Sunday, October 11, 2026 · generated · about 5 min read
Morning Brief
Patch today vendors with the most new CVEs today
- WordPress 7 critical 101
- jeecgboot 70
- ThemeREX Group 17 critical 18
- ThemeREX 16 critical 17
- Microsoft 1 critical 12
- kutethemes 12
- Unknown 6
- 1Panel-dev 6
- bPlugins 5
- AncoraThemes 4 critical 5
Ranked by CVE count. Each vendor opens the CVE Feed filtered to that vendor and these dates.
Top developments ranked by cross-source trending
-
Image: Hak5 Why Apple Says Your Mac Is at Risk From AI | Threat Wire
Are AI agents becoming a cybersecurity threat? From fake AI-generated bug bounty submissions overwhelming Google's vulnerability rewards program to Apple's warning about AI agents accessing sensitive Mac data, this week's ThreatWire explores how artificial intelligence is changing cybersecurity — and creating new security risks. Google has temporarily paused its open-source vulnerability rewards program, curl has shut down its bug bounty program, and Debian has announced more than 1,000 kernel CVEs. Meanwhile, Apple is tightening macOS Full Disk Access controls as concerns grow over…
Also in Bleeping Computer SecurityWeek The Hacker News +3
-
Microsoft Teams to Warn Users About Malicious Links Hidden in QR Codes
Microsoft is extending Teams security to detect malicious links hidden inside QR codes and warn users after a message has been delivered. The update adds QR code checks to existing Microsoft Defender for Office 365 protections, giving users clearer warnings and security teams more data to investigate suspicious messages. According to Message Center notice MC1490905 , published on October 7, worldwide rollout begins in early October 2026 and is expected to finish by early November. The feature applies to organizations using Microsoft Teams with Defender for Office 365 and requires no separate…
Also in The Hacker News Bleeping Computer
-
Citrix Patches Critical NetScaler Flaw That Could Enable RCE in SAML Deployments
Citrix has released patches for yet another critical security flaw impacting NetScaler ADC and NetScaler Gateway that could result in remote code execution or denial-of-service (DoS) under certain conditions. "CVE-2026-107406 is a memory overflow vulnerability that may lead to remote code execution or denial-of-service under specific configuration conditions," Citrix said. The vulnerability
Also in CCCS Alerts & Advisories CCCS Alerts & Advisories Bleeping Computer
-
One Prompt Could Hijack AWS AI Agents and Steal Cloud Credentials
A single prompt sent to a public-facing AI agent could have exposed every Amazon Bedrock AgentCore agent in the same AWS account and region, according to new research from Zenity Labs. The attack chain, named AgentCorruption, gave the researchers access to private chats, source code, long-term memories, API keys, OAuth tokens, and secrets held in AWS Secrets Manager. Amazon Bedrock AgentCore is a managed service for building and running AI agents. Zenity found that an agent with a tool able to make web requests could be told to contact the local metadata endpoint at 169.254.169.254 . This…
Also in The Register Security
-
CastleStealer Malware Uses Browser Protection Bypass and Remote Shell to Expand Attacker Access
CastleStealer, an emerging C#-based information stealer, has added browser protection bypass and remote shell features that give its operators a wider path into compromised Windows systems. The newer malware samples can collect browser data protected by Chromium’s App-Bound Encryption, run commands on a victim device, download extra payloads, and move stolen information through small encrypted network transmissions rather than one large archive. Flashpoint’s analysis shows that the malware is becoming more capable even though it has not yet reached the broad use seen with major established…
Also in Microsoft Security Microsoft Security Microsoft Security
CVE-2026-62744 ↗CVE-2026-68875 ↗CVE-2026-68878 ↗View on Security Feed
-
$10 million bounty offered for Chinese Hafnium hacker accused of Microsoft Exchange Server mega-attack
The US State Department is offering up to US $10 million for information about the whereabouts of Zhang Yu, a 44-year-old Chinese national who is accused of being a key figure in China's state-sponsored hacking group…
Also in Microsoft Security
-
Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories
Cybersecurity researchers have disclosed details of an ongoing credential-theft campaign that has compromised two high-profile open-source maintainer accounts to push a malicious workflow into over 340 repositories. "Using the account of Takashi Kitao, author of the 18,400-star game engine pyxel, the attacker pushed a malicious workflow to 27 repositories starting at 13:20 UTC," StepSecurity
Also in Cyber Security News
-
AnyDesk Linux Flaw Lets Remote Attackers Execute Code as Root Without Authentication
A working proof-of-concept for a serious AnyDesk Linux vulnerability that can let remote attackers run commands as root without authentication or user approval. The issue, named AnyPwn, affects AnyDesk Linux 8.0.2 and was fixed in version 8.0.3. Organizations using AnyDesk for Linux should update immediately and check whether TCP port 7070 is exposed to untrusted networks. The flaw was discovered by Rick de Jager of the V12 security team using V12, an AI-powered security review platform. V12 first disclosed the issue publicly in June and described it as a pre-authentication, zero-click remote…
Also in The Hacker News
-
Threat Actors Exploit Critical AhsayCBS Flaws to Drop Webshells and XMRig Cryptominer
Threat actors are exploiting AhsayCBS flaws, including CVE-2026-105133 and CVE-2026-105134, to deploy webshells and XMRig cryptominers. Update to 10.3.4 and restrict access now.
