Daily briefing · September 9, 2026
Three CVEs Already Exploited Before CISA Confirmation, Dual Check Point RCE and cPanel SQLi-to-Root Round Out a High-Alert Day
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — attention3 seen before CISA
September 9, 2026 carries an ATTENTION verdict: three vulnerabilities were observed being exploited in the wild by VulnCheck ahead of any official CISA confirmation, underscoring how early-warning telemetry now outpaces traditional advisories. Among 367 new CVEs published today — 24 of them critical — the day's standouts include unauthenticated RCE on KGUARD DVR devices and authentication-bypass flaws in widely deployed WordPress infrastructure, all requiring immediate defensive attention. A cPanel SQLi-to-root exploit was weaponized on the same day it was disclosed, a clear signal that attackers are watching the feed just as closely as defenders.
Today’s brief
- CVE-2026-87827 (KGUARD DVR, CVSS 10.0): unauthenticated remote command execution, already exploited before CISA confirmation.
- CVE-2026-67401 (cPanel, CVSS 9.9): SQLi-to-root RCE armed same day as disclosure — proof-of-concept already public.
- Two Check Point Quantum Security Gateway RCEs (CVE-2026-85103 / CVE-2026-85102, CVSS 9.8 each) expose VPN infrastructure to unauthenticated attackers.
- Brazil is under heavy ransomware pressure: six victims identified recently across Healthcare, Technology, Manufacturing, and Retail, with thegentlemen leading activity.
Critical highlights
1
Unauthenticated command execution on KGUARD DVR firmware exposed on all network interfaces — CVSS 10.0 and already exploited in the wild before CISA confirmation, making this the most urgent item of the day. Any KGUARD device reachable from the internet or an internal segment should be considered actively targeted; network isolation and firmware replacement are the only reliable mitigations.
2
Authentication bypass affecting multiple Newfold WordPress plugins that bundle the wp-module-data module allows unauthenticated callers to pass a degenerate HMAC Bearer token check and gain elevated REST API access — observed by VulnCheck before CISA acted. WordPress environments running any Newfold-branded plugin should audit installed modules and apply updates immediately.
3
CVE-2026-14359◆ VulnCheckHIGH 8.8affects YITH WooCommerce Waitlist Premium Privilege escalation in YITH WooCommerce Waitlist Premium (up to v3.35.0) lets an unauthenticated attacker inject arbitrary variables via parse_str()/extract() on an unprotected AJAX action, effectively taking over WordPress site roles — again spotted by VulnCheck before official classification. WooCommerce-based stores using this plugin up to version 3.35.0 should patch without delay.
4
Code injection in Google Cloud ADK for Python (versions 2.0.0–2.6.0) allows an unauthenticated remote attacker to execute arbitrary code via crafted test session replay when pytest is installed on Cloud Run or GKE environments — CVSS 10.0. Teams running ADK-based AI agents in cloud environments should verify their version and apply the fix before exposing any web interface.
5
Unauthenticated RCE in the Akana API Platform Policy Manager console stems from a path normalization mismatch that lets attackers bypass authentication and reach a script-evaluation endpoint — CVSS 10.0. API gateway infrastructure running Akana should be treated as critically exposed until patched or isolated from untrusted networks.
6
Velociraptor's permission model fails to gate CLIENT_EVENTS monitoring artifacts the same way it gates direct execution artifacts, meaning a user without EXECVE rights can still schedule monitoring tasks that run arbitrary commands on endpoints — CVSS 9.9. Organizations using Velociraptor for endpoint telemetry should update immediately and audit any recently scheduled client monitoring artifacts.
7
A SQL injection in cPanel's EmailTrack component can be chained to achieve remote code execution as root by a mail-enabled account — CVSS 9.9, with a proof of concept already circulating and weaponized on the same day of disclosure. Hosting providers and managed service operators running cPanel should treat this as an emergency patch given the zero-day armament timeline.
8
CVE-2026-18351CVSS 9.8affects Drag and Drop File Upload for Elementor Forms Arbitrary file upload in the Drag and Drop File Upload for Elementor Forms WordPress plugin (up to v1.6.0) bypasses MIME type validation by abusing attacker-controlled regex keys, enabling web shell deployment — CVSS 9.8. Any WordPress site using this plugin should update immediately and inspect upload directories for unexpected files.
