Daily briefing · September 28, 2026
Apple Zero-Day and Netcore Router Cluster Top a High-Alert Day
Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — attention1 seen before CISA
September 28, 2026 carries an ATTENTION verdict: one CVE is already under active exploitation — CVE-2026-86950, an Apple iOS/iPadOS out-of-bounds write observed by VulnCheck before any CISA confirmation and armed on the very day it was disclosed, signaling an extremely sophisticated targeted campaign. Alongside it, a cluster of CVSS 10.0 flaws in Netcore networking devices flooded the day with 46 critical disclosures, all carrying public proof-of-concept exploits. Defenders should treat the Apple zero-day as the top immediate priority while assessing exposure to the Netcore device family.
Today’s brief
- CVE-2026-86950: Apple iOS/iPadOS zero-day under active exploitation in targeted attacks — armed same day as disclosure, VulnCheck spotted it before CISA
- Six Netcore devices (NBR200V2, NBR100V2, NAP930, NR289-GE, FAC1900R) carry CVSS 10.0 flaws with public PoCs — OS command injection and missing auth chains
- Apache Roller 9.9 flaw enables authenticated users to tamper with other weblogs via legacy XML-RPC APIs — only active if non-default setting is enabled
- Brazil is heavily targeted: four new ransomware victims in recent days across Technology, Manufacturing, Healthcare, and Agriculture sectors
Critical highlights
1
An out-of-bounds write in iOS and iPadOS (fixed in iOS 26.7.1 / iPadOS 26.7.1) is already being weaponized in what Apple describes as an extremely sophisticated attack against specific individuals; with VulnCheck flagging exploitation before CISA and a same-day arming timeline, any unpatched Apple mobile device must be treated as actively at risk right now.
2
A CVSS 10.0 OS command injection in the Netcore NBR200V2 web management interface allows a remote, unauthenticated attacker to execute arbitrary commands — a public exploit is available and the vendor has not responded to disclosure.
3
The Netcore NBR100V2 ACL handler exposes a missing authorization flaw (CVSS 10.0) in its unauthenticated JSON endpoint, enabling full remote compromise without credentials; exploit code is publicly disclosed.
4
Netcore NAP930's Network Tools CGI is vulnerable to OS command injection via the sid argument (CVSS 10.0), exploitable remotely with a public proof-of-concept and no vendor patch or response on record.
5
The boa_temp handler in Netcore NR289-GE 1.4.5102 requires no authentication to process requests (CVSS 10.0), giving remote attackers a direct path to device control; exploit is public.
6
A second critical flaw in the NR289-GE allows OS command injection through the ntp_ip argument in the NTP configuration CGI, enabling full remote code execution with no authentication required.
7
Another NR289-GE CGI endpoint — the Location Time handler — is injectable via the mac argument (CVSS 10.0), compounding the risk for any deployment of this device model that is internet-facing.
8
The /ap_ip.cgi endpoint of Netcore NR289-GE is also vulnerable to OS command injection via the ip argument (CVSS 10.0); four separate critical CVEs in a single device model with public exploits represent a near-total compromise surface.
9
A stack-based buffer overflow in the devdiscover service of FAST FAC1900R (CVSS 10.0) is remotely exploitable with a publicly available exploit, and the vendor has not acknowledged the disclosure.
10
Apache Roller 6.1.5's legacy XML-RPC APIs authenticate callers but skip authorization checks on the target weblog, allowing any authenticated user to read, modify, or delete other users' content — only sites with the non-default global XML-RPC option enabled are at risk, but the CVSS 9.9 score reflects the breadth of data exposure.
Ransomware today
Several Brazilian organizations were recently hit by ransomware: Amazon Informatica (Technology) and RECEITA FEDERAL DO BRASIL (Government & Defense) were claimed by emperador, Pantaneiro Capas (Manufacturing) by arcusmedia, ANP Health (Healthcare) by thegentlemen, and anery.com.br (Agriculture) by lockbit5. Over the past 30 days, thegentlemen leads activity with 8 known victims — all in Brazil — followed by emperador (4 BR), lockbit5 (3 BR), and akira (3 BR), illustrating that Brazil is far from a secondary target for these groups.
Amazon Informatica BRemperador · Technology
Pantaneiro Capas BRarcusmedia · Manufacturing
ANP Health BRthegentlemen · Healthcare
anery.com.br BRlockbit5 · Agriculture and Food Production
thegentlemen 8emperador 4lockbit5 3akira 3Vexy Ransomware 2settra 2
Active groups & APTs
Several threat groups have been flagged as active or updated recently, including ransomhouse, sinobi, spacebears, thegentlemen, and funksec, alongside North Korean state-affiliated APT38. While no new confirmed victims are attributed to these actors in the current window, their operational status warrants heightened monitoring, particularly given APT38's known focus on financial institutions and cryptocurrency theft.
Brazil focus
Brazil continues to absorb a disproportionate share of ransomware activity, with at least eight victims identified across sectors over the past 30 days — including a federal government agency (Receita Federal), multiple manufacturers (Pantaneiro Capas, Metallco, Grupo Caberj), healthcare providers (ANP Health, amorsaude.com.br), and an agribusiness (anery.com.br). The concentration of attacks by thegentlemen and emperador specifically targeting Brazilian organizations suggests deliberate, regionally focused campaigns rather than opportunistic hits.
Amazon Informaticaemperador · Technology
Pantaneiro Capasarcusmedia · Manufacturing
ANP Healththegentlemen · Healthcare
anery.com.brlockbit5 · Agriculture and Food Production
Grupo Caberjincransom · Manufacturing
RECEITA FEDERAL DO BRASILemperador · Government & Defense
amorsaude.com.brlockbit5 · Healthcare
Metallcoplay · Manufacturing
Today’s recommendation: Patch Apple iOS and iPadOS to version 26.7.1 immediately given confirmed in-the-wild exploitation of CVE-2026-86950; simultaneously audit all internet-exposed Netcore and FAST networking devices and apply firmware updates or isolate them, as multiple CVSS 10.0 exploits are publicly available.
Given the breadth of actively exploited and critically scored vulnerabilities disclosed today, organizations should validate which of these affected products exist within their own environment before assuming they are not exposed.Before an attacker finds it, find it first: run a free initial exposure assessment and see whether your infrastructure is vulnerable to flaws like these.Meet the Autonomous AI Pentest Agent →Previous briefings
September 30, 2026 — Cisco SD-WAN Zero-Day and Six Active Exploits Demand Immediate AttentionSeptember 29, 2026 — Two VulnCheck-Flagged SQL Injections, Six Chrome RCEs, and a Wave of Critical Unauthenticated Flaws Demand Immediate AttentionSeptember 28, 2026 — Apple Zero-Day and Netcore Router Cluster Top a High-Alert DaySeptember 27, 2026 — Citrix NetScaler Under Active Attack: Two Critical RCEs Hit KEV on Same DaySeptember 26, 2026 — WordPress and Joomla Plugins Dominate a Calm but Patch-Heavy Day With 18 Critical CVEsSeptember 25, 2026 — 742 New CVEs on a Calm Day, But Critical Flaws in Zimbra, MediaWiki and WordPress Demand AttentionSeptember 24, 2026 — Quiet CVE Day Masks Serious Risks: CVSS 10.0 Flaws and Heavy Ransomware Activity in BrazilSeptember 23, 2026 — Quiet CVE Day Masks Heavy GitLab, ManageEngine, and Ansible ExposureSeptember 22, 2026 — Triple KEV Alert: Check Point, VeloCloud, and F5 BIG-IP Under Active Exploitation as Adobe Campaign Classic Hit by Four Critical RCE FlawsSeptember 21, 2026 — Calm CVE Day Masked by Brazil Ransomware Surge and Critical Authentication BypassesSeptember 20, 2026 — Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026 — Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026 — WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026 — Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active Exploitationview full archive →