Daily briefing · September 15, 2026
Oracle Patch Tuesday Surge and Yonyou Active Exploitation Drive ATTENTION-Level Alert
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — attention3 seen before CISA
September 15, 2026 brings a high-volume critical vulnerability day, with 1,390 new CVEs published and 169 rated critical — anchored by a wave of perfect-score CVSS 10.0 Oracle flaws and three vulnerabilities already flagged by VulnCheck as actively exploited before any official CISA confirmation. The Yonyou ERP ecosystem and Issabel PBX are under active scrutiny with proof-of-concept code circulating, while Oracle's Fusion Middleware stack faces unauthenticated remote exploitation risks at maximum severity. Defenders should treat this as an urgent patching window, not a routine update cycle.
Today’s brief
- VulnCheck flags active exploitation of two Yonyou CVEs (U8 CRM and U8 Cloud) and Issabel PBX before CISA acts — patch or isolate immediately
- Six Oracle CVSS 10.0 vulnerabilities published today span WebLogic, Forms, Internet Directory, Access Manager, Hyperion, and Platform Security — all unauthenticated network-exploitable
- AI gateway mcp-context-forge carries a CVSS 10.0 sandbox escape flaw in versions prior to 1.0.2 — critical for AI infrastructure operators
- Brazil remains a primary ransomware target: thegentlemen, qilin, and others hit accounting, transport, healthcare, and manufacturing sectors recently
Critical highlights
1
Unauthenticated SQL injection in Yonyou U8 CRM's configuration endpoint bypasses login via DontCheckLogin=1, enabling arbitrary SQL execution and, on MSSQL deployments with xp_cmdshell enabled, full OS command execution — VulnCheck observed exploitation before CISA, and a proof of concept is circulating, making this an immediate priority for any organization running U8 CRM.
2
A Java deserialization flaw in Yonyou U8 Cloud's FileManageServlet passes raw POST body data directly to ObjectInputStream without validation, allowing remote unauthenticated attackers to execute arbitrary OS commands — flagged by VulnCheck ahead of CISA with a public PoC, this is a high-urgency threat for ERP environments dependent on U8 Cloud.
3
Issabel PBX's web framework hardcodes an identical HS256 JWT signing key across all installations, letting unauthenticated attackers forge valid bearer tokens and invoke the manager originate endpoint with the System application — enabling remote OS command execution; VulnCheck observed exploitation before CISA, making this a critical priority for any PBX operator running unpatched Issabel.
4
Oracle Hyperion Financial Management 11.2.26.0.000 carries a CVSS 10.0 unauthenticated HTTP-exploitable vulnerability with potential for full system compromise and lateral impact across additional Oracle products — financial sector organizations should treat this as an emergency patch given the maximum severity and unauthenticated attack vector.
5
Oracle Forms 12.2.1.19.0 and 14.1.2.0.0 are affected by a CVSS 10.0 unauthenticated vulnerability over HTTP that can compromise the Forms server and cascade to other products in the Fusion Middleware stack — organizations relying on Oracle Forms for business-critical workflows face immediate risk.
6
Oracle Internet Directory versions 12.2.1.4.0 and 14.1.2.1.0 expose a CVSS 10.0 flaw in the OID LDAP Server component exploitable by unauthenticated attackers via LDAP, with the potential to significantly compromise additional Oracle products — directory services are a high-value target for privilege escalation and lateral movement.
7
Oracle WebLogic Server versions 12.2.1.4.0 through 14.1.2.0.0 contain a CVSS 10.0 unauthenticated HTTP vulnerability in the Web Container component, a historically well-targeted attack surface for ransomware and APT groups — organizations must prioritize patching given WebLogic's notorious exploitation history.
8
Oracle Platform Security for Java (OPSS) versions 12.2.1.4.0 and 14.1.2.0.0 carry a CVSS 10.0 unauthenticated HTTP flaw in the Centralized Thirdparty Jars component, with cascading compromise potential across dependent Oracle Fusion Middleware products — a breach here could undermine the security foundation of an entire Oracle middleware deployment.
9
Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0 have a CVSS 10.0 unauthenticated HTTP vulnerability in the Authentication Engine — compromising an identity and access management system at this level can grant attackers broad access across enterprise applications that rely on OAM for authentication.
10
The mcp-context-forge AI gateway exposes raw getattr through safe_builtins and lacks a required _getattr_ guard, allowing attackers to construct sandbox-escaping payloads and achieve arbitrary code execution — this CVSS 10.0 flaw in versions before 1.0.2 is particularly urgent for organizations adopting AI infrastructure built on MCP-based architectures.
Ransomware today
The thegentlemen group is the most active ransomware actor targeting Brazil in the past 30 days, recently claiming Multipla Contabilidade Empresarial (Professional Services), Humboldt, and Biotipo Jeans (Retail) among its victims. Qilin claimed Alicotrans in the transportation sector, while nightspire, lockbit5, Vexy Ransomware, and Dark Project have also struck Brazilian organizations across manufacturing, healthcare, and technology verticals. With nine confirmed Brazilian victims attributed to thegentlemen alone in the past 30 days, the group represents a sustained and targeted threat to the country's business ecosystem.
Multipla Contabilidade Empresarial BRthegentlemen · Professional Services
Humboldt BRthegentlemen · Other
Alicotrans BRqilin · Transportation
thegentlemen 9krybit 3Vexy Ransomware 2dragonforce 2emperador 2kazu 2
Active groups & APTs
Several threat actor groups are currently flagged as active or updated, including mosesstaff (Iran-linked), siegedsec (Russia-linked), sinobi, spacebears, thegentlemen, and funksec — though no specific new victims have been attributed to these actors in the current reporting window. The Iranian-linked mosesstaff and Russian-affiliated siegedsec are geopolitically motivated actors whose activity patterns often target critical infrastructure and government entities, warranting elevated monitoring even when direct victim counts are low. Their continued operational status alongside ransomware crews underscores a multi-front threat landscape.
Brazil focus
Brazil continues to face disproportionately intense ransomware pressure, with recent victims spanning professional services (Multipla Contabilidade Empresarial), transportation (Alicotrans), manufacturing (Tuboaços da Amazônia, Alurwalls), technology (Logar Network Solutions), healthcare (amorsaude.com.br), and retail (Biotipo Jeans) — a breadth of sectors that signals opportunistic, indiscriminate targeting rather than sector-specific campaigns. The dominance of thegentlemen with nine Brazilian victims in 30 days, combined with activity from krybit, Vexy Ransomware, dragonforce, and others, indicates that Brazilian organizations of all sizes and sectors remain high-value targets. Defenders in Brazil should urgently review exposure of internet-facing systems, particularly those running ERP, PBX, and Oracle middleware products highlighted in today's bulletin.
Multipla Contabilidade Empresarialthegentlemen · Professional Services
Humboldtthegentlemen · Other
Alicotransqilin · Transportation
Tuboaços da Amazônia Ltda.nightspire · Manufacturing
Logar Network SolutionsVexy Ransomware · Technology
amorsaude.com.brlockbit5 · Healthcare
AlurwallsDark Project · Manufacturing
Biotipo Jeansthegentlemen · Retail & E-Commerce
Today’s recommendation: Prioritize immediate patching or network isolation for all Yonyou U8 CRM and U8 Cloud deployments and Issabel PBX instances, as VulnCheck has confirmed active exploitation ahead of official CISA listing; simultaneously fast-track Oracle Fusion Middleware patches — especially WebLogic, Access Manager, and Internet Directory — given their CVSS 10.0 ratings and unauthenticated attack vectors. For AI infrastructure teams, upgrade mcp-context-forge to version 1.0.2 or later without delay.
Given the breadth of today's critical vulnerabilities — spanning ERP, middleware, PBX, identity management, and AI gateways — now is the moment to actively validate which of these attack surfaces are exposed in your environment rather than assuming existing controls are sufficient.Find out in minutes, with a free exposure assessment, where your organization is truly exposed.Meet the Autonomous AI Pentest Agent →Previous briefings
September 20, 2026 — Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026 — Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026 — WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026 — Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active ExploitationSeptember 16, 2026 — Cisco Infrastructure Flooded With CVSS 10 Flaws as VulnCheck Spots Active Exploitation Before CISASeptember 15, 2026 — Oracle Patch Tuesday Surge and Yonyou Active Exploitation Drive ATTENTION-Level AlertSeptember 14, 2026 — Cisco Secure Email Under Active Exploitation as 58 Critical CVEs SurfaceSeptember 13, 2026 — WordPress Plugin Flaw Leads Quiet Day With 8 Critical CVEs and No Active ExploitationSeptember 12, 2026 — WordPress Plugin Blitz: Nine Critical RCE and Takeover Flaws Disclosed on a Quiet Exploit DaySeptember 11, 2026 — GitLab Critical Zero-Day Under Active Exploitation Leads a Heavy Patch Day with 36 Critical CVEsSeptember 10, 2026 — Ten Critical CVEs Published on a Calm Threat Day as Brazil Faces Ransomware SurgeSeptember 9, 2026 — Three CVEs Already Exploited Before CISA Confirmation, Dual Check Point RCE and cPanel SQLi-to-Root Round Out a High-Alert DaySeptember 8, 2026 — Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 2026 — 22 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on Brazilview full archive →