9
A heap-based buffer overflow in the ASN.1 parsing of VPN certificates on Check Point Quantum Security Management and Gateway allows unauthenticated remote code execution — CVSS 9.8. VPN perimeter devices are high-value targets; patching this before the weekend is strongly advisable to avoid exploitation over low-traffic periods.
10
Improper certificate trust validation during VPN negotiation on Check Point Quantum Security Gateway provides a second, distinct unauthenticated RCE path — CVSS 9.8 — compounding the risk from CVE-2026-85103 on the same product family. Organizations relying on Check Point for network perimeter security face a dual critical exposure and should apply vendor guidance without delay.
Ransomware today
Ransomware activity targeting Brazil has intensified recently, with six victims identified in the latest period spanning Healthcare, Technology, Manufacturing, and Retail sectors. The group thegentlemen is the most prolific actor over the past 30 days with nine confirmed victims in Brazil, including Biotipo Jeans, Zanini, and Mutant; Vexy Ransomware claimed both Logar Network Solutions and Engefitas; lockbit5 hit the healthcare provider amorsaude.com.br; and Dark Project targeted manufacturer Alurwalls. The breadth of sectors and the volume of Brazilian victims signals that threat actors are running broad opportunistic campaigns rather than selective targeting.
amorsaude.com.br BRlockbit5 · Healthcare
Logar Network Solutions BRVexy Ransomware · Technology
Alurwalls BRDark Project · Manufacturing
Biotipo Jeans BRthegentlemen · Retail & E-Commerce
Zanini BRthegentlemen · Manufacturing
Mutant BRthegentlemen · Other
thegentlemen 9direwolf 3krybit 3dragonforce 2emperador 2Vexy Ransomware 2
Active groups & APTs
Several threat groups are being tracked for updated activity, including dragonforce, fulcrumsec, funksec, linkc, spacebears, and the Iranian-attributed blackshadow — none of which have confirmed new victims in the current window but whose infrastructure or tooling has been updated or observed recently. The presence of dragonforce in both the APT tracking list and the 30-day ransomware statistics (two Brazilian victims) suggests operational overlap between criminal and state-aligned actors worth monitoring closely.
Brazil focus
Brazil is one of the most heavily targeted countries in the current ransomware landscape, with at least eight organizations claimed as victims over recent weeks across Transportation (Lider Aviacao), Manufacturing (Zanini, Alurwalls, Engefitas), Healthcare (amorsaude.com.br), Technology (Logar Network Solutions), Retail (Biotipo Jeans), and other sectors. The dominance of thegentlemen — responsible for nine of the last thirty days' Brazilian victims — combined with active groups like Vexy Ransomware, direwolf, krybit, dragonforce, and emperador indicates that Brazilian organizations face sustained multi-group pressure and should prioritize incident response readiness alongside patching.
Logar Network SolutionsVexy Ransomware · Technology
amorsaude.com.brlockbit5 · Healthcare
Zaninithegentlemen · Manufacturing
Biotipo Jeansthegentlemen · Retail & E-Commerce
AlurwallsDark Project · Manufacturing
Mutantthegentlemen · Other
Lider Aviacaothegentlemen · Transportation
EngefitasVexy Ransomware · Manufacturing
Today’s recommendation: Patch or isolate KGUARD DVR devices, Check Point Quantum Security Gateways, and cPanel installations immediately, as these combine critical CVSS scores with confirmed or same-day weaponization. WordPress administrators should audit all installed plugins against today's affected components and restrict file upload functionality until updates are confirmed.
With multiple critical vulnerabilities weaponized the same day they were disclosed and active exploitation detected before official confirmation, the only reliable way to know whether your organization is exposed is to continuously validate your actual attack surface — not just your patch records.Find out in minutes, with a free exposure assessment, where your organization is truly exposed.Meet the Autonomous AI Pentest Agent →Previous briefings
September 8, 2026 — Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 2026 — 22 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026 — Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026 — WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026 — WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026 — Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026 — WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026 — Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026 — WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026 — Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026 — Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 2026 — 10 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026 — Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026 — Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →