{"date_iso":"2026-10-02","date_human":"Friday, October 2, 2026","generated_utc":"2026-10-02 14:57 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"Hackers Turned a Microsoft SQL Server Into a Command and Data Exfiltration Channel","link":"https://cybersecuritynews.com/hackers-turned-a-microsoft-sql-server/","reason":"Microsoft","category":"News","sources":["Ars Technica Security","Bleeping Computer","Cyber Security News","Dark Reading","ESET WeLiveSecurity","Infosecurity Magazine","SecurityWeek","The Hacker News","The Record","The Register Security","Zero Day Initiative"],"coverage":11,"cve_ids":[],"summary":"Hackers turned a Microsoft SQL Server into a channel for running commands and moving collected files in an intrusion linked to a Viva Aerobus environment. Their own publicly accessible server then exposed attack tools\u2026","source":"Cyber Security News","date_rel":"52m ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/10/Hackers-Turned-a-Microsoft-SQL-Server-Into-a-Command-and-Data-Exfiltration-Channel.webp","description":"Hackers turned a Microsoft SQL Server into a channel for running commands and moving collected files in an intrusion linked to a Viva Aerobus environment. Their own publicly accessible server then exposed attack tools and stolen material to unrelated internet users. The activity, observed between September 25 and 29, 2026, involved credential harvesting, source code collection, and preparation to access additional systems. The investigation did not establish how the attackers first entered the environment or identify a named malware family. The available records describe a toolkit rather than\u2026","related":[{"title":"Microsoft: AI Cuts Post-Compromise Attack Time to Minutes","link":"https://www.infosecurity-magazine.com/news/microsoft-ai-attack-time-minutes/","source":"Infosecurity Magazine","date_rel":"41m ago"},{"title":"'Warlock' ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking countries","link":"https://therecord.media/warlock-ransomware-used-in-critical-infrastructure-attacks","source":"The Record","date_rel":"51m ago"},{"title":"Crypto Scammers Hijack Microsoft\u2019s Official X Account","link":"https://www.securityweek.com/crypto-scammers-hijack-microsofts-official-x-account/","source":"SecurityWeek","date_rel":"3h ago"},{"title":"Session Cookie Vulnerability Lets Attackers Bypass Entra ID MFA and Impersonate Users","link":"https://cybersecuritynews.com/session-cookie-vulnerability/","source":"Cyber Security News","date_rel":"3h ago"},{"title":"Microsoft\u2019s X account hacked in crypto pump-and-dump scheme","link":"https://www.bleepingcomputer.com/news/security/microsofts-x-account-hacked-in-crypto-token-pump-and-dump-scheme/","source":"Bleeping Computer","date_rel":"5h ago"},{"title":"Microsoft says threat actors are ahead in the early AI race","link":"https://www.bleepingcomputer.com/news/security/microsoft-says-threat-actors-are-ahead-in-the-early-ai-race/","source":"Bleeping Computer","date_rel":"19h ago"}]},{"title":"Fortinet sounds the alarm over actively exploited FortiMail zero-day","link":"https://www.theregister.com/security/2026/10/02/fortinet-sounds-the-alarm-over-actively-exploited-fortimail-zero-day/5300803","reason":"CVE-2026-104286","category":"News","sources":["Bleeping Computer","CISA Alerts & Advisories","SecurityWeek","The Register Security"],"coverage":4,"cve_ids":["CVE-2026-104286"],"summary":"Fortinet is warning customers to lock down FortiMail after attackers started exploiting a critical bug that lets them write files to vulnerable systems without logging in. The flaw, tracked as CVE-2026-104286, carries a\u2026","source":"The Register Security","date_rel":"4h ago","thumbnail":"https://image.theregister.com/?imageId=5300807&width=800","description":"Fortinet is warning customers to lock down FortiMail after attackers started exploiting a critical bug that lets them write files to vulnerable systems without logging in. The flaw, tracked as CVE-2026-104286, carries a CVSS score of 9.8 and affects multiple versions of Fortinet's email security platform. Fortinet describes the vulnerability as a combination of path traversal and improper handling of null characters in FortiMail's web interface. An unauthenticated attacker can exploit it using specially crafted HTTP or HTTPS requests to write arbitrary files to the underlying system. Writing\u2026","related":[{"title":"Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action","link":"https://www.securityweek.com/exploited-fortinet-fortimail-zero-day-calls-for-urgent-action/","source":"SecurityWeek","date_rel":"6h ago"},{"title":"Fortinet warns of critical FortiMail flaw exploited in zero-day attacks","link":"https://www.bleepingcomputer.com/news/security/fortinet-warns-of-critical-fortimail-flaw-exploited-in-zero-day-attacks/","source":"Bleeping Computer","date_rel":"16h ago"},{"title":"CISA Adds One Known Exploited Vulnerability to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/10/01/cisa-adds-one-known-exploited-vulnerability-catalog","source":"CISA Alerts & Advisories","date_rel":"1 Oct"}]},{"title":"SMTP is the key: BPFDoor and AVERAT hitting the network edge","link":"https://www.rapid7.com/blog/post/tr-smtp-is-the-key-bpfdoor-averat-hitting-the-network-edge","reason":"Linux","category":"Research","sources":["Dark Reading","Rapid7 Blog","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Overview Rapid7 tracked a set of Linux samples that blend into the software and device conventions of the telecom environments they target. The set spans a newly observed BPFDoor variant, a BPF Rekoobe build seen\u2026","source":"Rapid7 Blog","date_rel":"1h ago","thumbnail":"https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt26c0aaf38298d29b/6abeb286ee5ee36131f01beb/Copy_of_Rapid7_intelligence_report_template_(1).png","description":"Overview Rapid7 tracked a set of Linux samples that blend into the software and device conventions of the telecom environments they target. The set spans a newly observed BPFDoor variant, a BPF Rekoobe build seen against South Korean targets, a dropper, and six builds of a Linux implant we track as AVERAT , deployed against Taiwanese appliances. Additionally, we provide source code details of the Rapid7 BPFDoor controller introduced in our April 2026 blog, Stealthy BPFDoor Variants are a Needle That Looks Like Hay . The chain uses two binaries. A dropper writes a shell script to the\u2026","related":[{"title":"Malicious Linux Implants Mimic Asian Mail Security Products","link":"https://www.darkreading.com/threat-intelligence/malicious-linux-implants-mimic-asian-mail-security","source":"Dark Reading","date_rel":"1h ago"},{"title":"New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses","link":"https://thehackernews.com/2026/09/new-spectre-v2-btr-attack-leaks-linux.html","source":"The Hacker News","date_rel":"29 Sep"}]},{"title":"Google Rolls Out Gemini 4 Argon to Trusted Cyber Defenders, Plans Guardrail-Free Version","link":"https://thehackernews.com/2026/10/google-rolls-out-gemini-4-argon-to.html","reason":"Google","category":"News","sources":["CCCS Alerts & Advisories","Dark Reading","Infosecurity Magazine","The Hacker News"],"coverage":4,"cve_ids":[],"summary":"Google on Wednesday announced its latest frontier artificial intelligence (AI) model, Gemini 4 Argon, that it said is being rolled out to a set of trusted cyber defenders through its Fairwind Program. \"It delivers\u2026","source":"The Hacker News","date_rel":"1 Oct","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhYk4zu5KwFghyphenhyphenGNFmUKfmtScZfRpYSwO3huCn6VYY6EiFZH7t7zWwr6Agn-AqOHA19-uc6wQMnoOHXGY3V8F2ZWfxoTNiTp8VV1ePAvDGYlW3ocD8tXLN-tPuqvzwf7YRX9CXl1_Zj2b0ZcMqbZAo_5Ut3uG3gTTEXTCVxJyyTtcUlbfwXkdqCu8PpY4l6/s1600/gemini-4.jpg","description":"Google on Wednesday announced its latest frontier artificial intelligence (AI) model, Gemini 4 Argon, that it said is being rolled out to a set of trusted cyber defenders through its Fairwind Program. \"It delivers frontier performance in complex workflows across real-world software engineering, enterprise knowledge work like legal and finance, and cybersecurity defense,\" Koray Kavukcuoglu,","related":[{"title":"Google security advisory (AV26-984)","link":"https://cyber.gc.ca/en/alerts-advisories/google-security-advisory-av26-984","source":"CCCS Alerts & Advisories","date_rel":"20h ago"},{"title":"Malicious Custom GPTs Turn ChatGPT Into RAT Delivery Lure","link":"https://www.darkreading.com/cyberattacks-data-breaches/malicious-custom-gpts-chatgpt-rat-delivery-lure","source":"Dark Reading","date_rel":"30 Sep"},{"title":"AI-Found Vulnerabilities More Likely to Enable RCE, Google Says","link":"https://www.infosecurity-magazine.com/news/ai-found-vulnerabilities-rce/","source":"Infosecurity Magazine","date_rel":"30 Sep"},{"title":"Attackers Combine ChatGPT Feature Abuse With ClickFix to Deliver Trojan Malware","link":"https://www.infosecurity-magazine.com/news/chatgpt-feature-abuse-to-deliver/","source":"Infosecurity Magazine","date_rel":"30 Sep"}]},{"title":"ZDI-26-750: WatchGuard FireWare OS spamd statushdlr Stack-based Buffer Overflow Remote Code Execution Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-750/","reason":"Watchguard","category":"Research","sources":["CCCS Alerts & Advisories","Zero Day Initiative"],"coverage":2,"cve_ids":[],"summary":"This vulnerability allows remote attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of\u2026","source":"Zero Day Initiative","date_rel":"30 Sep","thumbnail":"","description":"This vulnerability allows remote attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-18145.","related":[{"title":"WatchGuard security advisory (AV26-990)","link":"https://cyber.gc.ca/en/alerts-advisories/watchguard-security-advisory-av26-990","source":"CCCS Alerts & Advisories","date_rel":"1h ago"},{"title":"WatchGuard security advisory (AV26-981)","link":"https://cyber.gc.ca/en/alerts-advisories/watchguard-security-advisory-av26-981","source":"CCCS Alerts & Advisories","date_rel":"1 Oct"},{"title":"ZDI-26-749: WatchGuard FireWare OS samld SAMLSession Deserialization of Untrusted Data Remote Code Execution Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-749/","source":"Zero Day Initiative","date_rel":"30 Sep"}]},{"title":"Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes","link":"https://thehackernews.com/2026/10/critical-fortimail-zero-day-flaw.html","reason":"Fortinet","category":"News","sources":["CCCS Alerts & Advisories","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities (KEV) catalog, following reports of\u2026","source":"The Hacker News","date_rel":"9h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhhcZguz-U3FsSD6t4YQ45EeFbgnWAy9lM28OAFydsLXZYzOS00aOD7pxUZcgvLMfMAO3SJV_Amu9SoNezLNQOvx823Z92CpqC5ow9XO3d7HJhEKZlwQt4H4Z7kirDwGcSrUyi1ONs_PuULNYjEjzae2c1mncDviOT9iqxD-PhmXCYpulTUNO2rtW5c9AAx/s1600/fortimail.jpg","description":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerability, tracked as CVE-2026-104286 (CVSS score: 9.8), allows unauthenticated attackers to write arbitrary files on the underlying system. \"An improper","related":[{"title":"Fortinet security advisory (AV26-989)","link":"https://cyber.gc.ca/en/alerts-advisories/fortinet-security-advisory-av26-989","source":"CCCS Alerts & Advisories","date_rel":"3h ago"}]},{"title":"CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV","link":"https://thehackernews.com/2026/10/cisa-adds-exploited-cisco-catalyst-sd.html","reason":"Cisco","category":"News","sources":["CCCS Alerts & Advisories","Infosecurity Magazine","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV), following\u2026","source":"The Hacker News","date_rel":"1 Oct","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj8jgm3LMY2zr1S1DmXnvVEPDiTKYR5FXHW7q_6duG1lVPhzbW2ZfJwRM9glqAJrQhBX3HAAiksz-tUpRN4pfT9VWHUksa-1SgHZmKcNUd1tJfsyFiwhtezZN_zBM_cEmqjkECI_2gfWhnqZ1ry2hgDou-qQCB21zbl1RzYN9JB0bRjqzhB2m6gBomg-ow9/s1600/cisa-wan.jpg","description":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV), following reports of active exploitation. The vulnerability, tracked as CVE-2026-76504 (CVSS score: 9.8), could allow an unauthenticated, remote attacker to access an affected system with","related":[{"title":"Critical Cisco Catalyst SD-WAN Zero-Day Under Active Exploitation","link":"https://www.infosecurity-magazine.com/news/critical-cisco-catalyst-sdwan/","source":"Infosecurity