Daily briefing · September 13, 2026
WordPress Plugin Flaw Leads Quiet Day With 8 Critical CVEs and No Active Exploitation
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm
September 13, 2026 was a calm day from a threat intelligence standpoint, with 176 new CVEs published, eight rated critical, and none confirmed under active exploitation or flagged by KEV. The most severe entry is a CVSS 10.0 authentication-bypass flaw in a WordPress payment plugin that exposes wallet credentials and allows arbitrary file deletion. While no exploits have been weaponized, proof-of-concept code is publicly available for several of these critical issues, shortening the window between disclosure and potential abuse.
Today’s brief
- CVSS 10.0 WordPress plugin flaw (CVE-2026-81648) allows unauthenticated attackers to delete files and steal crypto wallet credentials — PoC is public
- Four Totolink A3002MU buffer overflow flaws (CVSS 9.4) disclosed simultaneously with public exploits — router owners should prioritize patching or isolation
- Strapi stored XSS (CVE-2026-90561) enables account takeover of Editor and Super Admin sessions — affects versions 4.x and 5.x
- No CVEs reached weaponized status today, but PoC availability across multiple critical flaws demands prompt patch validation
Critical highlights
1
A CVSS 10.0 authorization bypass in the CryptoPayment Gateway WordPress plugin (versions 1.2.1–1.2.2) allows unauthenticated users to call privileged AJAX endpoints, enabling arbitrary file deletion, payment gateway reconfiguration, and cleartext recovery of stored wallet credentials — a proof of concept is already public, making rapid patching essential for any site processing crypto payments.
2
A remotely exploitable stack buffer overflow in the formPortFw handler of the Totolink A3002MU boa web server allows an unauthenticated remote attacker to execute arbitrary code on affected routers; the exploit has been publicly disclosed, meaning consumer and SOHO routers running this firmware are immediately at risk.
3
A second buffer overflow in the same Totolink A3002MU firmware affects the formNewSchedule handler via the submit-url argument; exploitation is remote and unauthenticated, and with a public exploit already available, this device should be treated as compromised until updated or isolated from untrusted networks.
4
The formIpv6Setup handler in Totolink A3002MU is vulnerable to a remotely triggerable buffer overflow through manipulation of the static_ipv6 parameter; the public exploit for this third consecutive flaw in the same firmware cluster reinforces the need to treat this device family as high-priority for replacement or network segmentation.
5
A fourth buffer overflow in the Totolink A3002MU targets the formFilter component via the ip6addr argument, also remotely exploitable without authentication and with a public exploit — the concentration of four critical BoF flaws in one firmware version suggests broad attack surface exposure across all affected routers.
6
A stored XSS vulnerability in Strapi's content manager WYSIWYG preview (versions 4.x through 4.26.2 and 5.x before 5.48.1) lets an Author-role user inject malicious script tags that execute in Editor or Super Admin sessions when the preview pane is opened, enabling full account takeover without any interaction beyond browsing content.
7
A local privilege escalation flaw in the idmwfp.sys kernel driver of Internet Download Manager (up to 6.42 Build 63) stems from improper access controls; a public PoC exists and the vendor has not responded to disclosure, leaving Windows users exposed to local privilege escalation with no official patch available.
8
LangBot before 4.10.11 uses only 24 bits of entropy for password recovery tokens and enforces no rate limiting on the unauthenticated reset endpoint — an attacker knowing the admin email can brute-force the token space through concurrent requests and seize full administrative control of the chatbot platform.
9
An authenticated user with a valid backend account in the TYPO3 Direct Mail extension (through 9.5.1) can inject arbitrary TSConfig, leading to configuration injection on TYPO3 10.4+ and remote code execution on TYPO3 9.5 and below — the risk is lower due to authentication requirements but elevated in shared or multi-tenant CMS environments.
10
A buffer overflow in the Bonjour Gateway component of Extreme Networks IQ Engine (before 10.6r1a and specific 10.6r4 builds) via the ah_event_send function poses a network-level risk in enterprise wireless environments; upgrading to 10.6r5 or applying vendor guidance should be treated as a standard patch cycle priority.
