435/$0.87 and $0.14/$0.28 per million input/output tokens respectively.

“One mixed RL run across coding, general agents, visual, and cybersecurity — not separate per-domain runs.” — Xiaomi MiMo Team

Source: MiMo-V2.6 (see also the MiMo-V2.6-Pro-RL model card)

Alibaba’s Qwen team releases Qwen-Image-2.1, a 7B unified generator and editor with native transparency

Qwen (Alibaba) · September 20, 2026

Qwen-Image-2.1 unifies text-to-image generation and image editing in a single model with just 7 billion parameters in its visual generation component (a 32-layer single-stream DiT), paired with a Qwen3-VL 8B text encoder and a 64-channel RGBA VAE. It natively generates and edits transparent images, accepts up to 10 reference images for multi-subject composition, supports circle, paint, and mask annotations to target local edits, and renders natively at 2K resolution. A mixed-granularity attention design lets the model encode text and condition images once and reuse the prefix KV cache across all denoising steps. Weights are on Hugging Face and ModelScope under the Qwen Research License, with day-zero support in Diffusers, ComfyUI, vLLM-Omni, SGLang, and LightX2V, and two fine-tuned Qwen3.5-VL 9B prompt-rewriting models released alongside.

“We are excited to open-source Qwen-Image-2.1, a unified text-to-image generation and image editing model in the Qwen family.” — Qwen team

Source: Qwen-Image-2.1 on GitHub (blog: qwen.ai)

Google opens Googlebook pre-orders: a $899 laptop built around on-device Gemini, Magic Pointer, and Antigravity

Google · September 21, 2026

Google detailed the intelligence layer of Googlebook, its new Android-and-ChromeOS-based laptop, which brings Gemini directly onto the device. Magic Pointer summons Gemini with a cursor wiggle to act on whatever is on screen (scheduling a training plan into Calendar, checking whether a hovered email is spam, combining selected images); Rambler turns spoken stream-of-consciousness into structured, multilingual notes; and Create My Widget builds custom widgets from a description. Every Googlebook ships with Google Antigravity and a full Linux terminal for agentic coding tools, and Gemini Spark can keep processing tasks after the lid is closed. Pre-orders start at $899 and include 12 months of Google AI Pro, with devices arriving October 4 in the U.S. and October 5 in Canada, the U.K., Ireland, France, Germany, and Australia.

“Developers also have access to a full Linux terminal environment to run tools like Claude Code or Antigravity CLI and do serious agentic coding right on your Googlebook.” — Alexander Kuscher, Google

Source: Googlebook’s built-in intelligence reinvents the way you use your laptop

OpenAI expands OpenAI Academy with role-based learning paths and course badges

OpenAI · September 21, 2026

OpenAI added new course pathways to OpenAI Academy for developers (Build with AI, eight courses covering Codex and the API, evaluations, agents, and production operation), leaders (an AI Leadership course on strategy, ownership, and roadmaps), and educators and college students (AI for Educators and AI for College Students), joining the existing Apply AI at Work pathway for knowledge workers. Each course ends with an assessment, and learners who pass earn an OpenAI Academy course badge. The company positions the expansion as part of deployment, encouraging organizations to combine pathways for onboarding, technical teams, and executive programs.

“At OpenAI, we treat learning as part of deployment.” — OpenAI

Source: Expanding OpenAI Academy with new learning paths

Still developing

OpenAI publishes an Australian Youth Safety Blueprint (September 18, 2026). Just before this window opened, OpenAI released a six-pillar roadmap for protecting young Australians using AI, spanning AI literacy, age-appropriate safeguards, privacy-protective age assurance, connections to crisis support, and parental controls, and noted that ChatGPT for Teens began rolling out in Australia in August as the default experience for users identified as 13 to 17. Source: Introducing the Australian Youth Safety Blueprint


This brief covers the trailing ~72 hours (September 19–22, 2026).

Primary sources:

CISA Flags Three Exploited Linux Kernel Bugs, WordPress 7.1.1 Fixes Click2Shell, vm2 Sandbox-Escape Wave Hits CVSS 10

This brief covers the trailing ~48 hours (September 17–19, 2026). Every item below was traced to a primary source — CISA’s KEV catalog, a vendor release or advisory, or the original researcher’s write-up — and the disclosure date was confirmed on that page.

