Daily briefing · September 19, 2026

Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and Suricata

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm

September 19, 2026 registers as a calm day by the numbers — zero actively exploited CVEs, no weaponized code confirmed in circulation — but the 10 highlighted vulnerabilities carry substantial real-world risk, with multiple CVSS 9.4–10.0 flaws already accompanied by public proof-of-concept exploits. Defenders should not mistake a quiet threat-intelligence day for a safe one: critical flaws in Totolink routers, WordPress plugins, Perl's DBI library, and the Suricata IDS all demand prompt attention. Meanwhile, ransomware activity targeting Brazilian organizations continues at an elevated pace, dominated by groups such as akira, thegentlemen, and emperador.

Today’s brief
  • Two Totolink A3002MU flaws (CVSS 10.0 and 9.4) with public PoC exploits enable remote buffer overflow and command injection — patch or isolate immediately.
  • Botiga Pro WordPress plugin (CVSS 9.8) exposes unauthenticated REST routes, allowing full site takeover and stored XSS — update before 1.6.5.
  • Two Suricata critical flaws (CVSS 9.4) — a use-after-free and a type confusion — can crash or destabilize IDS/IPS infrastructure running versions before 8.0.7.
  • Brazil faces a surge of ransomware claims: at least seven Brazilian victims identified recently, spanning government, technology, retail, and hospitality sectors.
8
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-93741CVSS 10PoCaffects A3002MU
A CVSS 10.0 buffer overflow in the Totolink A3002MU's formWlWds handler is remotely exploitable and already has a public proof-of-concept, making it an urgent patching priority for any network exposing this device to the internet.
2
CVE-2026-86591CVSS 9.8PoCaffects Botiga Pro
The Botiga Pro WordPress plugin before 1.6.5 exposes an unauthenticated REST route that allows arbitrary WordPress option updates — enabling privilege escalation, full site takeover, and persistent stored XSS — with no authentication required whatsoever.
3
CVE-2026-78030CVSS 9.8affects DBI
Perl's DBI library before 1.653 allows arbitrary module loading through unvalidated dbm_type and dbm_mldbm attributes in DBD::DBM, meaning a crafted connection string can cause Perl to execute attacker-controlled code on the server.
4
CVE-2026-93742CVSS 9.4PoCaffects A3002MU
A second Totolink A3002MU vulnerability (CVSS 9.4) enables remote OS command injection via the formWsc handler's localPin argument, with a public exploit already available — attackers can gain shell-level control of affected routers.
5
CVE-2026-94084CVSS 9.4affects Suricata
A use-after-free in Suricata before 8.0.7 is triggered when HTTP/2 response headers are inspected by rules using the http.response_header keyword with and without transforms, potentially crashing the detection engine and creating a blind spot for defenders.
6
CVE-2026-94083CVSS 9.4affects Suricata
A type confusion bug in Suricata's DoH2 handling before 8.0.7 can cause an invalid memory free when an HTTP1-to-HTTP2 upgrade occurs in a DoH2 session — the flaw is enabled by default in 8.x and could be used to crash or destabilize IDS deployments.
7
CVE-2026-93958CVSS 9.4PoCaffects R95
The D-Link R95 router is vulnerable to remote OS command injection through the NTPServer argument in the DHMAPI component, with a public exploit released — any internet-facing unit running BE9500_1.00.16 should be treated as compromised until patched or isolated.
8
CVE-2026-93985CVSS 9.4affects openpanel
OpenPanel's JavaScript webhook template validator fails to block computed member access to constructor chains, allowing any user with project write access to escape the sandbox and execute arbitrary code in the worker process — a significant supply-chain-style risk in multi-tenant environments.
9
CVE-2026-4327HIGH 8.8affects The Welcomizer
The Welcomizer WordPress plugin through 2.8.1 combines a missing authorization check with an eval() call on user-supplied code, enabling any authenticated user to achieve Remote Code Execution on the hosting server — sites running this plugin should disable or remove it immediately.
10
CVE-2026-85680HIGH 8.8PoCaffects Ultimate Member
The Ultimate Member WordPress plugin before 2.13.1 allows unauthenticated users to store JavaScript in profile names that bypasses sanitization via HTML entity decoding, executing in the context of any visitor — including administrators — who views the profile.
Ransomware today

Several ransomware groups have claimed Brazilian victims in recent days, with akira hitting both Vetta (Technology) and Javep Chevrolet (Retail), while emperor claimed the Cassias MG Government and thegentlemen targeted Multipla Contabilidade Empresarial. Other groups active against Brazilian targets include arcusmedia (AKAZZO), Panzer (K3G Solutions Brazil), N0n (Konnatus), and settra (fchhotels.com). Over the past 30 days, thegentlemen leads in Brazil-focused activity with 9 claimed victims, underscoring a sustained and deliberate targeting of Brazilian organizations across multiple sectors.

