Daily briefing · September 29, 2026

Two VulnCheck-Flagged SQL Injections, Six Chrome RCEs, and a Wave of Critical Unauthenticated Flaws Demand Immediate Attention

Automated Vexday summary · sources: NVD, CISA KEV, EPSS
Verdict of the day — attention2 seen before CISA

September 29, 2026 carries an ATTENTION-level verdict: two vulnerabilities — CVE-2023-54400 and CVE-2015-20122 — were observed in active exploitation by VulnCheck ahead of any CISA confirmation, signaling real-world attacker interest before official alerts were issued. The day also brought 68 critical CVEs across 608 new disclosures, with unauthenticated SQL injections, hardcoded cloud credentials, remote code execution in HPE networking gear, and three sandbox-escaping use-after-free flaws in Google Chrome all published simultaneously. Defenders should treat the VulnCheck-flagged entries as already weaponized and prioritize patching accordingly.

Today’s brief
  • VulnCheck observed active exploitation of CVE-2023-54400 (Fumeng Cloud SQL injection) and CVE-2015-20122 (Seeyon A6 OA SQL injection) before CISA issued any formal alert — treat these as actively exploited now.
  • Three use-after-free flaws in Google Chrome (CVE-2026-102304, CVE-2026-102308, CVE-2026-102309) allow remote code execution outside the sandbox — update Chrome to 154.0.8037.92 immediately.
  • HPE Networking Instant ON APs carry two critical unauthenticated RCE flaws (CVE-2026-76721, CVE-2026-76722) — unpatched wireless infrastructure is at direct risk.
  • Brazil faced a heavy ransomware week: six organizations across manufacturing, healthcare, retail, and technology were claimed by groups including thegentlemen, lockbit5, and emperador.
68
critical
2
Actively exploited
2
Before CISA
0
Weaponized
Critical highlights
1
CVE-2023-54400◆ VulnCheckCVSS 9.3affects Fumeng Cloud
Unauthenticated UNION-based SQL injection in Fumeng Cloud's AjaxMethod.ashx endpoint allows full database read and modification with no credentials required; VulnCheck flagged this as exploited in the wild before CISA acted, making it the highest-urgency item on today's list.
2
CVE-2015-20122◆ VulnCheckHIGH 8.7affects A6 OA
Seeyon A6 OA platform exposes an unauthenticated SQL injection through the attach_ids parameter in downloadAtt.jsp, enabling arbitrary database extraction; VulnCheck's pre-CISA observation means attackers are already actively leveraging this against unpatched deployments.
3
CVE-2026-71379CVSS 10affects TMS7
Any unauthenticated attacker can export arbitrary database tables from TMS7 by sending a crafted POST request to the file export endpoint — a trivially exploitable data exfiltration path requiring zero authentication or special knowledge.
4
CVE-2026-96587CVSS 10affects Dashcam Android Application
The Viidure Android dashcam application hardcodes permanent plaintext cloud storage credentials in compiled code, granting anyone who reverses the APK full access to operational platform storage including the ability to tamper with firmware and application binaries.
5
CVE-2026-84154CVSS 9.9affects GEOVIA Geospatial Data Manager
A code injection vulnerability in Dassault Systèmes GEOVIA Geospatial Data Manager (3DEXPERIENCE R2024x through R2026x) allows an attacker to execute arbitrary code server-side — a critical risk in industrial and geospatial environments where these platforms manage sensitive operational data.
6
CVE-2026-76722CVSS 9.8affects Instant ON
An uncontrolled format string vulnerability in HPE Networking Instant ON APs enables an unauthenticated remote attacker to run arbitrary commands or cause denial of service on the underlying host — wireless infrastructure exposure is severe.
7
CVE-2026-76721CVSS 9.8affects Instant ON
A buffer overflow in HPE Networking Instant ON allows unauthenticated remote code execution as a privileged user on the operating system, making this a full device takeover risk for any internet-exposed or poorly segmented wireless deployment.
8
CVE-2026-102308CVSS 9.6affects Chrome
A use-after-free in Chrome's Views component allows a remote attacker, via social engineering, to execute arbitrary code outside the browser sandbox — the requirement for user interaction does not significantly reduce urgency given how routinely attackers deploy lure pages.
9
CVE-2026-102309CVSS 9.6affects Chrome
A use-after-free in Chrome's FullScreen component enables remote arbitrary code execution outside the sandbox via a crafted page, adding a second browser-level sandbox escape vector that should be patched in tandem with CVE-2026-102308 and CVE-2026-102304.
10
CVE-2026-102304CVSS 9.6affects Chrome
A use-after-free in Chrome's Passwords component allows remote code execution outside the sandbox, with a direct implication that credential data managed by the browser could be at risk; this is the third sandbox-escaping Chrome flaw disclosed today, underscoring the urgency of the 154.0.8037.92 update.
Ransomware today

