Daily briefing · September 25, 2026

742 New CVEs on a Calm Day, But Critical Flaws in Zimbra, MediaWiki and WordPress Demand Attention

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm

September 25, 2026 registered no actively exploited vulnerabilities and no weaponized exploits, placing the day squarely in calm territory. Despite the subdued threat posture, 22 critical-severity CVEs were published, touching high-value targets including Zimbra Collaboration Suite, Apache Qpid Broker-J, and the Linux kernel. Defenders should treat the absence of active exploitation as an opportunity to patch proactively, not as a reason to deprioritize.

Today’s brief
  • No KEV entries or weaponized exploits today — but 22 critical CVEs published, several affecting enterprise-grade platforms
  • Zimbra Collaboration Suite carries two critical flaws: unauthenticated RCE via path traversal and a stored XSS enabling mailbox takeover
  • WordPress plugin CVE-2026-14281 was armed the same day it was disclosed, making privilege escalation trivially reachable for unauthenticated attackers
  • Brazilian organizations remain heavily targeted by ransomware groups, with hits on agriculture, healthcare, manufacturing, and federal government
22
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-100382CVSS 10affects Mediawiki - ExternalData Extension
A CVSS 10.0 OS command injection in MediaWiki's ExternalData Extension (versions before 3.7) allows remote attackers to execute arbitrary operating system commands through the extension's data-fetching functionality — any wiki instance using this extension should be treated as fully compromised until patched.
2
CVE-2026-14281CVSS 9.8PoCsame dayaffects Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code
A privilege escalation flaw in the WooCommerce Notifications and OTP plugin (up to version 4.8.6) exposes a publicly accessible REST endpoint with no permission enforcement, letting unauthenticated users elevate to administrator; a proof of concept was available on the day of disclosure, making this an immediate remediation priority for WordPress-based e-commerce sites.
3
CVE-2026-92609CVSS 9.8affects Apache Qpid Broker-J
A session fixation vulnerability in Apache Qpid Broker-J's HTTP management interface (through version 10.1.0) enables remote attackers to hijack authenticated management sessions by reusing a session identifier retained across logins — upgrade to 10.1.1 is the only mitigation, as network restriction alone does not eliminate the risk if the management interface is reachable.
4
CVE-2026-92161CVSS 9.8affects oauth
The FriendsOfFlarum OAuth extension for Flarum fails to verify the Discord email verified field before trusting it as a confirmed address, allowing an unauthenticated attacker who knows a victim's email to log into their Flarum account via Discord OAuth — sites with Discord sign-in enabled must upgrade to 1.7.4 or 2.0.0-beta.4 immediately.
5
CVE-2026-93643CVSS 9.8affects Zimbra Collaboration Suite (ZCS)
An unauthenticated attacker with access to a public Briefcase document in Zimbra Collaboration Suite can abuse unsigned save fields in the OnlyOffice integration to perform path-traversal writes and execute arbitrary commands as the zimbra system user — this is a pre-auth RCE in a widely deployed enterprise mail platform and should be treated as urgent.
6
CVE-2026-100075CVSS 9.8affects Linux
A memory-safety bug in the Linux kernel's RDMA/srpt subsystem leaves stale counter values and a dangling pointer after a failed multi-buffer allocation unwind, which can lead to use-after-free conditions and potential privilege escalation on systems using RDMA storage target functionality.
7
CVE-2026-48482CVSS 9.4affects glpi
In GLPI versions 11.0.0 through 11.0.7, a form administrator can import a crafted asset with a path-traversal identifier, writing a malicious script to an executable server location and enabling remote code execution — the fix is version 11.0.8, and the attack requires only form-admin privileges, a low bar in many ITSM deployments.
8
CVE-2026-97064CVSS 9.3PoCaffects X-SpringBoot
X-SpringBoot through version 6.0 ships with a hardcoded master login code (172839) seeded into the database by default, allowing any unauthenticated attacker who knows a valid email or phone number to authenticate as that user — a proof of concept exists, and any exposed instance should be considered fully bypassed until the credential is removed and the software is updated.
9
CVE-2026-97063CVSS 9.3PoCaffects X-SpringBoot
A companion flaw in X-SpringBoot through 6.0 causes login verification codes to be returned directly in unauthenticated HTTP responses, effectively handing attackers a one-time password they can immediately use to hijack any account with a known email or mobile number — the combination of CVE-2026-97064 and this flaw makes the platform trivially ownable from the internet.
10
CVE-2026-93647CVSS 9.3affects Zimbra Collaboration Suite (ZCS)
A stored XSS vulnerability in Zimbra Collaboration Suite Classic allows an unauthenticated calendar attacker to embed active markup in the RFC From address of a COUNTER message; when the victim selects the message, arbitrary scripts execute in their mailbox context, enabling data exfiltration and full account takeover without any authenticated access required.
Ransomware today