CISA adds three actively exploited Linux kernel flaws to KEV, federal deadline Sept. 21

CISA · September 18, 2026

In two separate alerts on September 18, CISA added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2025-39682 (improper check in the kernel TLS receive path, where a zero-length record from rx_list bypasses recvmsg() record-type handling), CVE-2026-53266 (out-of-bounds write in the ebtables SNAT target’s ARP hardware-address rewrite), and CVE-2025-39964 (race condition on concurrent writes to the same AF_ALG socket). Published CVSS scores are 9.8, 8.8, and 7.8 respectively. All three carry a KEV due date of September 21, 2026, and CISA marks each as requiring forensic triage under BOD 26-04; ransomware use is listed as “Unknown.” Red Hat updated its advisories for all three to acknowledge active exploitation, and fixes are available in current stable kernels.

“CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-39964 Linux Kernel Race Condition Vulnerability. CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability.” — CISA alert, September 18, 2026

Source: CISA alert (two KEVs) · CISA alert (one KEV) · KEV catalog entry · The Hacker News

Public root exploits released for four Linux kernel LPEs: DirtyAH6, TUNderflow, PPPoEject, DiagSpill

Asim Manizada (researcher write-up) · September 18, 2026

Researcher Asim Manizada published a coordinated write-up and working proof-of-concept exploits for four Linux kernel local privilege escalation bugs, all found with an AI-assisted hunting harness: CVE-2026-80844 (DirtyAH6, IPv6 IPsec AH routing-header OOB), CVE-2026-81000 (TUNderflow, TUN/TAP headroom integer underflow), CVE-2026-68121 (PPPoEject, PPPoE use-after-free), and CVE-2026-74469 (DiagSpill, SCTP sctp_diag 16-bit transport counter wrap spilling ~8 MiB). The bugs were reported to the kernel security team in mid-July; patches landed upstream and the first stable releases containing all four fixes are 5.10.270, 5.15.221, 6.1.188, 6.6.157, 6.12.109, 6.18.50, and 7.2.4. Three require unprivileged user namespaces; DiagSpill needs no special privileges when SCTP is available. No CVSS scores are listed in the write-up, and no in-the-wild exploitation has been reported. Not in KEV.

“Four more Linux LPEs; two of the corruption bugs are reachable remotely under very specific circumstances, with one theoretically remote-groomable to remote root.” — Asim Manizada, lpe-quartet write-up

Source: Researcher write-up (heyitsas.im) · The Hacker News

WordPress 7.1.1 ships 11 security fixes, including the “Click2Shell” forced theme-install flaw

WordPress.org · September 17, 2026

WordPress 7.1.1 is a short-cycle security and maintenance release with 17 core bug fixes, 19 Block Editor fixes, and 11 security fixes. The headline items are an unauthenticated stored cross-site scripting bug in wpautop() (subject to comment approval) and a flaw where specially crafted URLs can automatically install and preview an inactive theme from WordPress.org when opened by a logged-in administrator — reported by Paulos Yibelo and pwn.ai, who describe a chain they call Click2Shell. Other fixes include an authenticated path traversal in the REST Templates Controller and a Contributor+ arbitrary post overwrite (both reported by Anthropic), an XML-RPC edit_css bypass, and several authorization and disclosure issues. The release post does not list CVE IDs or CVSS scores. Backports to older branches are in progress. Not in KEV.

“Because this is a security release, it is recommended that you update your sites immediately.” — WordPress 7.1.1 release announcement

Source: WordPress.org release post · The Hacker News

vm2 sandbox-escape wave: more than a dozen CVEs, several at CVSS 10, fixed in 3.11.7

VulnCheck (CNA) / CVE.org · September 17, 2026

A batch of CVE records published September 17 covers a wave of sandbox escapes in the widely used vm2 Node.js library. CVE-2026-92941 (CVSS 10.0, CWE-732) allows NodeVM sandbox code to reach the host tls module and call tls.setDefaultCACertificates(), replacing the process-wide certificate trust store; it affects vm2 3.11.3 through 3.11.6 and is fixed in 3.11.7. Related records in the same batch (including CVE-2026-92937, CVE-2026-92940, CVE-2026-92946, CVE-2026-92953, CVE-2026-92955, CVE-2026-92956, and CVE-2026-92960, each scored 10.0, plus several at 9.9) describe escapes via Promise rejection handling, https.globalAgent, require.external, TypedArray/ArrayBuffer prototypes, WebAssembly compilation streams, and the os/dns builtins. Any service running untrusted JavaScript in-process with vm2 — including many AI-agent tool runners — should upgrade to 3.11.7 or later. No exploitation in the wild has been reported; not in KEV.

“vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tls.setDefaultCACertificates() and replace process-wide certificate authorities.” — CVE-2026-92941 record (VulnCheck)

Source: CVE.org record · vm2 GitHub advisory · Vulners

Plugin4Shell: SHA-pinning bypass in four AI coding agents; Claude Code and Codex patched, Copilot and Gemini CLI unfixed

Air Security · September 17, 2026

Air Security disclosed a plugin supply-chain flaw affecting Claude Code, OpenAI Codex, GitHub Copilot, and Gemini CLI. Each agent checks out a marketplace-pinned commit but never verifies that the resulting working tree matches the pin; an attacker controlling a plugin’s repository can create a default branch named with the 40-hex pinned SHA (or, for Gemini CLI, a branch named FETCH_HEAD) so that git checkout resolves the ref instead of the commit. Combined with background auto-update, the swap requires no user interaction. Per Air’s timeline, the flaw was found in May, disclosed to all four vendors in June, fixed in Claude Code 2.1.179 and Codex 0.146.0, while Copilot has no fix and Google will not patch the deprecated Gemini CLI. GitHub rejects hash-shaped branch names, so the branch variant applies to plugins hosted on Bitbucket or self-hosted git. No CVE has been assigned, no CVSS is published, and Air reports no evidence of in-the-wild exploitation. Not in KEV.

“It is a plugin SHA-pinning bypass: the agent checks out the exact commit the marketplace pinned but never verifies it landed there, so an attacker who controls the plugin’s repo makes the checkout resolve to malicious code while the pin still looks honored.” — Air Security, Plugin4Shell disclosure

Source: Air Security disclosure · The Hacker News

Microsoft Fabric authentication bypass rated CVSS 10.0 (CVE-2026-69843)

Microsoft MSRC · September 17, 2026

Microsoft published CVE-2026-69843, an authentication bypass by spoofing in Microsoft Fabric that allows an unauthorized attacker to elevate privileges over a network, rated CVSS 10.0 and classified as CWE-287. As a cloud-service vulnerability it was mitigated on Microsoft’s side and carries no customer patch. It was published alongside a cluster of other Microsoft cloud-service CVEs the same day. Microsoft has not reported exploitation; not in KEV.

“Authentication bypass by spoofing in Microsoft Fabric allows an unauthorized attacker to elevate privileges over a network.” — MSRC Security Update Guide, CVE-2026-69843

Source: MSRC CVE-2026-69843 · CVE Brief daily roundup

Brevo post-mortem: stolen Cloudflare API key used to inject ClickFix into customer-embedded scripts

Brevo (status.brevo.com) / BleepingComputer · September 17, 2026

Brevo published a post-mortem confirming that attackers obtained a long-lived, full-permission Cloudflare API key that had been hardcoded in application source code and used it to create a malicious Cloudflare Worker. For roughly five and a half hours on September 14 (16:07–20:30 UTC), the Worker rewrote responses at the CDN edge for brevo.com, sendinblue.com, and sibforms.com, and modified the Brevo forms, Conversations widget, and SDK loader scripts that customers embed on their own sites — Sansec estimates up to 100,000 sites were affected. Visitors were shown a fake Cloudflare verification page with ClickFix instructions; on WordPress sites the script also tried to upload a backdoor plugin (“Web Media Optimizer”) if the visitor was a logged-in admin. Brevo revoked the key, removed the Worker, and says its app, API, and customer data were not affected. No CVE applies.

“Because the Worker rewrote responses at the edge and removed security headers such as Content-Security-Policy, our origin servers and files remained unmodified and standard integrity checks did not detect the change.” — Brevo post-mortem, as quoted by BleepingComputer

Source: Brevo post-mortem · BleepingComputer · SecurityWeek

Still developing

Cisco ISE zero-day authentication bypass (CVE-2026-76460, CVSS 10.0) exploited in the wild

Cisco PSIRT · September 16, 2026

Cisco published an advisory for CVE-2026-76460, a maximum-severity authentication bypass in an API endpoint of Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), exploitable regardless of configuration. Cisco PSIRT confirmed active exploitation, and successful attacks can lead to command execution as root. There are no workarounds; fixed releases are 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4. CISA added the CVE to KEV on September 16 with a three-day federal deadline. Cisco recommends checking access.log on every node for suspicious usernames and re-imaging nodes where compromise is suspected.

“The Cisco PSIRT is aware of active exploitation of this vulnerability. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability.” — Cisco Security Advisory cisco-sa-ISE-ABP-VNSW7Tn5

Source: Cisco advisory · CISA KEV alert · BleepingComputer


This brief covers the trailing ~48 hours (September 17–19, 2026).

Primary sources: