Daily briefing · September 9, 2026

Three CVEs Already Exploited Before CISA Confirmation, Dual Check Point RCE and cPanel SQLi-to-Root Round Out a High-Alert Day

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — attention3 seen before CISA

September 9, 2026 carries an ATTENTION verdict: three vulnerabilities were observed being exploited in the wild by VulnCheck ahead of any official CISA confirmation, underscoring how early-warning telemetry now outpaces traditional advisories. Among 367 new CVEs published today — 24 of them critical — the day's standouts include unauthenticated RCE on KGUARD DVR devices and authentication-bypass flaws in widely deployed WordPress infrastructure, all requiring immediate defensive attention. A cPanel SQLi-to-root exploit was weaponized on the same day it was disclosed, a clear signal that attackers are watching the feed just as closely as defenders.

Today’s brief
  • CVE-2026-87827 (KGUARD DVR, CVSS 10.0): unauthenticated remote command execution, already exploited before CISA confirmation.
  • CVE-2026-67401 (cPanel, CVSS 9.9): SQLi-to-root RCE armed same day as disclosure — proof-of-concept already public.
  • Two Check Point Quantum Security Gateway RCEs (CVE-2026-85103 / CVE-2026-85102, CVSS 9.8 each) expose VPN infrastructure to unauthenticated attackers.
  • Brazil is under heavy ransomware pressure: six victims identified recently across Healthcare, Technology, Manufacturing, and Retail, with thegentlemen leading activity.
24
critical
3
Actively exploited
3
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-87827◆ VulnCheckCVSS 10affects KGUARD_firmware
Unauthenticated command execution on KGUARD DVR firmware exposed on all network interfaces — CVSS 10.0 and already exploited in the wild before CISA confirmation, making this the most urgent item of the day. Any KGUARD device reachable from the internet or an internal segment should be considered actively targeted; network isolation and firmware replacement are the only reliable mitigations.
2
CVE-2026-80099◆ VulnCheckHIGH 8.8affects WP Module Data
Authentication bypass affecting multiple Newfold WordPress plugins that bundle the wp-module-data module allows unauthenticated callers to pass a degenerate HMAC Bearer token check and gain elevated REST API access — observed by VulnCheck before CISA acted. WordPress environments running any Newfold-branded plugin should audit installed modules and apply updates immediately.
3
CVE-2026-14359◆ VulnCheckHIGH 8.8affects YITH WooCommerce Waitlist Premium
Privilege escalation in YITH WooCommerce Waitlist Premium (up to v3.35.0) lets an unauthenticated attacker inject arbitrary variables via parse_str()/extract() on an unprotected AJAX action, effectively taking over WordPress site roles — again spotted by VulnCheck before official classification. WooCommerce-based stores using this plugin up to version 3.35.0 should patch without delay.
4
CVE-2026-79696CVSS 10affects Agent Development Kit (ADK) for Python
Code injection in Google Cloud ADK for Python (versions 2.0.0–2.6.0) allows an unauthenticated remote attacker to execute arbitrary code via crafted test session replay when pytest is installed on Cloud Run or GKE environments — CVSS 10.0. Teams running ADK-based AI agents in cloud environments should verify their version and apply the fix before exposing any web interface.
5
CVE-2026-85978CVSS 10affects Akana
Unauthenticated RCE in the Akana API Platform Policy Manager console stems from a path normalization mismatch that lets attackers bypass authentication and reach a script-evaluation endpoint — CVSS 10.0. API gateway infrastructure running Akana should be treated as critically exposed until patched or isolated from untrusted networks.
6
CVE-2026-19583CVSS 9.9affects Velociraptor
Velociraptor's permission model fails to gate CLIENT_EVENTS monitoring artifacts the same way it gates direct execution artifacts, meaning a user without EXECVE rights can still schedule monitoring tasks that run arbitrary commands on endpoints — CVSS 9.9. Organizations using Velociraptor for endpoint telemetry should update immediately and audit any recently scheduled client monitoring artifacts.
7
CVE-2026-67401CVSS 9.9PoCsame dayaffects cPanel
A SQL injection in cPanel's EmailTrack component can be chained to achieve remote code execution as root by a mail-enabled account — CVSS 9.9, with a proof of concept already circulating and weaponized on the same day of disclosure. Hosting providers and managed service operators running cPanel should treat this as an emergency patch given the zero-day armament timeline.
8
CVE-2026-18351CVSS 9.8affects Drag and Drop File Upload for Elementor Forms
Arbitrary file upload in the Drag and Drop File Upload for Elementor Forms WordPress plugin (up to v1.6.0) bypasses MIME type validation by abusing attacker-controlled regex keys, enabling web shell deployment — CVSS 9.8. Any WordPress site using this plugin should update immediately and inspect upload directories for unexpected files.
9
CVE-2026-85103CVSS 9.8affects Quantum Security Gateway
A heap-based buffer overflow in the ASN.1 parsing of VPN certificates on Check Point Quantum Security Management and Gateway allows unauthenticated remote code execution — CVSS 9.8. VPN perimeter devices are high-value targets; patching this before the weekend is strongly advisable to avoid exploitation over low-traffic periods.
10
CVE-2026-85102CVSS 9.8affects Quantum Security Gateway
Improper certificate trust validation during VPN negotiation on Check Point Quantum Security Gateway provides a second, distinct unauthenticated RCE path — CVSS 9.8 — compounding the risk from CVE-2026-85103 on the same product family. Organizations relying on Check Point for network perimeter security face a dual critical exposure and should apply vendor guidance without delay.
Ransomware today

Ransomware activity targeting Brazil has intensified recently, with six victims identified in the latest period spanning Healthcare, Technology, Manufacturing, and Retail sectors. The group thegentlemen is the most prolific actor over the past 30 days with nine confirmed victims in Brazil, including Biotipo Jeans, Zanini, and Mutant; Vexy Ransomware claimed both Logar Network Solutions and Engefitas; lockbit5 hit the healthcare provider amorsaude.com.br; and Dark Project targeted manufacturer Alurwalls. The breadth of sectors and the volume of Brazilian victims signals that threat actors are running broad opportunistic campaigns rather than selective targeting.

amorsaude.com.br BRlockbit5 · Healthcare
Logar Network Solutions BRVexy Ransomware · Technology
Alurwalls BRDark Project · Manufacturing
Biotipo Jeans BRthegentlemen · Retail & E-Commerce
Zanini BRthegentlemen · Manufacturing
Mutant BRthegentlemen · Other
thegentlemen 9direwolf 3krybit 3dragonforce 2emperador 2Vexy Ransomware 2
Active groups & APTs

Several threat groups are being tracked for updated activity, including dragonforce, fulcrumsec, funksec, linkc, spacebears, and the Iranian-attributed blackshadow — none of which have confirmed new victims in the current window but whose infrastructure or tooling has been updated or observed recently. The presence of dragonforce in both the APT tracking list and the 30-day ransomware statistics (two Brazilian victims) suggests operational overlap between criminal and state-aligned actors worth monitoring closely.

Brazil focus

Brazil is one of the most heavily targeted countries in the current ransomware landscape, with at least eight organizations claimed as victims over recent weeks across Transportation (Lider Aviacao), Manufacturing (Zanini, Alurwalls, Engefitas), Healthcare (amorsaude.com.br), Technology (Logar Network Solutions), Retail (Biotipo Jeans), and other sectors. The dominance of thegentlemen — responsible for nine of the last thirty days' Brazilian victims — combined with active groups like Vexy Ransomware, direwolf, krybit, dragonforce, and emperador indicates that Brazilian organizations face sustained multi-group pressure and should prioritize incident response readiness alongside patching.

Logar Network SolutionsVexy Ransomware · Technology
amorsaude.com.brlockbit5 · Healthcare
Zaninithegentlemen · Manufacturing
Biotipo Jeansthegentlemen · Retail & E-Commerce
AlurwallsDark Project · Manufacturing
Mutantthegentlemen · Other
Lider Aviacaothegentlemen · Transportation
EngefitasVexy Ransomware · Manufacturing
Today’s recommendation: Patch or isolate KGUARD DVR devices, Check Point Quantum Security Gateways, and cPanel installations immediately, as these combine critical CVSS scores with confirmed or same-day weaponization. WordPress administrators should audit all installed plugins against today's affected components and restrict file upload functionality until updates are confirmed.
With multiple critical vulnerabilities weaponized the same day they were disclosed and active exploitation detected before official confirmation, the only reliable way to know whether your organization is exposed is to continuously validate your actual attack surface — not just your patch records.Find out in minutes, with a free exposure assessment, where your organization is truly exposed.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 8, 2026Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 202622 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 202610 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →
Share