Daily briefing · September 26, 2026
WordPress and Joomla Plugins Dominate a Calm but Patch-Heavy Day With 18 Critical CVEs
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — calm
September 26, 2026 brings a calm threat landscape in terms of active exploitation, with zero vulnerabilities confirmed as weaponized in the wild or tracked by KEV. However, 18 critical CVEs were published in a single day, the majority targeting widely deployed WordPress plugins and Joomla extensions, several of which arrived with proof-of-concept code ready on day one. Defenders running open-source CMS ecosystems should treat today's disclosures as a prioritized patching window.
Today’s brief
- 18 critical CVEs published today — no active exploitation confirmed, but multiple PoCs dropped on day of disclosure
- WordPress plugins (WooCommerce quote, Contact Form 7 addons, miniOrange OTP) and Joomla extensions (UP plugin, AcyMailing) are the primary attack surface
- File upload and RCE flaws dominate: unauthenticated attackers can potentially achieve code execution on unpatched CMS sites
- Brazil is under sustained ransomware pressure: RECEITA FEDERAL, ANP Health, and others claimed by active groups
Critical highlights
1
A CVSS 10.0 critical flaw in the UP plugin for Joomla (versions 5.0.0–5.2.0 and 6.0.0–6.0.29) allows unauthenticated remote code installation — the most severe score possible, with a PoC available on day of disclosure, making patching or disabling the extension immediately non-negotiable.
2
CVE-2026-18143CVSS 9.8PoCsame dayaffects Request a Quote for WooCommerce The Request a Quote for WooCommerce plugin (up to 2.9.2) allows unauthenticated arbitrary file upload due to absent extension and MIME type validation, effectively handing attackers a direct path to remote code execution on any unpatched WooCommerce storefront.
3
CVE-2026-82901CVSS 9.8PoCsame dayaffects Ultra Addons for Contact Form 7 Ultra Addons for Contact Form 7 (up to 3.5.50) permits unauthenticated arbitrary file upload through insufficient file type validation, enabling potential RCE on WordPress sites — a PoC was published the same day as the CVE.
4
CVE-2026-85984CVSS 9.8affects miniOrange OTP Login, Verification and SMS Notifications The miniOrange OTP Login plugin for WordPress (up to 5.5.5) contains an authentication bypass that allows an attacker to skip password verification entirely on sites with skip_pass_fallback enabled, granting administrator-level access without credentials.
5
The vm2 sandbox library before 3.12.2 has an authorization bypass in its NodeVM external-module resolver that allows a crafted module path to escape sandboxing restrictions, a serious concern for any application using vm2 to isolate untrusted JavaScript.
6
CVE-2026-94132CVSS 9.5PoCsame dayaffects AcyMailing Enterprise extension for Joomla AcyMailing Enterprise for Joomla (below 11.1.0) accepts incoming email MIME attachments and saves them to a web-accessible path without any extension check, meaning an attacker who can send email to the monitored mailbox can plant a PHP webshell — a PoC dropped on the same day.
7
D-Link DIR-895L (A1_102b07) is vulnerable to an out-of-bounds write in the L2TP Control Channel Parser, exploitable remotely — a public exploit already exists, making this router model an attractive target for network-level attackers.
8
A second critical flaw in the UP plugin for Joomla enables authenticated but privileged PHP command injection (CVSS 9.4), complementing CVE-2026-97163 and reinforcing that the entire plugin should be considered compromised until updated.
9
Froxlor server panel (2.3.10 and earlier) fails to validate intermediate path components in the customer data-export cron, enabling path traversal that could allow attackers to write files outside intended directories.
10
A second Froxlor flaw (before 2.3.12) allows command injection through the unescaped letsencryptchallengepath setting, which is concatenated directly into a command executed by the root cron — a local or web-based attacker with settings access could achieve full server compromise.
Ransomware today
Ransomware activity targeting Brazil remains intense: recently, ANP Health and amorsaude.com.br (Healthcare) were claimed by thegentlemen and lockbit5 respectively, while agricultural company anery.com.br was also listed by lockbit5. Grupo Caberj (Manufacturing) was claimed by incransom, and in a particularly significant claim, RECEITA FEDERAL DO BRASIL — the country's federal revenue authority — was listed by the grupo emperador, indicating that no sector is out of scope. Over the past 30 days, thegentlemen leads activity with 8 victims, all in Brazil, followed by lockbit5, emperador, and akira.
ANP Health BRthegentlemen · Healthcare
anery.com.br BRlockbit5 · Agriculture and Food Production
Grupo Caberj BRincransom · Manufacturing
RECEITA FEDERAL DO BRASIL BRemperador · Government & Defense
amorsaude.com.br BRlockbit5 · Healthcare
thegentlemen 8lockbit5 3emperador 3akira 3Vexy Ransomware 2settra 2
Active groups & APTs
Several threat actor groups are being actively tracked, including handala, linkc, mogilevich, and Iran-linked mosesstaff, though no confirmed victims are attributed to these groups in the current window. China-linked Elderwood and fulcrumsec are also flagged as active or recently updated in threat intelligence feeds. The lack of confirmed victims does not imply inactivity — these groups are known for reconnaissance and pre-positioning before visible impact.
Brazil focus
Brazil continues to be one of the most heavily targeted countries in the current ransomware cycle, with victims spanning Healthcare, Agriculture, Manufacturing, Government, and Retail sectors. Beyond the ransomware claims, other recent victims include Metallco (Manufacturing, claimed by play), Javep Chevrolet (Retail, claimed by akira), and AKAZZO (claimed by arcusmedia), painting a picture of broad and opportunistic targeting across the Brazilian economy. Organizations in regulated and critical sectors should treat the RECEITA FEDERAL claim as a signal that even high-profile government entities are within scope.
ANP Healththegentlemen · Healthcare
anery.com.brlockbit5 · Agriculture and Food Production
Grupo Caberjincransom · Manufacturing
amorsaude.com.brlockbit5 · Healthcare
RECEITA FEDERAL DO BRASILemperador · Government & Defense
Metallcoplay · Manufacturing
Javep Chevroletakira · Retail & E-Commerce
AKAZZOarcusmedia
Today’s recommendation: Administrators running Joomla or WordPress sites should audit all third-party plugins and extensions immediately, prioritizing the UP plugin, AcyMailing Enterprise, Request a Quote for WooCommerce, Ultra Addons for Contact Form 7, and miniOrange OTP — applying available patches or disabling the components until patches are confirmed. Froxlor operators should upgrade to 2.3.12 and review cron execution permissions to mitigate the command injection risk.
Given the volume of PoC-backed critical vulnerabilities targeting CMS ecosystems and server panels, now is the right time to validate which of these components exist across your own infrastructure and confirm that exposure is actually closed — not just assumed.Don’t wait to become a statistic: validate today, at no cost, whether any of these vectors reach your systems.Meet the Autonomous AI Pentest Agent →Previous briefings
September 30, 2026 — Cisco SD-WAN Zero-Day and Six Active Exploits Demand Immediate AttentionSeptember 29, 2026 — Two VulnCheck-Flagged SQL Injections, Six Chrome RCEs, and a Wave of Critical Unauthenticated Flaws Demand Immediate AttentionSeptember 28, 2026 — Apple Zero-Day and Netcore Router Cluster Top a High-Alert DaySeptember 27, 2026 — Citrix NetScaler Under Active Attack: Two Critical RCEs Hit KEV on Same DaySeptember 26, 2026 — WordPress and Joomla Plugins Dominate a Calm but Patch-Heavy Day With 18 Critical CVEsSeptember 25, 2026 — 742 New CVEs on a Calm Day, But Critical Flaws in Zimbra, MediaWiki and WordPress Demand AttentionSeptember 24, 2026 — Quiet CVE Day Masks Serious Risks: CVSS 10.0 Flaws and Heavy Ransomware Activity in BrazilSeptember 23, 2026 — Quiet CVE Day Masks Heavy GitLab, ManageEngine, and Ansible ExposureSeptember 22, 2026 — Triple KEV Alert: Check Point, VeloCloud, and F5 BIG-IP Under Active Exploitation as Adobe Campaign Classic Hit by Four Critical RCE FlawsSeptember 21, 2026 — Calm CVE Day Masked by Brazil Ransomware Surge and Critical Authentication BypassesSeptember 20, 2026 — Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026 — Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026 — WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026 — Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active Exploitationview full archive →