Daily briefing · September 2, 2026

WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active Exploitation

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — attention1 seen before CISA

September 2, 2026 demands defensive attention: 310 new CVEs were published, 21 classified as critical, with one vulnerability in active exploitation — CVE-2026-9055, affecting the Amelia WordPress plugin, flagged by VulnCheck before any CISA confirmation, and weaponized on the same day of disclosure. The day's highlight is a concentration of critical flaws across WordPress plugins and major Cisco infrastructure software, spanning privilege escalation, arbitrary file upload, unauthenticated remote code execution, and improper access control — all with proof-of-concept code already available.

Today’s brief
  • CVE-2026-9055 (Amelia plugin): actively exploited, weaponized on day zero — patch or disable immediately.
  • Two critical Cisco IOS XR flaws (CVE-2026-20279, CVE-2026-20274) and one Cisco NX-OS RCE (CVE-2026-20212) expose core network infrastructure to unauthenticated attackers.
  • Multiple WordPress plugins carry unauthenticated file upload, arbitrary file deletion, and PHP code execution vulnerabilities — high exposure for shared hosting environments.
  • Brazil is a top ransomware target this period: five new victims identified recently, including two in Healthcare, with thegentlemen, BrainCipher, and direwolf among the most active groups.
21
critical
1
Actively exploited
1
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-9055◆ VulnCheckCVSS 9.8PoCsame dayaffects Booking for Appointments and Events Calendar – Amelia
Active exploitation confirmed by VulnCheck before CISA, with a proof-of-concept weaponized on the same day of disclosure — attackers can manipulate the 'type' parameter in the Amelia Premium plugin (versions 8.0–9.6.2) to escalate their role to manager-level, effectively hijacking site administration. Any WordPress site running this plugin should be treated as actively targeted until patched.
2
CVE-2026-4357CVSS 10PoCaffects Embed HTML5 Game
A CVSS 10.0 flaw in the Embed HTML5 Game WordPress plugin allows unauthenticated attackers to upload PHP backdoors directly to the server with no access controls in place — full remote code execution with zero authentication required. This is one of the most severe unauthenticated upload vulnerabilities disclosed this cycle.
3
CVE-2026-77009CVSS 9.9PoCaffects WatchMan-Site7
The WatchMan-Site7 plugin exposes an unrestricted debugging console that executes arbitrary PHP code for any authenticated user, including low-privilege subscribers — effectively granting server-level code execution to anyone with a WordPress account. The risk is extreme on multi-user sites or membership platforms.
4
CVE-2026-78657CVSS 9.8affects SigmaForms Pro – AI Generated Forms
SigmaForms Pro allows unauthenticated attackers to delete arbitrary server files through the delete_submission_files function, a path that reliably leads to remote code execution when critical files such as configuration or index files are removed. All versions up to 1.4.11 are affected and there is no authentication barrier.
5
CVE-2026-19117CVSS 9.8affects Secret Server (On-Prem)
Under specific conditions in Secret Server (On-Prem), an attacker can register a malicious FIDO2 credential against a target account and authenticate as that user — effectively bypassing multi-factor authentication in an on-premises privileged access management solution. Organizations relying on Secret Server for privileged credential storage should treat this as a high-priority remediation.
6
CVE-2026-20279CVSS 9.8affects Cisco IOS XR Software
Cisco internally discovered and disclosed improper access control vulnerabilities in IOS XR Software, scored CVSS 9.8, that could allow remote attackers to gain unauthorized access to affected routers — devices that sit at the core of carrier and enterprise networks. Cisco's proactive disclosure should not reduce urgency: patching core routing infrastructure is critical.
7
CVE-2026-20274CVSS 9.8affects Cisco IOS XR Software
A companion critical flaw in Cisco IOS XR involves improper resource control, also scored CVSS 9.8, and similarly discovered through Cisco's internal security review. Its co-existence with CVE-2026-20279 means IOS XR operators may face compounded risk and should apply the hardening releases covering both issues simultaneously.
8
CVE-2026-20212CVSS 9.8affects Cisco NX-OS Software
Cisco Nexus 9000 Series Switches are exposed to unauthenticated remote code execution with root privileges via TCP ports 43210 and 43211, accessible by default in the L3 VRF — an attacker on the network can connect and execute arbitrary commands as root. Data center operators running NX-OS with Silicon One integration should treat this as an emergency-level patch.
9
CVE-2026-53611CVSS 9.8affects looking-glass
An OS command injection flaw in the Looking Glass network diagnostic platform (prior to 1.3.5) stems from an unanchored regular expression that fails to sanitize user input, allowing attackers to inject shell commands through the diagnostic interface. Network operations teams using this tool for BGP and routing diagnostics are directly exposed.
10
CVE-2025-9314CVSS 9.8PoCaffects Developer Tools
The Developer Tools WordPress plugin (through version 1.1.3) bundles a vulnerable SWFUpload component that permits unauthenticated arbitrary file upload — a classic attack vector that can lead directly to web shell deployment and full server compromise. The bundled legacy component significantly widens the attack surface.
Ransomware today

