Daily briefing · September 20, 2026

Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation Detected

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm

September 20, 2026 registers a calm threat landscape from an active exploitation standpoint, with zero vulnerabilities confirmed in the wild or flagged as weaponized. Despite the absence of in-the-wild attacks, 16 critical CVEs were published in a single day — the majority targeting Netcore NBR200V2 routers — all accompanied by public proof-of-concept code, keeping defensive teams on alert.

Today’s brief
  • No vulnerabilities reached weaponized or KEV status today — the day is assessed as calm.
  • Netcore NBR200V2 routers are hit with at least seven critical CVEs (command injection and buffer overflow), all with public PoCs.
  • D-Link DIR-868L and Comfast CF-N1-S also carry CVSS 10.0 stack-based buffer overflow flaws with disclosed exploits.
  • REDCap research platform has an unauthenticated RCE (CVSS 9.8) affecting survey and data import logic — high-value target in academia and healthcare.
16
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-94097CVSS 10PoCaffects NBR200V2
A CVSS 10.0 command injection in Netcore NBR200V2's CGI Diagnostic Endpoint allows unauthenticated remote attackers to execute arbitrary commands; the public PoC makes opportunistic exploitation straightforward for any internet-exposed device.
2
CVE-2026-94089CVSS 10PoCaffects DIR-868L
A CVSS 10.0 stack-based buffer overflow in D-Link DIR-868L's authentication handler can be triggered remotely by manipulating the id or password fields, potentially granting full device control — a serious risk given the large installed base of this end-of-life router.
3
CVE-2026-94003CVSS 10PoCaffects CF-N1-S
Comfast CF-N1-S's web management interface carries a CVSS 10.0 stack-based buffer overflow in its mbox-config CGI handler; with the exploit already public, any externally reachable management interface should be considered immediately at risk.
4
CVE-2026-90817CVSS 9.8affects REDCap
An unauthenticated RCE (CVSS 9.8) in REDCap's survey passthrough and data import logic lets a malicious actor reach unintended controller routes from a public survey context, making research institutions and healthcare organizations running REDCap a priority patching target.
5
CVE-2026-94101CVSS 9.4PoCaffects NBR200V2
A buffer overflow in the vlan_load_form_uci function of the Netcore NBR200V2 routerd binary (CVSS 9.4) is remotely triggerable and has a public PoC, adding another attack vector to an already heavily affected device.
6
CVE-2026-94100CVSS 9.4PoCaffects NBR200V2
The WAN VLAN reconfiguration component of Netcore NBR200V2 is vulnerable to a remotely exploitable buffer overflow via the vlan_wanX.ports argument (CVSS 9.4), with the exploit publicly available and the vendor already notified.
7
CVE-2026-94099CVSS 9.4PoCaffects NBR200V2
Command injection through the QUERY_STRING parameter in NBR200V2's Backup Restore CGI (CVSS 9.4) enables remote code execution; the public disclosure compounds risk for any organization with this router exposed to untrusted networks.
8
CVE-2026-94098CVSS 9.4PoCaffects NBR200V2
The Firmware Upgrade CGI endpoint of Netcore NBR200V2 suffers from the same QUERY_STRING command injection pattern (CVSS 9.4), meaning attackers can chain this with other flaws or use it independently to gain persistent access.
9
CVE-2026-94096CVSS 9.4PoCaffects NBR200V2
Command injection via the ipv4 argument in NBR200V2's LAN IP Configuration Handler (CVSS 9.4) is remotely exploitable; with multiple PoCs now public for this device family, each additional vector meaningfully lowers the bar for attackers.
10
CVE-2026-94095CVSS 9.4PoCaffects NBR200V2
The Traceroute Diagnostic Feature of Netcore NBR200V2 allows remote command injection through the url argument (CVSS 9.4); organizations using this device should treat all seven disclosed vulnerabilities as a combined critical risk requiring immediate mitigation.
Ransomware today

Ransomware activity targeting Brazil has been notable in recent days, with seven Brazilian organizations identified as victims across multiple groups. Akira claimed two Brazilian targets — Vetta (Technology) and Javep Chevrolet (Retail & E-Commerce) — while thegentlemen remains the most active group over the past 30 days with nine victims, all in Brazil. Other groups active against Brazilian entities include emperador (Cassias MG Government), arcusmedia (AKAZZO), Panzer (K3G Solutions Brazil), N0n (Konnatus), and settra (fchhotels.com), reflecting a sustained, multi-group pressure on the Brazilian market.

AKAZZO BRarcusmedia
Cassias MG Government BRemperador · Government & Defense
K3G Solutions Brazil BRPanzer · Other
Konnatus (usucapião legal services) BRN0n · Professional Services
Vetta BRakira · Technology
Javep Chevrolet BRakira · Retail & E-Commerce
fchhotels.com BRsettra · Hospitality
thegentlemen 9krybit 3emperador 2Vexy Ransomware 2akira 2settra 2
Active groups & APTs

Several threat actor groups are currently tracked as active or recently updated, including handala, linkc, mogilevich, mosesstaff (attributed to Iran), Elderwood (attributed to China), and fulcrumsec. While no confirmed victims are associated with these actors in the current reporting window, the presence of state-linked groups such as mosesstaff and Elderwood in active tracking warrants continued vigilance, particularly for organizations in sectors historically targeted by Iranian and Chinese espionage operations.

Brazil focus

Brazil continues to be heavily targeted by ransomware operators, with at least eight organizations compromised across government, technology, professional services, retail, and hospitality sectors in recent weeks. The Cassias MG Government breach by emperador highlights ongoing risk to public-sector entities, while the breadth of affected industries — from accounting firm Multipla Contabilidade Empresarial (thegentlemen) to hotel operator fchhotels.com (settra) — underscores that no vertical is exempt. The concentration of activity from groups like thegentlemen, akira, and emperador specifically in Brazil signals a deliberate focus on the region.

Cassias MG Governmentemperador · Government & Defense
AKAZZOarcusmedia
Vettaakira · Technology
Konnatus (usucapião legal services)N0n · Professional Services
K3G Solutions BrazilPanzer · Other
Javep Chevroletakira · Retail & E-Commerce
fchhotels.comsettra · Hospitality
Multipla Contabilidade Empresarialthegentlemen · Professional Services
Today’s recommendation: Organizations running Netcore NBR200V2 devices should immediately restrict management interface access to trusted networks and apply any available firmware patches, treating all seven disclosed CVEs as a combined critical risk. REDCap administrators should review access controls on survey and data import endpoints and apply vendor patches without delay.
With multiple critical PoCs now public across router and web application platforms, the most important question for any defender today is whether those assets are reachable from the internet — validating your own external attack surface is the fastest way to know if you are exposed before threat actors find out first.Don’t wait to become a statistic: validate today, at no cost, whether any of these vectors reach your systems.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 20, 2026Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active ExploitationSeptember 16, 2026Cisco Infrastructure Flooded With CVSS 10 Flaws as VulnCheck Spots Active Exploitation Before CISASeptember 15, 2026Oracle Patch Tuesday Surge and Yonyou Active Exploitation Drive ATTENTION-Level AlertSeptember 14, 2026Cisco Secure Email Under Active Exploitation as 58 Critical CVEs SurfaceSeptember 13, 2026WordPress Plugin Flaw Leads Quiet Day With 8 Critical CVEs and No Active ExploitationSeptember 12, 2026WordPress Plugin Blitz: Nine Critical RCE and Takeover Flaws Disclosed on a Quiet Exploit DaySeptember 11, 2026GitLab Critical Zero-Day Under Active Exploitation Leads a Heavy Patch Day with 36 Critical CVEsSeptember 10, 2026Ten Critical CVEs Published on a Calm Threat Day as Brazil Faces Ransomware SurgeSeptember 9, 2026Three CVEs Already Exploited Before CISA Confirmation, Dual Check Point RCE and cPanel SQLi-to-Root Round Out a High-Alert DaySeptember 8, 2026Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 202622 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on Brazilview full archive →
Share