Daily briefing · September 18, 2026

WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active Exploitation

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — attention5 seen before CISA

September 18, 2026 carries an ATTENTION-level verdict: five vulnerabilities are confirmed under active exploitation, and five were detected by VulnCheck before CISA issued any official alert — meaning defenders relying solely on federal feeds are already behind. With 505 new CVEs published, 55 rated critical, and high-profile flaws spanning WordPress plugins, IBM enterprise products, and the widely-used vm2 sandbox library, the day demands immediate triage rather than routine monitoring.

Today’s brief
  • 5 CVEs confirmed in active exploitation, 5 flagged by VulnCheck before CISA — early-warning signals are critical today
  • Gravity Forms WordPress plugin (CVE-2026-84434, CVSS 9.8) allows unauthenticated arbitrary file upload — patch or disable immediately
  • Two vm2 sandbox escape flaws (CVE-2026-93606, CVE-2026-93605, both CVSS 10.0) let attackers break out of Node.js sandboxes and execute host commands
  • Brazil is under intense ransomware pressure: 7+ victims claimed in recent days by akira, thegentlemen, settra, and others
55
critical
5
Actively exploited
5
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-84434◆ VulnCheckCVSS 9.8affects Gravity Forms
A critical arbitrary file upload flaw in the Gravity Forms WordPress plugin (all versions through 3.1.0.4) allows unauthenticated attackers to upload malicious files by bypassing extension validation through hidden upload fields — VulnCheck observed exploitation before any CISA alert, making this an immediate web server compromise risk for any site running this plugin.
2
CVE-2023-54399◆ VulnCheckCVSS 9.3PoCaffects e-HR
Hongjing e-HR before version 8.2 exposes an unauthenticated SQL injection endpoint where crafted UNION SELECT payloads can extract credential tables from the database; VulnCheck flagged active exploitation ahead of CISA, and the existence of a public proof of concept makes this a high-urgency patch target for any HR system deployment.
3
CVE-2017-20284◆ VulnCheckHIGH 8.7PoCaffects Resin
Caucho Resin's documentation webapp (resin-doc) contains a path traversal vulnerability allowing unauthenticated remote attackers to read arbitrary files via directory traversal sequences — VulnCheck confirmed exploitation in the wild before official CISA acknowledgment, and the availability of a proof of concept means threat actors can trivially read sensitive configuration or credential files.
4
CVE-2021-48008◆ VulnCheckHIGH 8.7affects CRM
Chanjet CRM's webservice endpoint is vulnerable to unauthenticated SQL injection via the site_id parameter, enabling full database extraction through UNION-based techniques; VulnCheck observed active exploitation before CISA catalogued it, making unpatched Chanjet CRM deployments a critical exposure for organizations holding sensitive customer records.
5
CVE-2019-25776◆ VulnCheckHIGH 8.7PoCaffects E-cology
Weaver E-cology's mobile plugin endpoint contains an unauthenticated SQL injection flaw where parentheses-wrapped keywords bypass space-based filters, allowing attackers to extract administrative credentials via UNION injection — VulnCheck flagged exploitation before CISA, and a proof of concept is publicly available, compounding the urgency for organizations running this platform.
6
CVE-2026-93740CVSS 10PoCaffects A3002MU
A remotely exploitable buffer overflow in the Totolink A3002MU router's formWlEncrypt function (CVSS 10.0) can be triggered without authentication, and the exploit is already publicly available — routers exposed to the internet or on untrusted network segments should be isolated or firmware-updated immediately.
7
CVE-2026-10747CVSS 10affects MQ Appliance
IBM MQ Appliance is affected by a heap buffer overflow in protocol message processing that triggers before authentication completes, meaning unauthenticated remote attackers could cause denial of service or potentially achieve arbitrary code execution on a messaging infrastructure component that is often deeply trusted within enterprise environments.
8
CVE-2025-15399CVSS 10affects Common Licensing
IBM Common Licensing Agent (multiple 9.0.x versions) and ART are vulnerable to cross-site request forgery, allowing attackers to execute unauthorized actions on behalf of authenticated users — in a licensing management context, this can be abused to tamper with license allocations or administrative configurations.
9
CVE-2026-93606CVSS 10affects vm2
vm2 versions 3.12.0 and earlier contain a sandbox escape where the bridge's rejection sanitizer fails to properly handle host-realm Promises, allowing sandbox-side Symbol.species manipulation to break containment — any application using vm2 to isolate untrusted code should treat this as a full host compromise risk and migrate to a patched version or alternative sandbox immediately.
10
CVE-2026-93605CVSS 10affects vm2
vm2 NodeVM (before 3.12.1) omits child_process from its DANGEROUS_BUILTINS denylist, letting attackers with access to the sandbox require child_process and run arbitrary OS commands on the host — the impact is total host compromise and affects any deployment using wildcard builtin configuration.
Ransomware today