Ransomware activity remains intensive, with five Brazilian victims identified recently across multiple groups: direwolf claimed Oportunidados, BrainCipher targeted paipharma.com in the Healthcare sector, thegentlemen hit Exacta Optech Labcenter (Healthcare), emperador claimed Uniguacu, and ZaWoo listed frm.ind.br. Over the past 30 days, thegentlemen leads activity with six victims — all in Brazil — followed by krybit (four, all in Brazil) and direwolf (three, all in Brazil), indicating a sustained and geographically concentrated campaign against Brazilian organizations.

Oportunidados BRdirewolf
paipharma.com BRBrainCipher · Healthcare
Uniguacu BRemperador · Other
Exacta Optech Labcenter BRthegentlemen · Healthcare
frm.ind.br BRZaWoo · Other
thegentlemen 6krybit 4direwolf 3emperador 2dragonforce 2L Group 2
Active groups & APTs

Several threat actor groups are currently being tracked as active or recently updated, including dragonforce, fulcrumsec, handala, kazu, kelvinsecurity, and the Iran-linked blackshadow. While no new confirmed victims are attributed to these groups in the current window, their active monitoring status suggests operational readiness and potential forthcoming campaigns — defenders should watch for indicators associated with these actors, particularly blackshadow given its state-linked origins.

Brazil focus

Brazil continues to face disproportionate ransomware pressure over the past 30 days, with organizations in Healthcare proving to be a recurring target: paipharma.com (BrainCipher), Exacta Optech Labcenter (thegentlemen), and www.neooftalmo.com.br (krybit) were all recently claimed. Technology and unclassified sectors are also affected, with sysconth.com (krybit) and amzur.com (unsafe) among recent victims. The concentration of active groups operating almost exclusively within Brazil — thegentlemen, krybit, direwolf, and emperador — signals that Brazilian entities are being deliberately selected as primary targets.

Oportunidadosdirewolf
paipharma.comBrainCipher · Healthcare
Exacta Optech Labcenterthegentlemen · Healthcare
Uniguacuemperador · Other
frm.ind.brZaWoo · Other
amzur.comunsafe
sysconth.comkrybit · Technology
www.neooftalmo.com.brkrybit · Healthcare
Today’s recommendation: Prioritize immediate patching or disabling of affected WordPress plugins — especially Amelia Premium, Embed HTML5 Game, WatchMan-Site7, and SigmaForms Pro — as all carry unauthenticated or low-privilege exploitation paths with existing proof-of-concept code. Cisco network operators should apply IOS XR hardening releases and restrict or firewall TCP ports 43210 and 43211 on Nexus 9000 devices without delay.
With critical vulnerabilities spanning WordPress plugins, enterprise network infrastructure, and PAM solutions simultaneously, now is the moment to validate your own attack surface and confirm that exposure to these vectors is either patched, mitigated, or monitored.Don’t wait to become a statistic: validate today, at no cost, whether any of these vectors reach your systems.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 8, 2026Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 202622 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 202610 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →
Share