Daily briefing · September 18, 2026
WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active Exploitation
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — attention5 seen before CISA
September 18, 2026 carries an ATTENTION-level verdict: five vulnerabilities are confirmed under active exploitation, and five were detected by VulnCheck before CISA issued any official alert — meaning defenders relying solely on federal feeds are already behind. With 505 new CVEs published, 55 rated critical, and high-profile flaws spanning WordPress plugins, IBM enterprise products, and the widely-used vm2 sandbox library, the day demands immediate triage rather than routine monitoring.
Today’s brief
- 5 CVEs confirmed in active exploitation, 5 flagged by VulnCheck before CISA — early-warning signals are critical today
- Gravity Forms WordPress plugin (CVE-2026-84434, CVSS 9.8) allows unauthenticated arbitrary file upload — patch or disable immediately
- Two vm2 sandbox escape flaws (CVE-2026-93606, CVE-2026-93605, both CVSS 10.0) let attackers break out of Node.js sandboxes and execute host commands
- Brazil is under intense ransomware pressure: 7+ victims claimed in recent days by akira, thegentlemen, settra, and others
Critical highlights
1
A critical arbitrary file upload flaw in the Gravity Forms WordPress plugin (all versions through 3.1.0.4) allows unauthenticated attackers to upload malicious files by bypassing extension validation through hidden upload fields — VulnCheck observed exploitation before any CISA alert, making this an immediate web server compromise risk for any site running this plugin.
2
Hongjing e-HR before version 8.2 exposes an unauthenticated SQL injection endpoint where crafted UNION SELECT payloads can extract credential tables from the database; VulnCheck flagged active exploitation ahead of CISA, and the existence of a public proof of concept makes this a high-urgency patch target for any HR system deployment.
3
Caucho Resin's documentation webapp (resin-doc) contains a path traversal vulnerability allowing unauthenticated remote attackers to read arbitrary files via directory traversal sequences — VulnCheck confirmed exploitation in the wild before official CISA acknowledgment, and the availability of a proof of concept means threat actors can trivially read sensitive configuration or credential files.
4
Chanjet CRM's webservice endpoint is vulnerable to unauthenticated SQL injection via the site_id parameter, enabling full database extraction through UNION-based techniques; VulnCheck observed active exploitation before CISA catalogued it, making unpatched Chanjet CRM deployments a critical exposure for organizations holding sensitive customer records.
5
Weaver E-cology's mobile plugin endpoint contains an unauthenticated SQL injection flaw where parentheses-wrapped keywords bypass space-based filters, allowing attackers to extract administrative credentials via UNION injection — VulnCheck flagged exploitation before CISA, and a proof of concept is publicly available, compounding the urgency for organizations running this platform.
6
A remotely exploitable buffer overflow in the Totolink A3002MU router's formWlEncrypt function (CVSS 10.0) can be triggered without authentication, and the exploit is already publicly available — routers exposed to the internet or on untrusted network segments should be isolated or firmware-updated immediately.
7
IBM MQ Appliance is affected by a heap buffer overflow in protocol message processing that triggers before authentication completes, meaning unauthenticated remote attackers could cause denial of service or potentially achieve arbitrary code execution on a messaging infrastructure component that is often deeply trusted within enterprise environments.
8
IBM Common Licensing Agent (multiple 9.0.x versions) and ART are vulnerable to cross-site request forgery, allowing attackers to execute unauthorized actions on behalf of authenticated users — in a licensing management context, this can be abused to tamper with license allocations or administrative configurations.
9
vm2 versions 3.12.0 and earlier contain a sandbox escape where the bridge's rejection sanitizer fails to properly handle host-realm Promises, allowing sandbox-side Symbol.species manipulation to break containment — any application using vm2 to isolate untrusted code should treat this as a full host compromise risk and migrate to a patched version or alternative sandbox immediately.
10
vm2 NodeVM (before 3.12.1) omits child_process from its DANGEROUS_BUILTINS denylist, letting attackers with access to the sandbox require child_process and run arbitrary OS commands on the host — the impact is total host compromise and affects any deployment using wildcard builtin configuration.