Magazine","date_rel":"1 Oct"},{"title":"Cisco security advisory (AV26-978)","link":"https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-978","source":"CCCS Alerts & Advisories","date_rel":"1 Oct"},{"title":"Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager","link":"https://thehackernews.com/2026/09/cisco-warns-of-attackers-exploiting.html","source":"The Hacker News","date_rel":"30 Sep"}]},{"title":"Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools","link":"https://thehackernews.com/2026/10/android-17-advanced-protection-locks.html","reason":"Android","category":"News","sources":["SecurityWeek","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"Google has announced a new security measure that limits access to Android's accessibility services to verified applications classified as Accessibility Tools when Advanced Protection is enabled. With malicious Android\u2026","source":"The Hacker News","date_rel":"6h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh5MS0sgdeAX_o_HWccABZaieMupy9x1vp2YHXeUfCod9bQMOAfEufGcm59eXhz4cQnwur_AjUhL1ER6FkR4nacwK2pn8K8ojfyZ254B_1Jfjk1OXwBi4VzqhPXgHukmnvVP5ItRHUeez8TcJVXvPlXRBIj0-h6YrI0rhn1G6RFyeZPT9jJf6y4Ng8D_1OD/s1600/android17.jpg","description":"Google has announced a new security measure that limits access to Android's accessibility services to verified applications classified as Accessibility Tools when Advanced Protection is enabled. With malicious Android applications abusing the API serving as the main conduit for malware and financial fraud, the tech giant said the move would block a major attack pathway. Advanced Protection is a","related":[{"title":"In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats","link":"https://www.securityweek.com/in-other-news-15k-icloud-spoofing-bugs-ai-policy-experts-phished-adblocker-spies-on-ai-chats/","source":"SecurityWeek","date_rel":"26m ago"}]},{"title":"macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor","link":"https://www.securityweek.com/macos-users-targeted-by-fake-zoom-installer-carrying-cloudsyncd-backdoor/","reason":"Macos","category":"News","sources":["Infosecurity Magazine","SecurityWeek"],"coverage":2,"cve_ids":[],"summary":"The dropper \u201ccarries a complete universal Mach-O inside itself, roughly 756 KB in the development build, and extracts it at runtime.","source":"SecurityWeek","date_rel":"1h ago","thumbnail":"","description":"","related":[{"title":"CloudSyncD MacOS Backdoor Hides Behind Fake Zoom Installer","link":"https://www.infosecurity-magazine.com/news/cloudsyncd-macos-backdoor-fake/","source":"Infosecurity Magazine","date_rel":"1 Oct"}]},{"title":"Exposed WordPress Backups Became a Gold Mine of AWS and Email Credentials","link":"https://cybersecuritynews.com/exposed-wordpress-backups/","reason":"Wordpress","category":"News","sources":["Cyber Security News","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"Exposed WordPress backups have become a valuable source of cloud and email credentials for attackers using a toolkit called TIKTOUK. Rather than relying on one technique, its components search websites for sensitive\u2026","source":"Cyber Security News","date_rel":"2h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/10/Exposed-WordPress-Backups-Became-a-Gold-Mine-of-AWS-and-Email-Credentials.webp","description":"Exposed WordPress backups have become a valuable source of cloud and email credentials for attackers using a toolkit called TIKTOUK. Rather than relying on one technique, its components search websites for sensitive files, recover stored passwords, and collect secrets from JavaScript delivered to visitors. The operation was already active at scale when researchers first observed it. A leaked control panel contained approximately 50,000 real server-side credentials across about 37,000 domains, including hundreds of AWS keys that the attackers had validated as active. LevelBlue researchers\u2026","related":[{"title":"WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory","link":"https://thehackernews.com/2026/10/wordpress-backdoor-rebuilds-itself.html","source":"The Hacker News","date_rel":"1 Oct"}]}],"worth_reading":[{"title":"Critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in the wild (CVE-2026-76504)","link":"https://www.rapid7.com/blog/post/etr-critical-cisco-catalyst-sd-wan-manager-api-authentication-bypass-exploited-in-the-wild-cve-2026-76504","reason":"CVE-2026-76504","category":"Research","sources":["CISA Alerts & Advisories","Rapid7 Blog"],"coverage":2,"cve_ids":["CVE-2026-76504"],"summary":"Overview On September 30, 2026, Cisco published a security advisory for CVE-2026-76504 , a critical API authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Manager. The vulnerability has a CVSSv3.1 score\u2026","source":"Rapid7 Blog","date_rel":"30 Sep","thumbnail":"https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp","description":"Overview On September 30, 2026, Cisco published a security advisory for CVE-2026-76504 , a critical API authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Manager. The vulnerability has a CVSSv3.1 score of 9.8 and results from improper handling of URL encoding ( CWE-177 ). An unauthenticated, remote attacker can send a crafted HTTP request that bypasses an authentication rule for a specific API endpoint, gaining access to the API with the privileges of the admin user. According to Cisco, CVE-2026-76504 is being actively exploited in the wild; Cisco PSIRT became aware of the\u2026","related":[{"title":"CISA Adds One Known Exploited Vulnerability to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/09/30/cisa-adds-one-known-exploited-vulnerability-catalog","source":"CISA Alerts & Advisories","date_rel":"30 Sep"}]}],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-79901","vendor":"Microsoft","product":"BoKS Manager boks-server","severity":"CRITICAL","score":9.9,"description":"In deployments using BoKS keytab management, affected versions of boks_keytabmd generate Active Directory service-account passwords from a predictable pseudo-random sequence seeded with the current Unix timestamp. An attacker who knows the \u2026","cwe":"CWE-338","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://www.fortra.com/security/advisories/product-security/fi-2026-012"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-79901"},{"id":"CVE-2026-96658","vendor":"Red Hat","product":"Red Hat Satellite 6.16 for RHEL 8","severity":"CRITICAL","score":9.9,"description":"A flaw was found in Foreman. An authenticated attacker with low-level permissions can achieve remote code execution (RCE) by bypassing the safemode sandbox within the templating engine. Due to improper handling of delegated methods, an atta\u2026","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://access.redhat.com/errata/RHSA-2026:74503","https://access.redhat.com/errata/RHSA-2026:74504","https://access.redhat.com/errata/RHSA-2026:74506"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-96658"},{"id":"CVE-2026-93698","vendor":"Webpros","product":"cPanel","severity":"CRITICAL","score":9.9,"description":"Insufficient validation allows arbitrary commands to be executed via the Multilang adminbin.","cwe":"CWE-78","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://docs.cpanel.net/changelogs/110-change-log/#1100148","https://docs.cpanel.net/changelogs/134-change-log/#134061","https://docs.cpanel.net/changelogs/136-change-log/#136045"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-93698"},{"id":"CVE-2026-15989","vendor":"WordPress","product":"Super Forms \u2013 Drag & Drop Form Builder","severity":"CRITICAL","score":9.8,"description":"The Super Forms \u2013 Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function whitelisti\u2026","cwe":"CWE-269","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://github.com/RensTillmann/super-forms/pull/205","https://www.wordfence.com/threat-intel/vulnerabilities/id/7eb62d35-3f0e-4733-8f7f-723d0f25b710?source=cve"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-15989"},{"id":"CVE-2026-75957","vendor":"WordPress","product":"Ultimate Multisite \u2013 WordPress Multisite SaaS & WaaS Platform","severity":"CRITICAL","score":9.8,"description":"The Ultimate Multisite \u2013 WordPress Multisite SaaS & WaaS Platform plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 2.15.0 via the `checkout_form` parameter of the `login_customer_after_checko\u2026","cwe":"CWE-287","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://plugins.trac.wordpress.org/browser/ultimate-multisite/tags/2.14.2/inc/checkout/class-checkout.php#L1223","https://plugins.trac.wordpress.org/browser/ultimate-multisite/tags/2.14.2/inc/checkout/class-checkout.php#L208","https://plugins.trac.wordpress.org/browser/ultimate-multisite/tags/2.14.2/inc/checkout/class-checkout.php#L2489"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-75957"},{"id":"CVE-2026-103244","vendor":"sgoudelis","product":"ground-station","severity":"CRITICAL","score":9.8,"description":"ground-station versions before 0.8.0 contain an authentication bypass vulnerability in the setup.restore command that allows unauthenticated attackers to execute arbitrary SQL during first-run setup mode. Attackers can invoke setup.restore \u2026","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://github.com/sgoudelis/ground-station/commit/940df2128e57fa779d0ddee2d9726bd829fc61e1","https://github.com/sgoudelis/ground-station/security/advisories/GHSA-3mqj-q84c-crjq","https://www.vulncheck.com/advisories/ground-station-before-0.8.0-authentication-bypass-via-setup-restore"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-103244"},{"id":"CVE-2026-103752","vendor":"Paul Ryan","product":"Authorizer","severity":"CRITICAL","score":9.8,"description":"Unauthenticated Privilege Escalation in Authorizer <= 3.15.3 versions.","cwe":"CWE-266","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://patchstack.com/database/wordpress/plugin/authorizer/vulnerability/wordpress-authorizer-plugin-3-15-3-privilege-escalation-vulnerability?_s_id=cve"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-103752"},{"id":"CVE-2026-12627","vendor":"Fortra","product":"Fortra's Core Privileged Access Manager (BoKS)","severity":"CRITICAL","score":9.8,"description":"Fortra's Core Privileged Access Manager (BoKS) contains a stack-based buffer overflow vulnerability in boks_autoregisterd. A remote attacker with network access to the autoregistration service may be able to trigger memory corruption during\u2026","cwe":"CWE-121","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://www.fortra.com/security/advisories/product-security/fi-2026-017"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-12627"},{"id":"CVE-2026-56154","vendor":"Apache","product":"Apache HTTP Server","severity":"CRITICAL","score":9.8,"description":"Use After Free vulnerability in Apache HTTP Server's mod_rewrite when using lookahead (%{LA-U:HTTP:...})\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.","cwe":"CWE-416","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/17"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-56154"},{"id":"CVE-2026-57941","vendor":"Apache","product":"Apache HTTP Server","severity":"CRITICAL","score":9.8,"description":"Use After Free vulnerability in Apache HTTP Server's mod_http2\u00a0via shared session->bbtmp re-entrancy\n\n\n\nThis issue affects Apache HTTP Server: from 2.4.0 through 2.4.68.","cwe":"CWE-416","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://httpd.apache.org/security/vulnerabilities_24.html","http://www.openwall.com/lists/oss-security/2026/10/01/19"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-57941"}],"vendor_spikes":[{"vendor":"WordPress","count":65,"critical_count":5},{"vendor":"Apache","count":28,"critical_count":3},{"vendor":"Unknown","count":27,"critical_count":0},{"vendor":"TryGhost","count":24,"critical_count":0},{"vendor":"Red Hat","count":17,"critical_count":3},{"vendor":"n8n-io","count":15,"critical_count":2},{"vendor":"HCL Software","count":14,"critical_count":0},{"vendor":"Microsoft","count":13,"critical_count":2},{"vendor":"Johnson Controls","count":12,"critical_count":0},{"vendor":"JetBrains","count":10,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":20,"new_cve_count":395,"has_news_data":true,"has_cve_data":true,"news_for_cve":{"CVE-2026-104286":{"anchor":"#dev-2","rank":2,"coverage":4}}}