Daily briefing · September 23, 2026
Quiet CVE Day Masks Heavy GitLab, ManageEngine, and Ansible Exposure
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm
September 23, 2026 recorded no actively exploited vulnerabilities and no weaponized exploits confirmed in the wild, placing the day firmly in calm territory despite 467 new CVEs and 43 critical ones published. What stands out is the concentration of CVSS 10.0 and 9.9 flaws across widely deployed platforms — GitLab, ManageEngine, Ansible Automation Platform, and OpenC3 COSMOS — demanding patch prioritization even without confirmed in-the-wild abuse. The absence of active exploitation signals an opportunity for defenders to act before attackers do.
Today’s brief
- Two CVSS 10.0 GitLab RCE flaws (CVE-2026-89078, CVE-2026-93577) with proof-of-concept code target CI/CD pipelines — patch immediately.
- ManageEngine Applications Manager exposed a Google Cloud service-account private key in its installer, enabling full cloud account takeover (CVE-2026-86708).
- Three critical Ansible Automation Platform flaws allow privilege escalation and argument injection — Red Hat environments need urgent review.
- No KEV entries today, but ransomware groups are actively hitting Brazilian targets across government, healthcare, and manufacturing sectors.
Critical highlights
1
A stack-based buffer overflow in the Fast FAC1203R Gigabit Edition 2.0.4 Device Discovery Service is remotely exploitable with a published proof of concept and CVSS 10.0 — the vendor has not responded, leaving users without an official patch and fully exposed.
2
SunEditor's sanitizer fails to strip event-handler attributes from namespaced or custom HTML elements, enabling stored XSS with code execution potential when attacker-controlled content is rendered — any application embedding SunEditor before 2.47.11 is at risk.
3
ManageEngine Applications Manager versions 182200 and below embedded a Google Cloud service-account private key in the installer itself, meaning any unauthenticated attacker who obtained the installer could impersonate the account and access or modify cloud resources at will.
4
An authenticated GitLab user can trigger a double-free memory corruption via a crafted regex in a CI/CD configuration, achieving arbitrary code execution on the GitLab server — a proof of concept exists and all CE/EE versions from 19.2 to 19.4.0 are affected.
5
A companion GitLab flaw exploits integer overflow during regex compilation in CI/CD configs, also enabling authenticated arbitrary code execution across the same version range as CVE-2026-89078 — organizations should treat both as a pair and patch to 19.2.7, 19.3.3, or 19.4.1.
6
CVE-2026-84719CVSS 9.9affects Red Hat Ansible Automation Platform 2.4 for RHEL 8 Ansible Automation Platform's WorkflowJobTemplate copy operation fails to sanitize instance_groups, execution environments, and labels, allowing a workflow-admin to escalate access beyond their organization boundary in multi-tenant deployments.
7
Authenticated non-administrator users of OpenC3 COSMOS (versions 5.1.0 through 7.3.0) can write content to targets_modified/ that is subsequently executed by configuration processors, effectively achieving code execution above their intended privilege tier.
8
CVE-2026-84502CVSS 9.9affects Red Hat Ansible Automation Platform 2.4 for RHEL 8 Ansible Automation Platform's automation-controller fails to validate the Project scm_url field against values beginning with a dash, allowing a crafted URL like --upload-pack=<command> to be interpreted as a git argument and execute arbitrary commands on the controller.
9
CVE-2026-84474CVSS 9.9affects Red Hat Ansible Automation Platform 2.4 for RHEL 8 The provisioning-callback secret (host_config_key) in Ansible Automation Platform is exposed to read-only users through the job template API and activity stream, and the callback endpoint trusts a client-supplied X-Forwarded-For header, allowing host spoofing and unauthorized callback triggering.
10
ManageEngine OpManager MSP versions 12.8.709 and below contain a remote code execution vulnerability in the Notification Profile module — unauthenticated or low-privilege attackers reaching this module could fully compromise the monitoring server.
Ransomware today
Ransomware activity targeting Brazil remains intense in recent days, with four newly identified victims spanning critical sectors: RECEITA FEDERAL DO BRASIL (government) claimed by emperador, amorsaude.com.br (healthcare) by lockbit5, Metallco (manufacturing) by play, and Javep Chevrolet (retail) by akira. Over the past 30 days, thegentlemen leads in volume with eight Brazilian victims, followed by emperador and akira with three each, indicating a sustained and coordinated focus on Brazilian organizations across all verticals.