Ransomware today
Multiple ransomware groups claimed Brazilian victims in recent days, with akira hitting Javep Chevrolet and Vetta (Technology sector), thegentlemen targeting Multipla Contabilidade Empresarial and Humboldt, settra claiming fchhotels.com, Panzer listing K3G Solutions Brazil, and N0n targeting Konnatus legal services. Over the past 30 days, thegentlemen stands out as the most active group against Brazilian organizations with 9 confirmed victims, followed by krybit (3), akira (2), settra (2), and Vexy Ransomware (2). The breadth of targeted sectors — retail, hospitality, professional services, technology — signals that no vertical is being spared.
Javep Chevrolet BRakira · Retail & E-Commerce
Konnatus (usucapião legal services) BRN0n · Professional Services
Vetta BRakira · Technology
K3G Solutions Brazil BRPanzer · Other
fchhotels.com BRsettra · Hospitality
Multipla Contabilidade Empresarial BRthegentlemen · Professional Services
Humboldt BRthegentlemen · Other
thegentlemen 9krybit 3akira 2settra 2emperador 2Vexy Ransomware 2
Active groups & APTs
Several threat actor groups are currently listed as active or recently updated, including Iran-linked mosesstaff, Russia-origin siegedsec, and groups sinobi, spacebears, thegentlemen, and funksec. While no specific new victims are attributed to these actors in the current cycle, their operational activity status warrants monitoring, particularly for organizations in sectors historically targeted by Iranian and Russian state-aligned groups. The presence of thegentlemen on both the APT tracking list and the ransomware victim list suggests this group is in an aggressive operational phase.
Brazil focus
Brazil continues to face a concentrated and multi-group ransomware campaign, with at least eight organizations across diverse sectors claimed as victims in recent activity — including Alicotrans (Transportation) by qilin and Javep Chevrolet (Retail) by akira. The Professional Services and Other sectors appear repeatedly, suggesting that smaller and mid-market firms without mature security controls are being systematically targeted. Brazilian defenders should cross-reference the five VulnCheck-flagged CVEs in today's bulletin with their exposed assets, as exploitation of unpatched web applications and enterprise software is a common ransomware initial access vector.
K3G Solutions BrazilPanzer · Other
Vettaakira · Technology
Konnatus (usucapião legal services)N0n · Professional Services
Javep Chevroletakira · Retail & E-Commerce
fchhotels.comsettra · Hospitality
Humboldtthegentlemen · Other
Multipla Contabilidade Empresarialthegentlemen · Professional Services
Alicotransqilin · Transportation
Today’s recommendation: Prioritize immediate patching or mitigation for CVE-2026-84434 (Gravity Forms), CVE-2026-93605 and CVE-2026-93606 (vm2), and the three SQL injection CVEs flagged by VulnCheck as actively exploited — these represent the highest-probability paths to breach today. Organizations should also audit IBM MQ Appliance and IBM Common Licensing Agent deployments for the two additional CVSS 10.0 flaws and apply vendor patches or compensating network controls without delay.
Given that five of today's highlighted vulnerabilities were confirmed in exploitation before any official alert was issued, now is the moment to validate whether your exposed attack surface — web applications, enterprise middleware, and containerized sandboxes — is visible and tested against current threat intelligence.Knowing the flaw exists is half the job; the other half is knowing if it affects you. Start with a no-cost exposure test.Meet the Autonomous AI Pentest Agent →Previous briefings
September 20, 2026 — Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026 — Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026 — WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026 — Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active ExploitationSeptember 16, 2026 — Cisco Infrastructure Flooded With CVSS 10 Flaws as VulnCheck Spots Active Exploitation Before CISASeptember 15, 2026 — Oracle Patch Tuesday Surge and Yonyou Active Exploitation Drive ATTENTION-Level AlertSeptember 14, 2026 — Cisco Secure Email Under Active Exploitation as 58 Critical CVEs SurfaceSeptember 13, 2026 — WordPress Plugin Flaw Leads Quiet Day With 8 Critical CVEs and No Active ExploitationSeptember 12, 2026 — WordPress Plugin Blitz: Nine Critical RCE and Takeover Flaws Disclosed on a Quiet Exploit DaySeptember 11, 2026 — GitLab Critical Zero-Day Under Active Exploitation Leads a Heavy Patch Day with 36 Critical CVEsSeptember 10, 2026 — Ten Critical CVEs Published on a Calm Threat Day as Brazil Faces Ransomware SurgeSeptember 9, 2026 — Three CVEs Already Exploited Before CISA Confirmation, Dual Check Point RCE and cPanel SQLi-to-Root Round Out a High-Alert DaySeptember 8, 2026 — Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 2026 — 22 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on Brazilview full archive →