Skip to content

Morning Brief

Saturday, September 26, 2026 · generated · ~6 min read

Top developments

SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, citing…

Crooks use fake desktop apps to fool HR staff into giving them remote access

You work in your company's human resources department and use HR software to check employee information, benefits, and payroll. So, when you see a downloadable Windows version promising a faster alternative to the usual…

Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The ShinyHunters-linked activity involves the…

OnePlus 15 Flaws Let Zero-Permission Apps Gain Root Access Through OxygenOS Services

Two flaws in the latest OxygenOS build could let malicious Android apps run code with root privileges on OnePlus devices, including the OnePlus 15, by exploiting accessible privileged services. The vulnerabilities are…

Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the May 2026 Mini Shai-Hulud campaign. The affected…

Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link

Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated attacker to create rogue administrator accounts and take control…

Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing

Security flaws in Salesforce Agentforce allowed poisoned leads to hijack its AI agents, silently steal CRM data without requiring a click, and send phishing messages under the agents’ identities. Zenity Labs uncovered…

Bitget blames North Korea for $387.5M crypto wallet raid

The CEO of crypto exchange Bitget has confirmed that a cyberattack with all the hallmarks of a North Korean operation resulted in approximately $387.5 million worth of digital assets being stolen from the exchange’s…

CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks

The Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are exploiting a critical authentication bypass vulnerability (CVE-2026-5430) affecting multiple products from enterprise software provider…

GitLab Email Addresses Can Be Weaponized for Supply Chain Attacks

Incoming email addresses automatically assigned to each user on the platform contain highly privileged access tokens that attackers can use.

Vulnerability watch

CVE-2026-100075 Linux · Linux CRITICAL 9.8

In the Linux kernel, the following vulnerability has been resolved: RDMA/srpt: Fix srpt_alloc_rw_ctxs() unwind counters When srpt_alloc_rw_ctxs() fails partway through a multi-buffer indirect descriptor, the unwind path destroys RDMA cont…

CVE-2026-93643 Microsoft · Zimbra Collaboration Suite (ZCS) CWE-22 CRITICAL 9.8

When OnlyOffice/Document Editing is available, an unauthenticated remote attacker with access to an existing supported public Briefcase document can abuse unsigned save fields to perform path-traversal writes and execute commands as zimbra.

CVE-2026-92161 FriendsOfFlarum · oauth CWE-345 CRITICAL 9.8

FriendsOfFlarum OAuth allows users to log in to Flarum with GitHub, Twitter, Facebook, and other providers. Prior to 1.7.4 and 2.0.0-beta.4, the Discord OAuth provider does not check the verified field returned for an OAuth email before pas…

CVE-2026-18143 WordPress · Request a Quote for WooCommerce CWE-434 CRITICAL 9.8

The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.9.2 via the `afrfq_submit_quote_via_popup()` function. This is due to missing file extension and MIME ty…

CVE-2026-93641 Zimbra · Zimbra Collaboration Suite (ZCS) CWE-79 CRITICAL 9.3

An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Classic recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.

CVE-2026-93642 Zimbra · Zimbra Collaboration Suite (ZCS) CWE-79 CRITICAL 9.3

An unauthenticated sender can forge a share notification that triggers stored XSS when a signed-in Zimbra Modern recipient clicks Accept Share, allowing the attacker to access mailbox data and act as the victim.

CVE-2026-93647 Zimbra · Zimbra Collaboration Suite (ZCS) CWE-79 CRITICAL 9.3

An unauthenticated calendar sender can place active markup in a COUNTER message's RFC From address. Selecting the message in Zimbra Classic triggers stored XSS, allowing the attacker to access mailbox data and act as the victim.

CVE-2026-39353 InvoicePlane · InvoicePlane CWE-98 CRITICAL 9.1

InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2-rc-1, InvoicePlane builds its permitted template list by scanning a PHP template directory that can be written through an adm…

CVE-2026-42322 Piwigo · Piwigo CWE-434 CRITICAL 9.1

Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/themes_standard_pages.php validates uploaded logo content by MIME type but reuses the attacker-controlled extension from std_pgs_logo when c…

CVE-2026-62262 Piwigo · Piwigo CWE-89 CRITICAL 9.1

Piwigo is a full featured open source photo gallery application for the web. In 17.0.0beta1 and earlier, when rating is enabled, an unauthenticated guest can call pwg.images.filteredSearch.create with a crafted ratings[] value and then open…

Full CVE Feed →

Worth reading

Wiz Named a Leader in The Forrester Wave™: Proactive Security Platforms, Q3 2026

Forrester’s Proactive Security Platforms evaluation rated Wiz with top scores across eight areas, reflecting our commitment to securing the AI era

Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127)

Well, well, well, well, well, well, well, well, well, well, well, well, well, well, well. We're back. Sorry. We've been watching the onslaught of vulnerabilities flood the internet. Every man, dog, and their grandmas…

About this brief Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score — no AI writes any of this. Every number and link traces back to something already published on those two tools.

Data sources Top developments from Security Feed's cross-source trending detection. Vulnerability watch from CVE Feed's daily NVD + CISA KEV sync.

More Browse past briefs → · Patch Tuesday specials →