Ransomware today
The nightspire group recently claimed Tuboaços da Amazônia Ltda., a Brazilian manufacturing firm, as its latest victim. Over the past 30 days, thegentlemen has been the most prolific group targeting Brazil with nine claimed victims, followed by krybit, direwolf, dragonforce, emperador, and the emerging Vexy Ransomware, all of which have concentrated a significant share of their activity specifically on Brazilian organizations.
Tuboaços da Amazônia Ltda. BRnightspire · Manufacturing
thegentlemen 9krybit 3direwolf 2dragonforce 2emperador 2Vexy Ransomware 2
Active groups & APTs
Several threat actor groups are currently flagged as active or updated, including the Iranian-linked mosesstaff, the Russia-attributed siegedsec, and the less-attributed sinobi, spacebears, thegentlemen, and funksec. While no specific new victims are associated with these groups in this reporting window, their continued operational status warrants monitoring, particularly for sectors already targeted in Brazil and the broader Latin American region.
Brazil focus
Brazil continues to face concentrated ransomware pressure across multiple sectors, with recent victims including Tuboaços da Amazônia Ltda. (Manufacturing, nightspire), Logar Network Solutions (Technology, Vexy Ransomware), amorsaude.com.br (Healthcare, lockbit5), Zanini and Biotipo Jeans (Manufacturing and Retail, thegentlemen), Mutant (thegentlemen), Alurwalls (Manufacturing, Dark Project), and Lider Aviacao (Transportation, thegentlemen). The breadth of targeted industries — from healthcare to aviation — underscores that no Brazilian sector should consider itself outside the threat perimeter.
Tuboaços da Amazônia Ltda.nightspire · Manufacturing
Logar Network SolutionsVexy Ransomware · Technology
amorsaude.com.brlockbit5 · Healthcare
Zaninithegentlemen · Manufacturing
Biotipo Jeansthegentlemen · Retail & E-Commerce
Mutantthegentlemen · Other
AlurwallsDark Project · Manufacturing
Lider Aviacaothegentlemen · Transportation
Today’s recommendation: Organizations running the CryptoPayment Gateway WordPress plugin should update immediately or disable it, as the CVSS 10.0 PoC is public; Totolink A3002MU router owners should apply firmware updates or isolate devices from external access given four simultaneous public-exploit buffer overflows. Strapi administrators should upgrade to 5.48.1 or a patched 4.x release to eliminate the stored XSS account-takeover risk.
Given the concentration of publicly available proof-of-concept code across today's critical disclosures, security teams should validate whether any of these affected components exist in their environment before assuming they are not exposed.New vulnerabilities surface every day — does your defense keep up? Get a free initial review of your attack surface.Meet the Autonomous AI Pentest Agent →Previous briefings
September 20, 2026 — Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026 — Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026 — WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026 — Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active ExploitationSeptember 16, 2026 — Cisco Infrastructure Flooded With CVSS 10 Flaws as VulnCheck Spots Active Exploitation Before CISASeptember 15, 2026 — Oracle Patch Tuesday Surge and Yonyou Active Exploitation Drive ATTENTION-Level AlertSeptember 14, 2026 — Cisco Secure Email Under Active Exploitation as 58 Critical CVEs SurfaceSeptember 13, 2026 — WordPress Plugin Flaw Leads Quiet Day With 8 Critical CVEs and No Active ExploitationSeptember 12, 2026 — WordPress Plugin Blitz: Nine Critical RCE and Takeover Flaws Disclosed on a Quiet Exploit DaySeptember 11, 2026 — GitLab Critical Zero-Day Under Active Exploitation Leads a Heavy Patch Day with 36 Critical CVEsSeptember 10, 2026 — Ten Critical CVEs Published on a Calm Threat Day as Brazil Faces Ransomware SurgeSeptember 9, 2026 — Three CVEs Already Exploited Before CISA Confirmation, Dual Check Point RCE and cPanel SQLi-to-Root Round Out a High-Alert DaySeptember 8, 2026 — Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 2026 — 22 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on Brazilview full archive →