RECEITA FEDERAL DO BRASIL BRemperador · Government & Defense
amorsaude.com.br BRlockbit5 · Healthcare
Metallco BRplay · Manufacturing
Javep Chevrolet BRakira · Retail & E-Commerce
thegentlemen 8emperador 3akira 3krybit 3Vexy Ransomware 2settra 2
Active groups & APTs
Several threat actor groups are flagged as active or recently updated, including handala, linkc, mogilevich, Iran-linked mosesstaff, China-linked Elderwood, and fulcrumsec, though no specific victims have been attributed to them in this period. The presence of state-linked groups such as mosesstaff and Elderwood alongside financially motivated actors signals a broad threat landscape that extends beyond ransomware into espionage and destructive operations.
Brazil focus
Brazil continues to be one of the most heavily targeted countries in the current threat landscape, with recent victims including RECEITA FEDERAL DO BRASIL, amorsaude.com.br, Metallco, Javep Chevrolet, Cassias MG Government, AKAZZO, Konnatus, and K3G Solutions Brazil — spread across government, healthcare, manufacturing, retail, legal services, and technology sectors. The diversity of targeted industries and the number of distinct ransomware groups involved (emperor, lockbit5, play, akira, arcusmedia, N0n, Panzer) underscore that no sector in Brazil should consider itself low-priority.
amorsaude.com.brlockbit5 · Healthcare
RECEITA FEDERAL DO BRASILemperador · Government & Defense
Metallcoplay · Manufacturing
Javep Chevroletakira · Retail & E-Commerce
Cassias MG Governmentemperador · Government & Defense
AKAZZOarcusmedia
Konnatus (usucapião legal services)N0n · Professional Services
K3G Solutions BrazilPanzer · Other
Today’s recommendation: Security teams should prioritize patching GitLab CE/EE to versions 19.2.7, 19.3.3, or 19.4.1 immediately given the dual RCE proof-of-concept flaws, while simultaneously auditing ManageEngine Applications Manager and OpManager deployments and rotating any Google Cloud service account credentials that may have been distributed with affected installers.
Even on a day without confirmed exploits in the wild, the concentration of critical flaws across CI/CD, cloud management, and automation platforms makes it essential to validate which of these systems are reachable from your environment before attackers run their own assessment.Every CVE above is a possible door — find out which ones are open in your environment with a free attack-surface check.Meet the Autonomous AI Pentest Agent →Previous briefings
September 30, 2026 — Cisco SD-WAN Zero-Day and Six Active Exploits Demand Immediate AttentionSeptember 29, 2026 — Two VulnCheck-Flagged SQL Injections, Six Chrome RCEs, and a Wave of Critical Unauthenticated Flaws Demand Immediate AttentionSeptember 28, 2026 — Apple Zero-Day and Netcore Router Cluster Top a High-Alert DaySeptember 27, 2026 — Citrix NetScaler Under Active Attack: Two Critical RCEs Hit KEV on Same DaySeptember 26, 2026 — WordPress and Joomla Plugins Dominate a Calm but Patch-Heavy Day With 18 Critical CVEsSeptember 25, 2026 — 742 New CVEs on a Calm Day, But Critical Flaws in Zimbra, MediaWiki and WordPress Demand AttentionSeptember 24, 2026 — Quiet CVE Day Masks Serious Risks: CVSS 10.0 Flaws and Heavy Ransomware Activity in BrazilSeptember 23, 2026 — Quiet CVE Day Masks Heavy GitLab, ManageEngine, and Ansible ExposureSeptember 22, 2026 — Triple KEV Alert: Check Point, VeloCloud, and F5 BIG-IP Under Active Exploitation as Adobe Campaign Classic Hit by Four Critical RCE FlawsSeptember 21, 2026 — Calm CVE Day Masked by Brazil Ransomware Surge and Critical Authentication BypassesSeptember 20, 2026 — Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026 — Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026 — WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026 — Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active Exploitationview full archive →