AKAZZO BRarcusmedia
Cassias MG Government BRemperador · Government & Defense
K3G Solutions Brazil BRPanzer · Other
Konnatus (usucapião legal services) BRN0n · Professional Services
Vetta BRakira · Technology
Javep Chevrolet BRakira · Retail & E-Commerce
fchhotels.com BRsettra · Hospitality
thegentlemen 9krybit 3emperador 2Vexy Ransomware 2akira 2settra 2
Active groups & APTs

Several threat actor groups are currently tracked as active or updated in threat-intelligence feeds: mosesstaff (Iran-linked), siegedsec (Russia-linked), sinobi, spacebears, thegentlemen, and funksec. While no specific new victims are attributed to these actors in today's data window, their continued operational status signals ongoing reconnaissance and targeting campaigns that defenders should monitor closely.

Brazil focus

Brazil is clearly a high-priority target for ransomware operators right now, with at least eight Brazilian organizations claimed as victims in recent days spanning government (Cassias MG Government), professional services (Konnatus, Multipla Contabilidade Empresarial), technology (Vetta), retail (Javep Chevrolet), hospitality (fchhotels.com), and other sectors. The breadth of targeted industries — from municipal government to legal services to hotel chains — indicates opportunistic mass targeting rather than sector-specific campaigns, meaning no vertical is low-risk. Organizations in Brazil should treat ransomware exposure as an active and immediate threat.

Cassias MG Governmentemperador · Government & Defense
AKAZZOarcusmedia
Vettaakira · Technology
Konnatus (usucapião legal services)N0n · Professional Services
K3G Solutions BrazilPanzer · Other
Javep Chevroletakira · Retail & E-Commerce
fchhotels.comsettra · Hospitality
Multipla Contabilidade Empresarialthegentlemen · Professional Services
Today’s recommendation: Prioritize patching the two Totolink A3002MU CVEs and the Botiga Pro and Welcomizer WordPress plugin flaws, all of which carry public proof-of-concept exploits and require no authentication to trigger; simultaneously upgrade Suricata to 8.0.7 or later to prevent detection-engine disruption that could blind your network monitoring during an active incident.
With critical flaws spanning routers, IDS engines, and popular CMS plugins — many already carrying public exploits — now is the right moment to validate your own attack surface and confirm which of these assets are actually reachable and unpatched in your environment.New vulnerabilities surface every day — does your defense keep up? Get a free initial review of your attack surface.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 20, 2026Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active ExploitationSeptember 16, 2026Cisco Infrastructure Flooded With CVSS 10 Flaws as VulnCheck Spots Active Exploitation Before CISASeptember 15, 2026Oracle Patch Tuesday Surge and Yonyou Active Exploitation Drive ATTENTION-Level AlertSeptember 14, 2026Cisco Secure Email Under Active Exploitation as 58 Critical CVEs SurfaceSeptember 13, 2026WordPress Plugin Flaw Leads Quiet Day With 8 Critical CVEs and No Active ExploitationSeptember 12, 2026WordPress Plugin Blitz: Nine Critical RCE and Takeover Flaws Disclosed on a Quiet Exploit DaySeptember 11, 2026GitLab Critical Zero-Day Under Active Exploitation Leads a Heavy Patch Day with 36 Critical CVEsSeptember 10, 2026Ten Critical CVEs Published on a Calm Threat Day as Brazil Faces Ransomware SurgeSeptember 9, 2026Three CVEs Already Exploited Before CISA Confirmation, Dual Check Point RCE and cPanel SQLi-to-Root Round Out a High-Alert DaySeptember 8, 2026Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 202622 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on Brazilview full archive →
Share