Ransomware activity targeting Brazilian organizations has been intense recently, with six victims claimed across diverse sectors: latitudesubro.com (Manufacturing, BrainCipher), somasolucoes.com (Professional Services, m3rx), camorim.com.br (Retail & E-Commerce, lockbit5), Amazon Informatica (Technology, emperador), Pantaneiro Capas (Manufacturing, arcusmedia), and ANP Health (Healthcare, thegentlemen). Over the past 30 days, thegentlemen leads with 8 known victims — all in Brazil — followed by lockbit5, emperador, and akira, painting a picture of Brazil as a primary target rather than incidental collateral. The breadth of sectors hit, from healthcare to manufacturing to retail, signals that no vertical should consider itself out of scope.

latitudesubro.com BRBrainCipher · Manufacturing
somasolucoes.com BRm3rx · Professional Services
camorim.com.br BRlockbit5 · Retail & E-Commerce
Amazon Informatica BRemperador · Technology
Pantaneiro Capas BRarcusmedia · Manufacturing
ANP Health BRthegentlemen · Healthcare
thegentlemen 8lockbit5 4emperador 4akira 3Vexy Ransomware 2BrainCipher 2
Active groups & APTs

Several threat groups have been flagged as recently active or updated in threat intelligence feeds, including ransomhouse, sinobi, spacebears, thegentlemen, and funksec, alongside North Korean state-sponsored actor APT38. While no specific new victims are attributed to these groups in today's data, the simultaneous appearance of multiple actors in intelligence tracking — including a nation-state group — suggests elevated operational tempo across both financially motivated and espionage-driven adversaries.

Brazil focus

Brazil remains a disproportionately targeted country in the current ransomware landscape, with eight organizations reported as victims in recent weeks spanning agriculture (anery.com.br, lockbit5), manufacturing (Grupo Caberj, incransom; Pantaneiro Capas, arcusmedia), healthcare (ANP Health, thegentlemen), and technology (Amazon Informatica, emperador). The concentration of thegentlemen's activity — 8 of its known victims in the last 30 days being Brazilian — alongside the presence of lockbit5 and emperador suggests coordinated or opportunistic campaigns specifically oriented toward Brazilian infrastructure. Organizations in these sectors should treat ransomware preparedness as an active operational priority, not a future project.

latitudesubro.comBrainCipher · Manufacturing
somasolucoes.comm3rx · Professional Services
camorim.com.brlockbit5 · Retail & E-Commerce
Amazon Informaticaemperador · Technology
Pantaneiro Capasarcusmedia · Manufacturing
ANP Healththegentlemen · Healthcare
anery.com.brlockbit5 · Agriculture and Food Production
Grupo Caberjincransom · Manufacturing
Today’s recommendation: Immediately update Google Chrome to version 154.0.8037.92 to close three sandbox-escaping use-after-free vulnerabilities, apply HPE Instant ON patches to prevent unauthenticated RCE on wireless infrastructure, and treat CVE-2023-54400 and CVE-2015-20122 as actively exploited — isolate or remediate affected Fumeng Cloud and Seeyon A6 deployments without waiting for CISA formal confirmation. Audit any applications for hardcoded credentials and unauthenticated data export endpoints as systemic patterns, not isolated findings.
Given the mix of actively exploited SQL injections, sandbox-escaping browser flaws, and hardcoded credential exposures disclosed today, now is the right moment to validate whether your own attack surface contains any of these systemic patterns before an attacker does it for you.Every CVE above is a possible door — find out which ones are open in your environment with a free attack-surface check.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 30, 2026 — Cisco SD-WAN Zero-Day and Six Active Exploits Demand Immediate AttentionSeptember 29, 2026 — Two VulnCheck-Flagged SQL Injections, Six Chrome RCEs, and a Wave of Critical Unauthenticated Flaws Demand Immediate AttentionSeptember 28, 2026 — Apple Zero-Day and Netcore Router Cluster Top a High-Alert DaySeptember 27, 2026 — Citrix NetScaler Under Active Attack: Two Critical RCEs Hit KEV on Same DaySeptember 26, 2026 — WordPress and Joomla Plugins Dominate a Calm but Patch-Heavy Day With 18 Critical CVEsSeptember 25, 2026 — 742 New CVEs on a Calm Day, But Critical Flaws in Zimbra, MediaWiki and WordPress Demand AttentionSeptember 24, 2026 — Quiet CVE Day Masks Serious Risks: CVSS 10.0 Flaws and Heavy Ransomware Activity in BrazilSeptember 23, 2026 — Quiet CVE Day Masks Heavy GitLab, ManageEngine, and Ansible ExposureSeptember 22, 2026 — Triple KEV Alert: Check Point, VeloCloud, and F5 BIG-IP Under Active Exploitation as Adobe Campaign Classic Hit by Four Critical RCE FlawsSeptember 21, 2026 — Calm CVE Day Masked by Brazil Ransomware Surge and Critical Authentication BypassesSeptember 20, 2026 — Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026 — Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026 — WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026 — Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active Exploitationview full archive →
Share