Multiple ransomware groups claimed Brazilian victims in recent days, with akira hitting Javep Chevrolet and Vetta (Technology sector), thegentlemen targeting Multipla Contabilidade Empresarial and Humboldt, settra claiming fchhotels.com, Panzer listing K3G Solutions Brazil, and N0n targeting Konnatus legal services. Over the past 30 days, thegentlemen stands out as the most active group against Brazilian organizations with 9 confirmed victims, followed by krybit (3), akira (2), settra (2), and Vexy Ransomware (2). The breadth of targeted sectors — retail, hospitality, professional services, technology — signals that no vertical is being spared.

Javep Chevrolet BRakira · Retail & E-Commerce
Konnatus (usucapião legal services) BRN0n · Professional Services
Vetta BRakira · Technology
K3G Solutions Brazil BRPanzer · Other
fchhotels.com BRsettra · Hospitality
Multipla Contabilidade Empresarial BRthegentlemen · Professional Services
Humboldt BRthegentlemen · Other
thegentlemen 9krybit 3akira 2settra 2emperador 2Vexy Ransomware 2
Active groups & APTs

Several threat actor groups are currently listed as active or recently updated, including Iran-linked mosesstaff, Russia-origin siegedsec, and groups sinobi, spacebears, thegentlemen, and funksec. While no specific new victims are attributed to these actors in the current cycle, their operational activity status warrants monitoring, particularly for organizations in sectors historically targeted by Iranian and Russian state-aligned groups. The presence of thegentlemen on both the APT tracking list and the ransomware victim list suggests this group is in an aggressive operational phase.

Brazil focus

Brazil continues to face a concentrated and multi-group ransomware campaign, with at least eight organizations across diverse sectors claimed as victims in recent activity — including Alicotrans (Transportation) by qilin and Javep Chevrolet (Retail) by akira. The Professional Services and Other sectors appear repeatedly, suggesting that smaller and mid-market firms without mature security controls are being systematically targeted. Brazilian defenders should cross-reference the five VulnCheck-flagged CVEs in today's bulletin with their exposed assets, as exploitation of unpatched web applications and enterprise software is a common ransomware initial access vector.

K3G Solutions BrazilPanzer · Other
Vettaakira · Technology
Konnatus (usucapião legal services)N0n · Professional Services
Javep Chevroletakira · Retail & E-Commerce
fchhotels.comsettra · Hospitality
Humboldtthegentlemen · Other
Multipla Contabilidade Empresarialthegentlemen · Professional Services
Alicotransqilin · Transportation
Today’s recommendation: Prioritize immediate patching or mitigation for CVE-2026-84434 (Gravity Forms), CVE-2026-93605 and CVE-2026-93606 (vm2), and the three SQL injection CVEs flagged by VulnCheck as actively exploited — these represent the highest-probability paths to breach today. Organizations should also audit IBM MQ Appliance and IBM Common Licensing Agent deployments for the two additional CVSS 10.0 flaws and apply vendor patches or compensating network controls without delay.
Given that five of today's highlighted vulnerabilities were confirmed in exploitation before any official alert was issued, now is the moment to validate whether your exposed attack surface — web applications, enterprise middleware, and containerized sandboxes — is visible and tested against current threat intelligence.Knowing the flaw exists is half the job; the other half is knowing if it affects you. Start with a no-cost exposure test.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 20, 2026Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active ExploitationSeptember 16, 2026Cisco Infrastructure Flooded With CVSS 10 Flaws as VulnCheck Spots Active Exploitation Before CISASeptember 15, 2026Oracle Patch Tuesday Surge and Yonyou Active Exploitation Drive ATTENTION-Level AlertSeptember 14, 2026Cisco Secure Email Under Active Exploitation as 58 Critical CVEs SurfaceSeptember 13, 2026WordPress Plugin Flaw Leads Quiet Day With 8 Critical CVEs and No Active ExploitationSeptember 12, 2026WordPress Plugin Blitz: Nine Critical RCE and Takeover Flaws Disclosed on a Quiet Exploit DaySeptember 11, 2026GitLab Critical Zero-Day Under Active Exploitation Leads a Heavy Patch Day with 36 Critical CVEsSeptember 10, 2026Ten Critical CVEs Published on a Calm Threat Day as Brazil Faces Ransomware SurgeSeptember 9, 2026Three CVEs Already Exploited Before CISA Confirmation, Dual Check Point RCE and cPanel SQLi-to-Root Round Out a High-Alert DaySeptember 8, 2026Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 202622 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on Brazilview full archive →
Share