WordPress Core RCE Under Active Exploitation, WSO2 and Adobe Commerce Added to KEV, TeamCity Flaw Tied to Ransomware

This brief covers security developments from September 23–25, 2026. Every item was checked against the vendor advisory, the CISA KEV catalog, or the original research, with reputable outlets linked for context.

Attackers move from probing to payloads on WordPress core flaw CVE-2026-87902

WordPress / Patchstack · September 23, 2026

CVE-2026-87902 is an unauthenticated path traversal flaw in WordPress core page-template resolution. It affects versions 4.7.0 through 7.1.1, and the WordPress security team rates it critical (CVSS v4.0 9.2). WordPress 7.1.2 fixed it on September 22, and the fix was backported to every branch down to 4.7. Patchstack saw reconnaissance start within hours of the patch. By September 23, traffic had grown tenfold and included pearcmd.php-based payloads that write PHP files to /tmp and /var/tmp. Remote code execution requires specific theme and server conditions, such as a theme directory whose name starts with page- and PHP’s register_argc_argv setting being enabled. None of the sources reviewed reported a CISA KEV listing.

“Because this is a security release, it is recommended that you update your sites immediately.” — WordPress.org, 7.1.2 release notes

Source: WordPress 7.1.2 Release · GHSA-7hp8-65ch-5whp · BleepingComputer

CISA adds WSO2 API Manager auth bypass CVE-2026-5430 to KEV

CISA / WSO2 · September 24, 2026

CISA added CVE-2026-5430 to the Known Exploited Vulnerabilities catalog after evidence of active exploitation. Federal agencies must patch by September 27. WSO2’s advisory scores the flaw CVSS 3.1 10.0, or 9.8 in single-tenant deployments. It describes a JWT authentication bypass: a token signed with an unsupported algorithm is accepted, which can lead to takeover of administrative accounts. CISA’s KEV entry calls it a path traversal. Affected products are WSO2 API Control Plane 4.5.0–4.6.0, API Manager 4.1.0–4.6.0, Traffic Manager 4.5.0–4.6.0, and Universal Gateway 4.5.0–4.6.0. watchTowr reported in-the-wild attempts against its honeypots since at least September 13.

“JWT authentication can be bypassed when a token is signed using an unsupported algorithm, allowing unauthorized access.” — WSO2 Security Advisory WSO2-2026-5328

Source: WSO2-2026-5328 · CISA alert · The Hacker News

Adobe Commerce / Magento session-switching flaw CVE-2026-71362 added to KEV

CISA / Adobe · September 24, 2026

CISA added CVE-2026-71362, an incorrect authorization flaw in Adobe Commerce and Magento Open Source (CVSS 9.1), to the KEV catalog in the same September 24 update. The federal remediation deadline is September 27. The bug lets an unauthenticated attacker switch a customer session to another customer’s account. Sansec reported blocking exploitation attempts in August, shortly after Adobe’s APSB26-92 fix. Adobe has not yet updated its advisory to confirm exploitation. The fix is to install the -2026-aug security release or the APSB26-92 isolated patch.

“The vulnerability lets attackers switch a customer session to another customer account.” — Sansec

Source: CISA alert · Sansec research · The Hacker News

CISA marks JetBrains TeamCity CVE-2026-63077 as used in ransomware campaigns

CISA / JetBrains · September 23, 2026

CISA updated the KEV entry for CVE-2026-63077 to show that it is “Known” to be used in ransomware campaigns. The flaw is a critical authentication bypass in TeamCity On-Premises that JetBrains patched on July 25 in versions 2025.11.7 and 2026.1.3. It allows unauthenticated OS command execution through the agent polling protocol. The CVE was first added to KEV on August 5. Shadowserver still tracks about 160 unpatched internet-exposed servers.

“An unauthenticated attacker could exploit the vulnerability via the TeamCity agent polling protocol to bypass authentication checks and execute arbitrary operating system commands.” — JetBrains

Source: CISA KEV entry · JetBrains update · BleepingComputer

Still developing

Check Point confirms exploitation of Security Gateway VPN RCE and a Management Server zero-day

Check Point · September 22, 2026

Check Point Research confirmed exploitation of two flaws, both rated CVSS 9.8. The first, CVE-2026-85102, is a pre-authentication RCE in Security Gateway and Spark VPN certificate handling. It was patched September 9, and exploitation attempts against Spark customers started September 12. The second, CVE-2026-93616, is a pre-authentication path traversal zero-day in the Management web service that allows arbitrary script execution and Java class loading. It was used in a handful of targeted attacks on July 23 and is fixed via sk1000171. CISA added both to KEV on September 22 with a September 25 due date.

“Customers running affected versions should install the applicable fixes immediately.” — Lotem Finkelstein, Check Point Research

Source: Check Point advisory · sk1000117 · sk1000171 · BleepingComputer

F5 BIG-IP APM OAuth Authorization Server zero-day CVE-2026-94127

F5 · September 22, 2026

F5 patched CVE-2026-94127, a heap-based buffer overflow in BIG-IP APM (CVSS 3.1 9.8 / CVSS 4.0 9.3). Unauthenticated attackers can get RCE when APM is configured as an OAuth Authorization Server. F5 confirmed in-the-wild exploitation and published indicators of compromise plus an iRule mitigation. CISA added the flaw to KEV on September 22. Shadowserver sees roughly 14,700 IPs with BIG-IP APM fingerprints.

“We have learned that this vulnerability has been exploited.” — F5, K000162605

Source: F5 K000162605 · BleepingComputer

ShinyHunters claims FBI breach via unpatched Oracle PeopleSoft zero-day

BleepingComputer · September 22, 2026

The ShinyHunters extortion group claims it used a new Oracle PeopleSoft RCE zero-day to reach FBI systems and FBI-managed AWS GovCloud infrastructure. It says it stole 2–3 TB of employee and applicant data. The FBI says it is investigating “claims regarding unauthorized activity affecting FBIjobs.gov” but has not confirmed a breach. Oracle has not published an advisory or CVE, and the zero-day has not been independently verified.

Source: BleepingComputer


This brief covers the trailing ~48 hours (September 23–25, 2026).

Primary sources:

Leave a Reply