Daily briefing · September 5, 2026

WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy Day

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm

September 5, 2026 closes with a calm threat verdict: no vulnerabilities moved to weaponized status, no active exploitation confirmed, and no VulnCheck early-warning signals. Still, the day produced 141 new CVEs — 22 of them critical — anchored by a pre-auth RCE in N-central and a cluster of severe WordPress plugin flaws that demand attention from defenders managing web-facing assets.

Today’s brief
  • No active exploitation or KEV additions today, but 22 critical CVEs published — patch queues should be updated
  • N-central pre-auth RCE (CVSS 10.0) is the day's most dangerous single finding; update to 2026.3.1.14 immediately
  • Multiple WordPress plugins carry CVSS 9.8 flaws: auth bypass, account takeover, PHP object injection, and RCE all present
  • Brazil remains a primary ransomware target: three new victims claimed in a single day across transport, manufacturing, and services
22
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-86218CVSS 10affects N-central
A pre-authentication remote code execution vulnerability scoring a perfect 10.0 in N-central means any internet-exposed instance can be fully compromised without credentials — upgrading to version 2026.3.1.14 is non-negotiable.
2
CVE-2026-86152CVSS 10affects CP3
OS command injection in the Tenda CP3 router's Kylin component (CVSS 10.0) is remotely exploitable with no authentication, making unpatched devices a trivial entry point for network intrusion.
3
CVE-2026-83627CVSS 9.8affects Hummingbird Performance – Cache & Page Speed Optimization for Core Web Vitals | Critical CSS | Minify CSS | Defer CSS Javascript | CDN
The Hummingbird WordPress plugin writes its debug log to a web-accessible PHP file, enabling unauthenticated RCE on sites running version 3.21.0 or earlier — a low-barrier attack on a widely deployed caching plugin.
4
CVE-2024-11080CVSS 9.8affects Post Grid
Unauthenticated hook injection in the ComboBlocks Post Grid plugin (versions 2.2.32–2.3.1) allows attackers to trigger arbitrary WordPress action hooks, potentially chaining into privilege escalation if no additional controls exist.
5
CVE-2026-13447CVSS 9.8affects MStore API – Create Native Android & iOS Apps On The Cloud
The MStore API plugin's JWT verification skips the cryptographic signature check entirely, letting attackers forge tokens and bypass authentication on any site running version 4.20.0 or below.
6
CVE-2026-75816CVSS 9.8affects Frontend Admin by DynamiApps
Frontend Admin by DynamiApps allows full account takeover up to version 3.29.12 due to missing ownership checks and a bypassable authorization gate triggered by non-numeric post IDs — a straightforward path to administrator hijacking.
7
CVE-2026-16310CVSS 9.8affects MemberDash
An IDOR in MemberDash (up to 1.8.5) lets unauthenticated users reset any WordPress account password, including administrator accounts, by simply supplying an arbitrary user ID during registration.
8
CVE-2026-10196CVSS 9.8affects Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails
PHP object injection via unsafe deserialization in Mail Mint (up to 1.31.0) is exploitable by unauthenticated attackers and, with a POP chain in place, can escalate to remote code execution.
9
CVE-2026-86153CVSS 9.4affects CP3
Improper privilege management in the Tenda CP3's redirect component (CVSS 9.4) is remotely exploitable and compounds the attack surface alongside the other CP3 flaws disclosed today.
10
CVE-2026-86151CVSS 9.4affects CP3
A second OS command injection in Tenda CP3's network configuration management (CVSS 9.4) reinforces that this device model carries multiple independently exploitable critical flaws and should be treated as untrusted until patched.
Ransomware today

Three Brazilian organizations were recently claimed as ransomware victims: Lider Aviacao (transportation) by thegentlemen, Engefitas (manufacturing) by Vexy Ransomware, and ialegre.com (other services) by settra. Over the past 30 days, thegentlemen has been the most active group with seven confirmed victims, all in Brazil, followed by direwolf, krybit, and dragonforce — all concentrating heavily on Brazilian targets.

Lider Aviacao BRthegentlemen · Transportation
Engefitas BRVexy Ransomware · Manufacturing
ialegre.com BRsettra · Other
thegentlemen 7direwolf 3krybit 3emperador 2dragonforce 2L Group 2
Active groups & APTs

Several threat actors are being tracked for recent activity, including dragonforce, fulcrumsec, handala, kazu, kelvinsecurity, and the Iranian-linked group blackshadow. While no confirmed new victims have been attributed to these groups in the current reporting window, their monitored status indicates continued operational readiness that defenders should not discount.

Brazil focus

Brazil is facing sustained ransomware pressure, with eight victims identified across multiple sectors in the past 30 days, including healthcare (paipharma.com, Exacta Optech Labcenter), manufacturing (Engefitas), transportation (Lider Aviacao), and others. The concentration of active groups — thegentlemen, direwolf, krybit, emperador, and BrainCipher — targeting Brazilian organizations signals an ongoing campaign environment that elevates risk for domestic enterprises across industries.

Lider Aviacaothegentlemen · Transportation
EngefitasVexy Ransomware · Manufacturing
ialegre.comsettra · Other
Oportunidadosdirewolf
paipharma.comBrainCipher · Healthcare
Exacta Optech Labcenterthegentlemen · Healthcare
frm.ind.brZaWoo · Other
Uniguacuemperador · Other
Today’s recommendation: Prioritize patching N-central to 2026.3.1.14 and auditing all Tenda CP3 deployments; WordPress administrators should immediately update Hummingbird, MStore API, Frontend Admin, MemberDash, Mail Mint, and ComboBlocks, and verify that debug logging to web-accessible PHP files is disabled.
With authentication bypass, object injection, and RCE flaws spread across widely deployed plugins and network devices, now is the right moment to validate which of these assets are actually exposed in your environment before an attacker does it for you.Every CVE above is a possible door — find out which ones are open in your environment with a free attack-surface check.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 8, 2026Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 202622 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 202610 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →
Share