Several Brazilian organizations have been claimed as victims by ransomware groups in recent days, spanning critical sectors: anery.com.br (agriculture) and amorsaude.com.br (healthcare) were claimed by lockbit5, Grupo Caberj (manufacturing) by incransom, and — most notably — RECEITA FEDERAL DO BRASIL, the Brazilian federal tax authority, was claimed by the emperador group, representing a significant government target. Among the most active groups over the past 30 days, thegentlemen leads with 8 victims, all in Brazil, followed by akira, krybit, emperador, lockbit5, and Vexy Ransomware, each with focused activity inside the country.

anery.com.br BRlockbit5 · Agriculture and Food Production
Grupo Caberj BRincransom · Manufacturing
RECEITA FEDERAL DO BRASIL BRemperador · Government & Defense
amorsaude.com.br BRlockbit5 · Healthcare
thegentlemen 8akira 3krybit 3emperador 3lockbit5 3Vexy Ransomware 2
Active groups & APTs

Several threat actor groups are being monitored for current activity, including handala, linkc, mogilevich, and the Iran-linked mosesstaff, as well as the China-attributed Elderwood group and fulcrumsec — none have newly attributed victims at this time, but their continued operational presence signals sustained reconnaissance and targeting postures that defenders in targeted sectors should account for.

Brazil focus

Brazil continues to face disproportionate ransomware pressure, with recent victims spanning government (RECEITA FEDERAL DO BRASIL, Cassias MG Government), healthcare (amorsaude.com.br), manufacturing (Grupo Caberj, Metallco), retail (Javep Chevrolet), and agriculture (anery.com.br) — the breadth of sectors and the involvement of multiple active groups including lockbit5, akira, emperador, play, and arcusmedia underscore that no vertical is being spared.

anery.com.brlockbit5 · Agriculture and Food Production
Grupo Caberjincransom · Manufacturing
amorsaude.com.brlockbit5 · Healthcare
RECEITA FEDERAL DO BRASILemperador · Government & Defense
Metallcoplay · Manufacturing
Javep Chevroletakira · Retail & E-Commerce
Cassias MG Governmentemperador · Government & Defense
AKAZZOarcusmedia
Today’s recommendation: Prioritize patching Zimbra Collaboration Suite (both CVE-2026-93643 and CVE-2026-93647), the WooCommerce OTP plugin (CVE-2026-14281), and Apache Qpid Broker-J (CVE-2026-92609) before the week ends, as these combine high CVSS scores with unauthenticated attack paths in internet-facing services. For X-SpringBoot deployments, take instances offline or block public access immediately until the hardcoded credential and code-leakage issues are resolved.
Even on a calm day, the sheer volume of critical CVEs across enterprise collaboration, kernel, and web platforms is a reminder that validating your own exposure surface — not just tracking advisories — is the only reliable way to know whether today's quiet really applies to you.New vulnerabilities surface every day — does your defense keep up? Get a free initial review of your attack surface.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 30, 2026 — Cisco SD-WAN Zero-Day and Six Active Exploits Demand Immediate AttentionSeptember 29, 2026 — Two VulnCheck-Flagged SQL Injections, Six Chrome RCEs, and a Wave of Critical Unauthenticated Flaws Demand Immediate AttentionSeptember 28, 2026 — Apple Zero-Day and Netcore Router Cluster Top a High-Alert DaySeptember 27, 2026 — Citrix NetScaler Under Active Attack: Two Critical RCEs Hit KEV on Same DaySeptember 26, 2026 — WordPress and Joomla Plugins Dominate a Calm but Patch-Heavy Day With 18 Critical CVEsSeptember 25, 2026 — 742 New CVEs on a Calm Day, But Critical Flaws in Zimbra, MediaWiki and WordPress Demand AttentionSeptember 24, 2026 — Quiet CVE Day Masks Serious Risks: CVSS 10.0 Flaws and Heavy Ransomware Activity in BrazilSeptember 23, 2026 — Quiet CVE Day Masks Heavy GitLab, ManageEngine, and Ansible ExposureSeptember 22, 2026 — Triple KEV Alert: Check Point, VeloCloud, and F5 BIG-IP Under Active Exploitation as Adobe Campaign Classic Hit by Four Critical RCE FlawsSeptember 21, 2026 — Calm CVE Day Masked by Brazil Ransomware Surge and Critical Authentication BypassesSeptember 20, 2026 — Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026 — Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026 — WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026 — Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active Exploitationview full archive →
Share