Also in SecurityWeek
-
Citrix gives NetScaler admins another critical reason to patch
Citrix is urging customers to patch another critical NetScaler vulnerability after weeks of disclosures involving actively exploited flaws. CVE-2026-107406 affects NetScaler ADC and NetScaler Gateway and can lead to remote code execution (RCE) or denial of service (DoS). It carries a CVSS v4.0 score of 9.5. The affected configurations depend on the software version. Older builds are vulnerable when configured as a SAML (Security Assertion Markup Language) service provider (SP) or identity provider (IdP); some more recent builds are affected only in the identity provider configuration…
Also in SecurityWeek
Vulnerability watch what to look at, most urgent first
| Details | CVE | Product | Severity | CVSS | EPSS | KEV | Fix | In the news | |
|---|---|---|---|---|---|---|---|---|---|
| Highest scoring today 10new CVEs, highest CVSS first | |||||||||
| CVE-2026-42696 | SiteVault – Backup, Restore, Migration & CloningRoyal Plugins | Critical | 10.0 | — | — | None linked | — | CVSS 10.0No fix linked | |
What it isUnauthenticated Remote Code Execution (RCE) in SiteVault – Backup, Restore, Migration & Cloning <= 1.5.19 versions. Attack
Exploitation
|
|||||||||
| CVE-2026-62024 | CodeBard Help DeskCodeBard | Critical | 9.9 | — | — | None linked | — | CVSS 9.9No fix linked | |
What it isSubscriber Arbitrary File Upload in CodeBard Help Desk <= 1.1.2 versions. Attack
Exploitation
|
|||||||||
| CVE-2026-62129 | Creator LMSWPFunnels | Critical | 9.9 | — | — | None linked | — | CVSS 9.9No fix linked | |
What it isContributor Arbitrary File Upload in Creator LMS <= 1.2.21 versions. Attack
Exploitation
|
|||||||||
| CVE-2026-108540 | SpugOpenSpug | Critical | 9.9 | — | — | None linked | — | CVSS 9.9No fix linked | |
What it isA flaw has been found in OpenSpug Spug up to 3.4.0/4.0.1. This impacts an unknown function of the file /exec/transfer of the component File Transfer. Executing a manipulation can lead to os command injection. The attack may be launched remo… Attack
Exploitation
|
|||||||||
| CVE-2026-104803 | WPCOM MemberWordPress | Critical | 9.8 | 0.4% | — | None linked | — | EPSS 0.4%CVSS 9.8No fix linked | |
What it isThe WPCOM Member plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.7.27 via the `uuid` and `code` parameters of the social-login callback handler registered on the `init` hook. The vulnerabi… Attack
Exploitation
|
|||||||||
| CVE-2026-62045 | BookloversThemeREX Group | Critical | 9.8 | 0.3% | — | None linked | — | EPSS 0.3%CVSS 9.8No fix linked | |
What it isDeserialization of Untrusted Data vulnerability in ThemeREX Group Booklovers booklovers allows Object Injection.This issue affects Booklovers: from n/a through 2.13.0. Attack
Exploitation
|
|||||||||
| CVE-2026-62046 | GutentypeThemeREX Group | Critical | 9.8 | 0.3% | — | None linked | — | EPSS 0.3%CVSS 9.8No fix linked | |
What it isDeserialization of Untrusted Data vulnerability in ThemeREX Group Gutentype gutentype allows Object Injection.This issue affects Gutentype: from n/a through 2.1.12. Attack
Exploitation
|
|||||||||
| CVE-2026-93927 | VetoAxiomthemes | Critical | 9.8 | 0.3% | — | None linked | — | EPSS 0.3%CVSS 9.8No fix linked | |
What it isDeserialization of Untrusted Data vulnerability in Axiomthemes Veto veto allows Object Injection.This issue affects Veto: from n/a through 1.6.0. Attack
Exploitation
|
|||||||||
| CVE-2026-93929 | TravesiaThemeREX Group | Critical | 9.8 | 0.3% | — | None linked | — | EPSS 0.3%CVSS 9.8No fix linked | |
What it isDeserialization of Untrusted Data vulnerability in ThemeREX Group Travesia travesia allows Object Injection.This issue affects Travesia: from n/a through 1.1.16. Attack
Exploitation
|
|||||||||
| CVE-2026-93930 | TantraThemeREX Group | Critical | 9.8 | 0.3% | — | None linked | — | EPSS 0.3%CVSS 9.8No fix linked | |
What it isDeserialization of Untrusted Data vulnerability in ThemeREX Group Tantra tantra allows Object Injection.This issue affects Tantra: from n/a through 2.9.0. Attack
Exploitation
|
|||||||||
Click a row, or press +, to expand it.EPSS is FIRST's estimated chance of exploitation in the next 30 days.Full CVE Feed
Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score. No AI writes any of this, and every number traces back to something already published on those two tools.
Top developments come from the Security Feed's cross-source trending detection. Vulnerability watch comes from the CVE Feed's daily NVD and CISA KEV sync.